I realize that some here are of the opinion that effective outbound
protection on a Windows system is impossible and that all PFWs are
useless. That aside...

I still see people recommending Sygate's PFW and Kerio 2.1.5. It
doesn't seem prudent to me to use security software that hasn't been
updated in a long time.

At approximately the same time (middle/end of 2005) Kerio was sold to
Sunbelt, Sygate was sold to Symantec and development of some DiamondCS
product(s) (ProcessGuard?) stopped.

Was some major flaw in these products disclosed at that time?

Given that any PFW is of value, is it wise to run PFWs that have long
since been supported?

It is possible to have effective outbound protection using kerio 2.15 and
/ or sygate.Not 100% of course ...but every little helps.I personally
prefer kerio 2.15.Volker and cohorts of course suggest otherwise ,and
prefer the puritanical approach ,which in laboratory conditions or being
members of the said families ..may suffice.The choice is yours...suck it
and see ;)
I'm still using an old Sygate on my desktop and Windows
Firewall on my laptop which is often used wirelessly.

I'm not really happy with either solution even though at
home I run a NAT router.

Why do you prefer Kerio over Sygate?



I have a couple of questions. Why do some people think they need to
update their PFW? If it used to work, why do you think it won't work

The argument that a PFW is just a packet filter is correct, isn't that
what all firewalls are? They examine packets of data that are sent or
received and filter out the "bad" ones according to rules you have
set. Am I missing something here?

Subscribing to updates for an antiviral program makes sense, viruses
change and the writers come up with better ways to implant their
malware. But if your PFW can tell which program exactly is attempting
to send packets, then isn't it doing what you want it to do?


