Re: Need Configuration for Kerio running W2K Gateway to create 100% Stealth

From: Charter (neosad1st_at_charter.net)
Date: 01/05/04


Date: Sun, 04 Jan 2004 20:27:47 -0700

Ron wrote:

> I've made a number of attempts at configuring the free version of
> Kerio 4X on W2K as a Gateway (ICS) but I can never achieve 100%
> Stealth on GRC.COM. Does anyone know if this can be done on the
> latest version of Kerion? If so could you fill me in or provide a
> reference. Thanks. Norton's Personal Firewall works great but I
> don't want to spend the $45.

First off, I believe it's not wise to use a windows machine as a gateway.
Use a Linux box or FreeBSD box for that, or buy a router. Any router will
usually do, such as a Linksys Broadband router or Firewall router.
Secondly, did you know that stealthed ports are actually not "proper"
according to the RFC and IEEE standards (I forget which) for TCP and IP?
See, what's supposed to happen is that if a machine tries to connect to
yours on a port that nothing is listening on, your machine should send
either ICMP or tcp with RST flag saying "hey, that port is closed", and the
machine will see the port is closed. This is like using iptables with -j
REJECT.
With "stealthed" ports, the machine tries to connect to yours, and yours
does nothing if the connection is denied. Therefore the machine can't tell
whether your port exists or not.
I'd suggest that if the port is closed and your machines are clean of
viruses and spyware/adware, etc, then you're fine. However, security goes
beyond firewalls, so do like the other guys said and harden your operating
system(s).

-- 
Be both a speaker of words and a doer of deeds.
                -- Homer


Relevant Pages

  • Re: Routers Firewall
    ... I ask him do you have a firewall and he says yes. ... I still have an IDS/firewall on all my machines behind the router. ... > to connect to a port your public IP address the router would reject the ... > An open port on the router could be connected to a service running on the ...
    (comp.security.firewalls)
  • Re: Possible Mail Relay or just new usages of returned mail by spammers
    ... If you have ANY type of firewall, be it a NAT router or true firewall ... ISA can be used in conjunction with the router/firewall, but if you do, you ... to be done twice...once in ISA, and once in the router to port forward to ...
    (microsoft.public.windows.server.sbs)
  • Re: Home firewall Hits
    ... >Port 162 with a UDP message. ... than theres nothing blocking access from the internet to your router. ... >Subject: Home firewall Hits ... >simplify the management and deployment of PGP and reduce overall PGP costs ...
    (Security-Basics)
  • Re: Routers Firewall
    ... > indicates that it has firewall technology, then the router doesn't have a ... What your router does have is NAT. ... ZA is a fine product which will protect a computer ... Port 80 is the WEB access port and port 21 is the FTP ...
    (comp.security.firewalls)
  • Re: Bypassing the firewall
    ... Firewall in the router but i think it comes with Zone Alarm. ... >> The one thing you MUST remember is that an open port is an open port no ... >> So start your game and then start TCPview to see the ports the game is ...
    (comp.security.firewalls)