Re: Kerio PFW 2.14 - Safe?

From: Felix Tiede (tiede_at_pc-tiede.de)
Date: 09/10/04


Date: Fri, 10 Sep 2004 09:55:43 +0200


Mailman wrote:
> Felix Tiede wrote:
>
>>A good firewall should signal to the sender, that the port is either
>>closed or communication is prohibited. Otherwise the sender can be sure,
>>that there is something and it's trying its best to conceal itself. If a
>>system should be hidden from the net, the last router before this system
>>should send a "destination host unreachable".
>>The difference between Kerio 2.1.5 and 4.x may be, that the latter uses
>>TCP RST packets to signal a closed port (which is almost equal to ICMP 3).
>>If there are *no* packets sent back to the DNS, the firewall doesn't obey
>>the RFCs regarding these cases, which is development in the wrong
>>direction.
>
>
> In principle your analysis is almost correct, with one small error: there is
> little chance of answering with a TCP RST to a UDP packet (he was talking
> about DNS, which is - mostly - UDP).
>
> Some firewalls make a virtue out of sending no reply, and they even invented
> a new term for it: "stealth". This may be great for a marketing brochure,
> but is quite useless in the real world, especially if you have any service
> at all open on your machine, with any protocol. Even worse, this breaks
> some RFC's - not that that ever stopped the marketroids.

Yes, you're right, I've missed that point. So Kerio has also made the step
to use this famous but almost completely useless "stealth" feature. One more
point to the list of reasons why I'm happy to stick with Kerio 2.1.5...

Greetings,
Felix






Relevant Pages

  • Re: Any suggestions?
    ... trying to get the Kerio program to recognize the proxy browser, ... We have scanned your system for open ports and for ports visible to others ... > "Firewall" tab to "Ask Me First". ... > then see the five or six default rules supplied by Kerio. ...
    (comp.security.firewalls)
  • Re: how to on firewall
    ... I have Kerio. ... The firewall frequently alerts. ... Certain web sites and/or web pages won't load because of blocking ...
    (alt.computer.security)
  • Re: Attack detection in Kerio PF
    ... The closest I get is seeing the arrow in my system tray icon ... >>indicates outgoing packets. ... Your firewall was blocking the outgoing packets. ... Kerio kept asking for permissions after I ...
    (comp.security.firewalls)
  • Re: Attack detection in Kerio PF
    ... The closest I get is seeing the arrow in my system tray icon ... >>indicates outgoing packets. ... Your firewall was blocking the outgoing packets. ... Kerio kept asking for permissions after I ...
    (comp.security.firewalls)
  • Re: Free Firewalls: ZoneAlarm vs Tiny Personal Firewall
    ... including with the firewall and Windoz. ... Try same tests with Kerio Firewall 2.1.4 ... > Tiny and Kerio have almost identical user interfaces. ... ZoneAlarm gives a warning from maybe almost every suspicious packet, ...
    (comp.security.firewalls)

Quantcast