A couple of Kerio Firewall Questions.

From: Ian Jordan (ian_at_sunhouse.TheFireplus.com)
Date: 05/31/03


Date: Sat, 31 May 2003 11:18:17 +0100

Hi All

I have just installed Kerio Personal Firewall v2.1.5,and downloaded Sponge's
"Sponge3" ruleset which I must admit seems very comprehensive.However when I
ran a test on the PCFlank website,it showed all my important ports as
"stealthed" ,but I got the following report regarding my browser.

"Danger!
While visiting web sites your browser reveals private information about you
and your computer. It sends information about previous sites you have
visited. It may also save special cookies on your hard drive that have the
purpose of directing advertising or finding out your habits while web
surfing."

Is this minor "scaremongering" by PCFlank or is it something I really need
to be concerned about? No other test site seems to be worried about it. They
then went on to say.

"Recommendation:
We advise you to get personal firewall software. If you already have a
firewall program adjust it to block the distribution of such information."

I have a firewall obviuosly,but am unable to work out how to achieve this
in Kerio,if indeed it can be done,or needs to be done.

Specifically regarding the "sponge3" ruleset,what exactly does the rule
"microsoft 1" do,I am guessing it prevents information being sent from my
computer to microsoft,but it also seems to stop me contacting any microsoft
website,for example to get critical updates etc,and seems to prevent
"Microsoft Messenger" from working in that when I try to "update windows"
or log in to "Microsoft messenger" I end up with a long list of
"1,[31/May/2003 11:07:54] Rule 'Microsoft 1': Blocked: Out TCP,
localhost:1275->207.46.104.20:1863, Owner: C:\PROGRAM FILES\MSN
MESSENGER\MSNMSGR.EXE" in the case of "Messenger",and "1,[31/May/2003
11:10:44] Rule 'Microsoft 1': Blocked: Out TCP,
localhost:1296->207.46.249.190:80, Owner: C:\PROGRAM FILES\INTERNET
EXPLORER\IEXPLORE.EXE" in the case of "Windows Update"

Is there a work around for this or can I safely delete the "microsoft 1"
rule,or simply edit it to allow outbound without compromising security?

Thanking you in advance for any forthcoming help or information.

Ian & Linda Jordan

-- 
Please put out "TheFire" to reply via e-mail


Relevant Pages

  • Re: XP Home security updates-Do I need?
    ... obviates the need for a lengthy connection to the Microsoft Windows Update ... Now I have 54 critical updates to download ... > Sygate Personal Firewall ...
    (microsoft.public.windowsxp.general)
  • RE: Microsoft Cant Win.
    ... Subject: Microsoft Can't Win. ... Tiny Personal Firewall is also free and far superior ... to ZoneAlarm IMHO, as well as much superior to BlackIce. ... PS I replied twice to the original message in this chain because the list ...
    (Focus-Microsoft)
  • Re: Access violation message
    ... networks, such as KaZaA, and IRC, and will attempt to kill antivirus and personal firewall ... Some devious person is "spoofing" Microsoft. ... "Ingolf Schmacke" wrote in message: ... | Norton system works and firewall do not work anymore - | system restore does not roll back either! ...
    (microsoft.public.windowsxp.security_admin)
  • Microsoft Windows Malicious Software Removal Tool
    ... install same a window appears headed "Rad the following EULA. ... luckily I installed a Personal Firewall about a month ago), ... Can anyone advise if this is from Microsoft or from some unscupulous person/s. ...
    (microsoft.public.windowsupdate)