Kerio PF

Mar 19, 2006 16 Replies
Kerio PF open original image

Hi I purchased the pro version of KPF some time ago. At the time, I was using a standard broadband modem for connecting to my ISP. I recently upgraded my system to wireless and found that Kerio blocked most of my Internet connections. I contacted support who gave me much advice on how to set it up. I followed their advice but got nowhere. I have now uninstalled Kerio and am relying on my wireless broadband modem/router and Windows firewall. I was wondering how safe this is and am looking for advice on where to go next with my PC security. I am using Windows XP HE with SP2. Any advice appreciated.



Ian


If it were me, then I wouldn't use the XP FW behind the NAT router either. Most likely the NAT router and the XP FW cannot stop outbound traffic. However, there is another packet filter on the XP O/S called IPsec that can stop inbound or outbound traffic behind the NAT router by port, protocol or IP and it's called IPsec. You can use it to supplement the NAT router too.

You can implement the the AnalogX IPsec rules on the machine make the rules,learn how the rules are made and configure the rules yourself.

formatting link

The buck stops at the O/S and nowhere else and you should try to secure it as much as possible on a wireless network, as someone can join your wireless network and be all over the top of your machines wired or wireless.

formatting link
Basics

formatting link
Duane :)

The XP Firewall behind a router should provide plenty of intrusion prevention. Beyond that, your on-line safety is a product of your on-line behavior.

Why not? It can't hurt anything.

Most likely the NAT router and the XP FW cannot stop outbound

You can do the same thing in XP by going into the advanced tcp/ip settings for your adapter. Of course, you want to remain behind a firewall.

I would choose IPsec over the XP FW to stop outbound by port, protocol or IP. The router is already stopping unsolicited inbound, which the XP FW would be doing too. I see no advantage there by using the XP FW to supplement the NAT router.

I don't see any ability to stop outbound packets by setting rules to stop the packets by port, protocol or IP (LAN or WAN IP) with the XP FW. I can do that with IPsec to supplement the NAT router. If I had to stop outbound, I can set rules with IPsec to stop outbound packets behind the XP FW or the NAT router, which neither one of the solutions can stop outbound packets by setting packet filtering rules, when the NAT router cannot set outbound filtering rules.

Duane :)

No, you're right. I was thinking this applied to both inbound and outbound traffic.

With a router, I see absolutely no need for the XP firewall, that's just redundant waste. I do totally agree with your second statement though, your internet safety relies completely on your online behavior, and what, if any, security products you use depends on this also.

It can be used to prevent programs from unsolicitedly opening listening ports. If that's not wanted/needed the Windows Firewall can be disabled.

cu

59cobalt

That's why I use IPsec to supplement BlackIce on the laptop while I am on the road.

Duane :)

There is no such thing as a program running behind a FW that makes or initiates contact with a remote program/application that is not the one doing the solicitation. So how can such a program/application running on the machine unsolicitedly do anything if it's the one doing the solicitation, which causes the ports to be open on the FW and the program listing on the opened ports due to its solicitation?

Duane :)

Maybe, but a waste of what? Certainly not time. You're not required to do anything on a routine basis. Nor resources. With or without the XP firewall, svchost memory usage is virtually the same. In 6 sigma application, waste has to be measurable.

I do totally agree with your second statement though,

^^^^^^^^^^^^^^^

Read again.

cu

59cobalt

Read it again for what? If one doesn't want something to run, then one should be going to the O/S to stop it and not some personal FW to stop it that can be circumvented and defeated.

Duane :)

Sometimes people accidentally run applications that do this. Sometimes applications can't be unbound from external interfaces (and cannot be replaced for whatever reason). Not allowing arbitrary applications to open listening ports helps mitigating risks.

cu

59cobalt

Ok, perhaps the system drain is minimal, but as long as software is filtering traffic, there is some hit. Perhaps a better word for it would have been 'pointless'..

People don't accidentally run applications. I'll give it that they didn't know what it was they were running that lead to a compromise that they contributed to it in someway. If one doesn't want an application to do it then don't run the application, take it off of the machine or go to the O/S and stop it.

They should know what's running on the machine in the first place and not let some PFW tell them what's happening on the machine.

Duane :)

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required