Kerio 2.1.5 + SSM - My New Favourite!

Discussion in 'other firewalls' started by cprtech, Oct 20, 2006.

Thread Status:
Not open for further replies.
  1. Jarmo P

    Jarmo P Registered Member

    Joined:
    Aug 27, 2005
    Posts:
    1,207
    My PC is also about 5 years old. Fujitsu-Siemens. It has started to show some total freezes when running videos or just playing mp3 songs. Only powerbutton 5 sec press will help to reboot, or sometimes this thing reboots itself.
    Really suspect some hardware problem like from a faulty motherboard, power source etc. Too hard for me to track them down.
    http://en.wikipedia.org/wiki/Capacitor_Plague
    http://www.badcaps.net/


    I used to run kerio 2.1.5, Cyberhawk and SSM same time with Sandboxie, but a few times after adding SB, SSM did not autostart indicating in my mind some conflict between the 3 HIPS's.
    So now SSM is only used when wanting, not all the time.

    Jarmo
     
    Last edited: Dec 1, 2006
  2. Chuck57

    Chuck57 Registered Member

    Joined:
    Sep 2, 2002
    Posts:
    1,770
    Location:
    New Mexico, USA
    Jarmo, besides the groans and moans, that's exactly what's happening with mine, too. If I try to download something, or uninstall something, without fail, it will freeze. It takes a hard boot to get it going again, and then it obeys. Next time I try to uninstall or download, though, it will freeze.

    The moaning and groaning are a constant thing even, as I said, when it's just sitting doing nothing.

    Sorry for being off topic.
     
  3. Jarmo P

    Jarmo P Registered Member

    Joined:
    Aug 27, 2005
    Posts:
    1,207
    I don't have that anymore. It is cause my display card has a small cooling fan and it has stopped that grinding noice, cause it is not rotating anymore :p :cool:
    I could just try to change that card, but since i have also those twisted caps in motherboard, am thinking also of just running this as long as it lasts.
     
  4. SamSpade

    SamSpade Registered Member

    Joined:
    Oct 22, 2006
    Posts:
    415

    Hey, five years from a generic box is not bad. I burned up three hard drives and one mother-board in an IBM T22 (which became a T21 due to the board change!) in less than four years. Count your blessings !!


    //
     
  5. Chuck57

    Chuck57 Registered Member

    Joined:
    Sep 2, 2002
    Posts:
    1,770
    Location:
    New Mexico, USA
    That's about what I figured SamSpade. Five years and one processor and one cooling fan recently replaced is all I've had to fix.

    The Sam's Club in Santa Fe has a really good deal on Compaq (not my favorite brand). Full system, 1G RAM, lots of USB ports, don't remember much else, for under $400, including monitor (15" CRT). That's cheaper than this thing cost me without the monitor. If I could get 5 yrs out of it, I'd be happy.
     
  6. SamSpade

    SamSpade Registered Member

    Joined:
    Oct 22, 2006
    Posts:
    415
    How times have changed, eh? With probably 90% of all computer components now being made in China, the prices will never be lower -- unless that start making parts in North Korea or some place like that. Anyway, you've got lots to choose from today at rock bottom prices, so go for it and enjoy it !!

    Regards,

    Sam
     
  7. Long View

    Long View Registered Member

    Joined:
    Apr 30, 2004
    Posts:
    2,295
    Location:
    Cromwell Country
    I don't want to drag this too much off topic but having used Kerio for years I removed it a few months ago and now use only the Windows Xp Firewall and the hardware firewall built into my Netgear router. Am I really taking much of a risk ?
     
  8. Chuck57

    Chuck57 Registered Member

    Joined:
    Sep 2, 2002
    Posts:
    1,770
    Location:
    New Mexico, USA
    I tried using Windows firewall for a while but never felt comfortable. It has no outbound protection.

    My computer is clean of spyware, etc, but there's always that nagging doubt in my mind even with antivirus, spyware and SSM running.

    I never had a problem with Windows firewall. It did it's job, along with the hardware firewall we have. If you have other security in place to protect you, I'd say you're probably fine.
     
