republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » The Site » Old Forums » Kerio - Tiny Support » Tiny to Kerio Rules
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Error Message - MacTransferData:Invalid Buffer Tag »
« Simple loopback solution for software proxy users  
AuthorAll Replies


BlitzenZeus
Burnt Out Cynic
Premium,MVM
join:2000-01-13
Beaverton, OR
·Verizon FIOS
·Verizon Online DSL

reply to bjf123
Re: Tiny to Kerio Rules

Is your computer running as a DHCP server? If not you shouldn't allow local: udp 67 connections as then you are acting as the server.

I allow 8085, and 8086 for DSLR's tweak test. If I don't the results are not accurate. I could secure those two ports to the testing address, but they are also used for another DSLR test. I'm only worried about the higher port ranges, and in this config you will have to permit each ftp request by your browser. I prefer it this way instead of allow them access to higher ports for no reason.

I see your still working on some rules like your icmp, etc..

Your next step for some apps is making rules for certain addresses only.... Do those when the programs only communicate out to only one, or two addresses if you need to. However some programs are fine being allow to any address since they are hard-coded to certain addresses anyway. Its obvious that browsers need access to any address, but here is where its up to you to make those judgements.
--
"Yesterday we obeyed kings, and bent our necks before emperors. But today we kneel only to the truth." -Kahlil Gibran


bjf123
We Want... A Shrubbery
Premium
join:2000-02-11
Cincinnati, OH
clubs:
·Cincinnati Bell

said by BlitzenZeus:
Is your computer running as a DHCP server? If not you shouldn't allow local: udp 67 connections as then you are acting as the server.
I'm not running a DHCP server, that I know of. I just know that without the rules for ports 67 and 68, both local and remote, I lose my DSL connection after about 15 minutes. Does that make sense?
quote:
Your next step for some apps is making rules for certain addresses only.... Do those when the programs only communicate out to only one, or two addresses if you need to. However some programs are fine being allow to any address since they are hard-coded to certain addresses anyway. Its obvious that browsers need access to any address, but here is where its up to you to make those judgements.
I've gone back through all my apps that connect out, deleted the rules, and tried to connect again. This time, in addition to specifying the remote port, I also specified the IP address. Most apps just seem to want one address. Some wanted multiple addresses, but usually within a range, like 123.456.789.0 to 123.456.789.255, so I put that range in the rule. What's the difference between using a range and a mask? For AOL and CompuServe (I know those are bad words around here!), I needed two rules each, as they seem to access multiple ranges that belong to AOL, according to the Whois lookup I did. One app, Quicken, needed to access multiple IPs as part of the downloading of my financial data from various banks and credit card companies. There, I ended up with an "any address" rule. Otherwise, I would have 6 to 10 rules, which I thought was overkill. Wouldn't you agree?

I haven't had a chance to get back to the ICMP rules. Had to take a break to go watch my Alma Mater (Xavier) win their conference basketball tournament!
--
Golf is a relatively simple game, played by reasonably intelligent people, stupidly.
Forums » The Site » Old Forums » Kerio - Tiny SupportError Message - MacTransferData:Invalid Buffer Tag »
« Simple loopback solution for software proxy users  


Wednesday, 10-Feb 04:13:11 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10.5 years online! © 1999-2010 dslreports.com.
page compression OFF
Most commented news this week
· [91] Verizon Wireless, Meet 4Chan
· [88] FBI Revamps Push For Two Year ISP Log Retention
· [72] Comcast Xfinity Rebranding Largely Laughed At
· [39] When MetroPCS Says 'No Contract,' They Mean 'Contract'
· [31] Instat: Average Connection is 7.12 Mbps
· [30] Fairpoint Files Bankruptcy Plan
· [23] Duh: Billing Companies Think Metered Billing 'Inevitable'
· [21] Google Lowers Nexus One ETF, Launches Phone Support
· [20] Cox Offers Free PS3s To Entire State Of Arizona
· [19] Qwest Still Shopping Itself Around
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· ADSL-CO/2009-261 Case update.... [TekSavvy]
· Love is in the Air-Lovely Charm Bracelet [World of Warcraft]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Microsoft Security Bulletin(s) for February 9, 2010 [Security]
· Ashen Verdict Rep farming guide (ICC 10) [World of Warcraft]
· [Info] Microsoft Patch Tuesday - Huge Security Update on 02/09/2 [Microsoft Help]
· Best Routing Protocol [Wireless Service Providers]
· Advice for a friend! Help, electricity usage (Insane) [Home Repair & Improvement]
· WRT320N vs WRT610N [Linksys]