republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » The Site » Old Forums » Kerio - Tiny Support » [Kerio 2.x] My Kerio 2.1.5 rules based on BZ's please critique
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
[Kerio 2.x] Rule 'Packet to unopened port received': Permitted »
« [Kerio 4.x] How to make Kerio old approve internet related pro  
AuthorAll Replies

Lilla1

join:2002-04-22
Fall City, WA


1 edit
reply to ghost16825
Re: [Kerio 2.x] My Kerio 2.1.5 rules based on BZ's

said by ghost16825 See Profile:
I have to say this is one of the better rulesets I have seen. There's not very much to criticise in it. Regardless, now that you seem pretty happy with it, it's important to see where the weakest parts are even if there's nothing you can do to restrict the rule further.

I'm delighted that you like my rule set (work in progress), I give credit to BZ's wonderful rule set. I endevor to follow the lead of those that understand firewalls, because most of it is greek to me.

said by ghost16825 See Profile:

Some people end their local port range at 4999 instead of 5000. (1024-4999) because of SSDP Discovery Service. (Incoming->5000). Do so if it makes you feel any safer.

I used 1024-5000 because that's what BZ uses in his rule set, and because I have disabled UPnP and SSDP. Still I suppose I could use 1024-4999 as an added safety net.

Below is some discussion that relates to this:

BZ 2003-09-22 00:32:21
Q: I notice on your rule set that you have ports 135, 445 and 500?? for xp services block. Is it 500 or 5000?
BZ: Its 500, and 5000(UPnP) is easily turned off, it’s not even as huge as a threat as it was made out to be. However you could add 5000 to that list, but once you do the task below, it won't be listening anymore. You don't even need those services.

Start -> Run: services.msc
In the properties of these services, stop, and disable them. SSDP Discovery Protocol, and Universal Plug n' Pray.

said by ghost16825 See Profile:

3. See if you can come up with a list of IP addresses for Spybot.

Good idea. Done.

said by ghost16825 See Profile:

I would take off your local port range for explorer(block) and perhaps make it both UDP/TCP both directions, just for the sake of it.

Good idea. Done.

Thanks for all the ideas you gave me, some I am still thinking about.

Lilla
Forums » The Site » Old Forums » Kerio - Tiny Support[Kerio 2.x] Rule 'Packet to unopened port received': Permitted »
« [Kerio 4.x] How to make Kerio old approve internet related pro  


Tuesday, 08-Dec 22:51:59 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [193] Sprint Sued For Distracted Driving Death
· [81] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [62] Sprint Poised For A Turnaround?
· [50] The Future Of Wi-Fi Is Bright
· [48] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [44] Microwaving Your Innards Is Not 'Extreme'
· [39] Verizon LTE: 5-12 Mbps Downstream
· [18] AT&T Releases Network Reporting iPhone App
Most people now reading
· Comcast refused to install 400' feet. [Comcast HSI]
· ICC Strats??? [World of Warcraft]
· Man Downloads Child Porn "Accidentally," Faces 20 Years [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· Servers UP!!! [World of Warcraft]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Microsoft Security Bulletin(s) for December 8, 2009 [Security]
· Need some wiring help, quick! Drywall goes up tomorrow. [Canadian Chat]