  9. farmerlee

    farmerlee Registered Member

    Joined:
    Jul 1, 2006
    Posts:
    2,585
    I see no point in running the xp firewall when your firewalled router is the doing the job for you. The only risk you take is not being able to control outbound connections. The latest version of ssm has outbound network protection however it is payware. You could also try something like appdefend which has a free version.
     
  10. herbalist

    herbalist Guest

    I had sounds like that coming from mine a while back. It was the processor cooling fan. Fans are pretty cheap to replace.
    When I see how many people have had hardware problems with systems much newer than mine, I have to wonder if I've just been that lucky or if hardware is getting more poorly made as the years go by. My 98 box runs 24/7, has for several years. Replaced the CD with a CDRW, upgraded one RAM strip, added a 2nd hard drive, a USB card and an ethernet card. The rest is original hardware.
    If you're running more than one HIPS program, you're seriously increasing your changes for conflicts. There's too many ways they can interfere with each other that can't be easily compensated for in their rulesets. One HIPS, well configured is sufficient. A conventional HIPS and a sandbox may be workable, but just because the 2 apps get along now doesn't mean they will when one of them is updated. If either one is auto-updating, you could end up with a conflicting non-functional system with no warning.
    Rick
     
  11. Long View

    Long View Registered Member

    Joined:
    Apr 30, 2004
    Posts:
    2,295
    Location:
    Cromwell Country
    Thanks - I wasn't aware of appdefend. I have a trial copy running now on one of my 7 machines ( 3 desktops for me, 2 desktops for my wife and two lap tops).
    The number of machines is part of the problem. Software is often free ( crapcleaner) but often requires a license per machine. appdefend looks good and
    I have no problem paying $49 for all machines.

    Apart from cost my other concern is the amount of resource each program requires. with so many virus programs, firewalls, spyware protection.......you need a computer before programs even get to run.

    I don't want to tempt fate but I haven't seen a live virus in over 5 years or more. I have recently loaded Spybot again and found nothing on any machine, tried adaware with the same result. So my question is "what is the right balance when it comes to protection ?" it is not difficult to keep a clean machine but is the amount of damage that is done to performance worth it ?
     
  12. lasu

    lasu Registered Member

    Joined:
    Mar 19, 2005
    Posts:
    43
    i have been using Kerio 2.1.5 since the post that CJsDAD mentioned at the start of this thread. i also have Startup Monitor installed and im using less that 1% ram, most of the time nothing at all. i really like kerio 2.1.5 and have installed it on the wifes pc also.
    i think ill stay with it till i buy a new machine w/vista. probably down the road a couple of yrs. at this time im not sure what fw's will work with vista as ive heard it will make many fw's obsolete?
    kerio 2.1.5 is the best, IMHO.
    Lasu
     
  13. Long View

    Long View Registered Member

    Joined:
    Apr 30, 2004
    Posts:
    2,295
    Location:
    Cromwell Country
    having tried out appdefend and then kerio 2.1.5 I have to say that they are both better ( for me ) than the latest bloated verion of Kerio.

    However I read on another thread about Jetico and that it what I am now using.
    It seems to be just as light as Kerio 2.1.5 so to anyone looking for a change I would say take a look at Jetico.
     
  14. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    The XP firewall covers primarily inbound, as does also the router. Thus, you have little or no coverage for outbound.

    A light-but-good-&-free setup in my opinion is Kerio 2.1.5 plus Cyberhawk plus Antivir-free. (Kerio 2.1.5 does a good job on outbound stuff & is light as a feather.)
     
  15. Long View

    Long View Registered Member

    Joined:
    Apr 30, 2004
    Posts:
    2,295
    Location:
    Cromwell Country
     
  16. pcalvert

    pcalvert Registered Member

    Joined:
    May 21, 2005
    Posts:
    237
    I have used Kerio 2.1.5 and liked it. However, I'd be a little reluctant to install it on a clueless newbie's computer. Instead, I'd be inclined to try a combination of ZoneAlarm Free 4.5 and SSM. Or maybe ZoneAlarm Free 6.? and SSM.

