Author Topic: Need some help about Kerio PF  (Read 7474 times)

0 Members and 1 Guest are viewing this topic.

Offline YLAP

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2119
Need some help about Kerio PF
« on: June 07, 2005, 04:14:23 PM »
I know it's an antivirus forum, but maybe who has Kerio PF could answer to my question. Should I allow this connection? I denied it this time.

Offline Kamulko!

  • Advanced Poster
  • **
  • Posts: 988
  • "CENSORED"
Re: Need some help about Kerio PF
« Reply #1 on: June 07, 2005, 06:08:34 PM »
I don't know... but here you can see the traceroute and the whois of the IP!!! ???

Offline YLAP

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2119
Re: Need some help about Kerio PF
« Reply #2 on: June 07, 2005, 06:23:40 PM »
Yep...  :o It can't be good thing so I think I've done rigth with creating rule to block this connection all the times.


I think i'll swith kerio to sygate, as all these pop ups keeps me anoying!  >:(
« Last Edit: June 07, 2005, 06:28:31 PM by Ylap »

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Need some help about Kerio PF
« Reply #3 on: June 07, 2005, 06:33:34 PM »
Deny all external connection attempts (red) and tick the create a rule box if there is one.

(Unless of course you need to accept an incoming connection: MSN needs to do this if you want to accept files. I believe you also need to allow inbound connections if you want to host an online game or create a web server.)

Check in Network Security>Appllications. Internet in should have a red cross for every application unless you're really sure you need to accept connections.

In cases like this you did the right thing to deny it. But make the rule permanent because Kerio GUI doesn't need to accept connections.



This certainly looks like a hacking attempt.

Isn't china the new hacker hotspot?

     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Need some help about Kerio PF
« Reply #4 on: June 07, 2005, 06:37:17 PM »
Make your rules permanent and you won't have any more pop-ups, Ylap.

Kerio is a strong firewall and you get intrusion protection with the free version which you don't with Sygate.

Sygate detects intrusions but it doesn't block them. Guess what happens when it detects them? A pop-up.

You'd be jumping out of the frying pan into the fire!

« Last Edit: June 07, 2005, 06:49:15 PM by FreewheelinFrank »
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline Kamulko!

  • Advanced Poster
  • **
  • Posts: 988
  • "CENSORED"
Re: Need some help about Kerio PF
« Reply #5 on: June 07, 2005, 06:40:33 PM »
Our pcs are under continuos scanning. Is normal. The real (but different) problem is in the map. As you can see, EVERY query from Italy to non-European addresses follow the same backbone route: STOCKTON. I see it when I verify the traceroute of my queries to Asia and Australia or New Zealand. This is a sign of the sourveillance of Europeans users by USA. Where is the privacy? Where is the freedom?  ??? When I try to query for the Whois of this unknown server in the USA, I have always the same automatic reply: "You are not authirized... etcetera"... eheheh...  :-X... Big Brother live and rule our communications. :'(.. and he is not yellow faced
« Last Edit: June 07, 2005, 06:43:04 PM by Kamulko! »

Offline YLAP

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2119
Re: Need some help about Kerio PF
« Reply #6 on: June 07, 2005, 07:23:10 PM »
thanks kamulko. I'll have it in mind.  ::) I've just deleted all kerio configuration (set to default) and now I'm very closely configuring it from zero.
« Last Edit: June 07, 2005, 07:46:24 PM by Ylap »

Offline YLAP

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2119
Re: Need some help about Kerio PF
« Reply #7 on: June 07, 2005, 08:24:11 PM »
Deny all external connection attempts (red) and tick the create a rule box if there is one.

(Unless of course you need to accept an incoming connection: MSN needs to do this if you want to accept files. I believe you also need to allow inbound connections if you want to host an online game or create a web server.)

Seems I need incoming connection for IE, as I can't browse in my ISP ftp server. But how about normal surfing then? Is it safe?  ??? On the other hand I can handle with kerio pop ups then surfing ftp as everytime i just need to press "permit" once everytime i go to other folder....
« Last Edit: June 07, 2005, 08:34:16 PM by Ylap »

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Need some help about Kerio PF
« Reply #8 on: June 07, 2005, 09:22:42 PM »
I use SmartFTP to connect to my ISP ftp server and it doesn't need to accept incoming connections. IE and firefox don't either. ???

