Re: No Log file with Kerio..

From: Systemguy (Me@here.ca)
Date: 05/21/02


From: "Systemguy" <Me@here.ca>
Date: Mon, 20 May 2002 18:13:10 -0400

Hi Kiwi Boy,

When setting up the rules for Kerio, make sure that you check the box "Log
when
this rule match" for items you want a record of. (At least that is what the
box says
for Tiny and I assume Kerio uses the same or similar terminology.)

If you are receiving a DoS attack, it is probably against a port you are
allowing
and _not_ blocking with your firewall. In this case, unless you change your
rules
to log the successful stuff as well, you will not detect it.

Cheers,

Systemguy

"Kiwi Boy." <roger.s@paradise.net.nz> wrote in message
news:1ilgeu08a376bnvkk42gm9mu0dsvj195e3@4ax.com...
>
> I seem to be getting what I think are Dos attacks but I have no log file,
how can I
> get this to work with Kerio.
>
> Thanks
>
>



Relevant Pages

  • Re: No Log file with Kerio..
    ... >When setting up the rules for Kerio, make sure that you check the box "Log ... >this rule match" for items you want a record of. ... >If you are receiving a DoS attack, it is probably against a port you are ... couple check boxes for "Log Packets Addressed to Unopened Ports" and ...
    (comp.security.firewalls)
  • Re: No Log file with Kerio..
    ... >When setting up the rules for Kerio, make sure that you check the box "Log ... >this rule match" for items you want a record of. ... >If you are receiving a DoS attack, it is probably against a port you are ... couple check boxes for "Log Packets Addressed to Unopened Ports" and ...
    (comp.security.firewalls)
  • Kerio reports "TCP ack packet attack"
    ... I keep getting the entry "TCP ack packet attack" in my ... log file. ... I've heard elsewhere that this is Kerio is simply blocking TCP ACKs to ports ...
    (comp.security.firewalls)