    Phil
     
  17. Long View

    Long View Registered Member

    Joined:
    Apr 30, 2004
    Posts:
    2,295
    Location:
    Cromwell Country
    Not sure that a clueless newbie should be encouraged to play with SSM either.
     
  18. kdm31091

    kdm31091 Registered Member

    Joined:
    Jul 18, 2006
    Posts:
    365
    Kerio and ZoneAlarm both pretty much have similar "allow/block" prompts so just install Kerio 2.1.5, they have to know what to allow or deny either way, and Kerio is muuuch lighter :)
     
  19. WSFuser

    WSFuser Registered Member

    Joined:
    Oct 7, 2004
    Posts:
    10,639
    yes but kerio 2 also has rules. it may or may not be a significant issue though.
     
  20. pcalvert

    pcalvert Registered Member

    Joined:
    May 21, 2005
    Posts:
    237
    Yeah, but with Kerio PF 2.1.5, doesn't one have to go in and move any new rules that get created above the last rule? I don't remember exactly what the last rule was, but I was always having to go in and move new rules above it because they were automatically being placed after it when they were created by Kerio.

    Phil
     
  21. Jarmo P

    Jarmo P Registered Member

    Joined:
    Aug 27, 2005
    Posts:
    1,207
    No one doesn't. First comes system protection rules. Made from BlitzenZeus's template or any other way.
    Made only once, of course them can be made customized as one likes too. And indeed they should be, for DNS and DHCP and how one then pleases to make them tighter.
    There should be no block rules at bottom! The only thing one should consider a bit difficult with kerio 2.1.5 is building a good and safe working system protection rules. This comes as granted with the so called application based firewalls but not as tight made as it should be. It is not something a newbie can do, but too often it is said that rulebased firewalls are difficult. Only some basic learning is needed, things that most here know already about TCP/IP filtering.

    Application rules are added when needed after the basic firewall protection rules for the system. Of course one can make as twisted ruleset by mistake one desires. But everything unkown is denied by kerio, so those "global" block rules you talk about I think? They are not needed.

    Adding application filter rules as when you get asked, you can just add them same way as with any other application firewall like ZA or Sygate etc. You have the ability to leave them as wide open as them regarding to port numbers and that is also a kerio 2.1.5 default allowance, exactly same as with application firewalls.
    Or make them tighter and then you get might get asked for more. Just add what ever is needed and have the diagnostic help from the alerts.
    I have a pretty tight setup regarding loopback proxies, so I have to make some adjustments, but it is only me.

    Qkweb should really since he is actually in his leaktests promoting the packet filter + HIPS feature firewalls causing all this bloat in "firewalls" to test also kerio 2.1.5 + SSM together. Both of course tailored to pretty tight protection. That is my opinion he should really do as a service and as the "firewalleaktester" to internet using community participating in these threads of wilders etc.

    I am not behind a router or HW firewall, so I have never tried Jetico since it does not run as a service to be able to say if it is as intuitive as kerio 2.x with packet filtering. Comodo is not. They should have first built the firewall basics functional before adding all hips's to pass those things most people anyways have settings disabled and are not protected against them, when running it.

    Jarmo
     
    Last edited: Dec 3, 2006
  22. herbalist

    herbalist Guest

    I'd like to see that combo tested as well, using good rulesets. I'd bet on it out-performing most of the competition.
     
  23. farmerlee

    farmerlee Registered Member

    Joined:
    Jul 1, 2006
    Posts:
    2,585
    The current version of appdefend is actually still beta and does not expire, even tho it says its a 15 day trial it stays fully functional after the trial period. I'd wait until the official release before getting a license. You're in luck with appdefend as its super light with minimum resource use.

    I have bought many licenses in the past and have found that it isn't worth it running lots of security apps. They never alerted me to nothing and just sucked the life from my computer. Currently i am phasing most of my security apps out, just using them till they expire then dropping them.
     
  24. Long View

    Long View Registered Member

    Joined:
    Apr 30, 2004
    Posts:
    2,295
    Location:
    Cromwell Country
    farmerlee are you running redefend as well ? The trial version includes this automatically.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.