Why does your ISP server need to connect to IE? I'd be a bit worried about having IE allowed to accept incoming connections too. I'm afraid this is outside my experience. :-\

Don't forget to visit ShieldsUp! to check your configuration when you've finished.
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline YLAP

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2119
Re: Need some help about Kerio PF
« Reply #9 on: June 07, 2005, 09:31:49 PM »
If I deny incoming connection in IE or FilleZilla I can't receive file list or directory tree (on FileZilla). And kerio reports incoming connection.
« Last Edit: June 07, 2005, 09:39:04 PM by Ylap »

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Need some help about Kerio PF
« Reply #10 on: June 07, 2005, 09:35:10 PM »
Hmmm. Got me baffled.  ???

Maybe somebody else can help you out.
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Need some help about Kerio PF
« Reply #11 on: June 07, 2005, 09:40:49 PM »
Of course you could always create a custom rule to allow connections from your ISP ftp address.
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline YLAP

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2119
Re: Need some help about Kerio PF
« Reply #12 on: June 07, 2005, 10:54:46 PM »
If I deny incoming connection in IE or FilleZilla I can't receive file list or directory tree (on FileZilla). And kerio reports incoming connection.

Seems to be safe, as Lietuvos Telekomas is my ISP. It's report about this Ip adress:

Look Up Domain or IP Information

% Information related to '212.59.0.0 - 212.59.31.255'

inetnum:      212.59.0.0 - 212.59.31.255
org:          ORG-LT1-RIPE
netname:      LT-LIETUVOS-980407
descr:        Lietuvos Telekomas
country:      LT
admin-c:      VD176-RIPE
tech-c:       LTIN1-RIPE
status:       ALLOCATED PA
mnt-by:       RIPE-NCC-HM-MNT
mnt-lower:    AS8764-MNT
mnt-routes:   AS8764-MNT
source:       RIPE # Filtered

organisation:   ORG-LT1-RIPE
org-name:       Lietuvos Telekomas
org-type:       LIR
address:        28 Savanoriu avenue
address:        LT-03501
address:        Vilnius
address:        Lithuania
phone:          +370 2 629992
fax-no:         +370 5 2783736
admin-c:        VD176-RIPE
admin-c:        JS3667-RIPE
mnt-ref:        AS8764-MNT
mnt-ref:        RIPE-NCC-HM-MNT
mnt-by:         RIPE-NCC-HM-MNT
source:         RIPE # Filtered

person:       Valentina Dubovskaja
address:      Savanoriu 28
address:      LT-2600 Vilnius
address:      Lithuania
phone:        +370 5 2367120
fax-no:       +370 5 2150787
nic-hdl:      VD176-RIPE
mnt-by:       TELECOMLT-MNT
source:       RIPE # Filtered

person:         Lithuanian Telecom IP NCC
address:        Savanoriu 28
address:        LT-03501 Vilnius
address:        Lithuania
remarks:        *******************************************************
remarks:        * ABUSE CONTACT: abuse@takas.lt in case of violation, *
remarks:        * illegal activity, scans, probes, spam, etc.         *
remarks:        *******************************************************
phone:          +370 5 2367082
nic-hdl:        LTIN1-RIPE
mnt-by:         TELECOMLT-MNT
source:         RIPE # Filtered
abuse-mailbox:  abuse@takas.lt

% Information related to '212.59.12.0/22AS8764'

route:        212.59.12.0/22
descr:        LT-TELEKOMAS
origin:       AS8764
mnt-by:       AS8764-MNT
source:       RIPE # Filtered



Offline YLAP

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2119
Re: Need some help about Kerio PF
« Reply #13 on: June 07, 2005, 11:00:50 PM »
After half an hour seems successfully created advanced rule for my ftp.  ;D
« Last Edit: June 07, 2005, 11:39:32 PM by Ylap »

Offline YLAP

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2119
Re: Need some help about Kerio PF
« Reply #14 on: June 07, 2005, 11:49:16 PM »
Damn! Stupid ftp!  >:( Local point 0.0.0.0 but port is changing everytime I go to next directory!  >:( RRRRR....


At last!  :P I'm so tired! But now seems to work fine as I left only IP address in advanced rule. Going to sleep now. Bye, and see you tomorrow.
« Last Edit: June 07, 2005, 11:58:54 PM by Ylap »