kerio 2.1.5 (last freeware version), strange behaviour, related to port logger and svchost.exe

kerio 2.1.5 (last freeware version), strange behaviour, related to port logger and svchost.exe

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
kerio 2.1.5 (last freeware version), strange behaviour, related to port logger and svchost.exe q_q_anonymous 07-31-2006
Posted by on July 31, 2006, 11:51 am
If you were  Registered and logged in, you could reply and use other advanced thread options
i'm trying kerio out, it seems to have a bad port logger. not picking
up smtp or pop. I wonder if sygate would've seen it. (ethereal sees it)
Why should kerio miss that out? How is it deciding what to miss out?


Sometimes when browsing , page weren't loading up, a little red arrow
flashes on the icon.

I disabled kerio and immediately the page loaded up.

I opened the port logger and then went to logs..firewall log, to see
what it was blocking.
(unlike sygate, it doesn't include blocked connections in the scren of
the port logger. It's elsewhere)

I saw it had blocked " SSDP " - particularly. There was Listening on
my machine 192.168.14.4:1900 svchost.exe , it was blocking incoming
connections from my "NAT router" 192.168.1.1:20xy: to my machine.

I thought PFWs didn't block svchost.exe Anyhow, even after adding a
rule to allow my router to connect to me (from any port) to me @ 1900,
I was still getting red arrows and inaccessible and a list of SSDP
blocked. I haven't noticed a problem loading up pages though.
I then noticed, that amongst all the ALLOWED including allowed for
outgoing svchost.exe, there was a deny for incoming to my port 1900 -
svchost.exe.

Is it using a strict policy - white list. Or a black list. It looks
like a "white list", many svchost.exe rules allowed. But I've just seen
an explicit rule to *deny* SSDP incoming - from any ip any port onto my
machine's port 1900. If it's a whitelist, why should it be necessary
to say that? And isn't it a silly thing to deny anyway, it should be
permitted in the white list! I have amended it to permit it from my
router any port. to my comp port 1900.

If only sygate was fixed. It kicks kerio to pluto. Is there any way to
nullify whatever security problem sygate has with the open windows?!!


Actually, on trying to post this, Kerio gave 2 flashes of a red arrow
poitning upwards, like giving me the finger. And it fails to post.
Listing nothing under blocked. disabling kerio lets me send this
post!! I guess that problem is unique, but the rest probably are
typical.


Posted by Kerodo on July 31, 2006, 5:38 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
q_q_anonymous@yahoo.co.uk says...
> i'm trying kerio out, it seems to have a bad port logger. not picking
> up smtp or pop. I wonder if sygate would've seen it. (ethereal sees it)
> Why should kerio miss that out? How is it deciding what to miss out?
>
>
> Sometimes when browsing , page weren't loading up, a little red arrow
> flashes on the icon.
>
> I disabled kerio and immediately the page loaded up.
>
> I opened the port logger and then went to logs..firewall log, to see
> what it was blocking.
> (unlike sygate, it doesn't include blocked connections in the scren of
> the port logger. It's elsewhere)
>
> I saw it had blocked " SSDP " - particularly. There was Listening on
> my machine 192.168.14.4:1900 svchost.exe , it was blocking incoming
> connections from my "NAT router" 192.168.1.1:20xy: to my machine.
>
> I thought PFWs didn't block svchost.exe Anyhow, even after adding a
> rule to allow my router to connect to me (from any port) to me @ 1900,
> I was still getting red arrows and inaccessible and a list of SSDP
> blocked. I haven't noticed a problem loading up pages though.
> I then noticed, that amongst all the ALLOWED including allowed for
> outgoing svchost.exe, there was a deny for incoming to my port 1900 -
> svchost.exe.
>
> Is it using a strict policy - white list. Or a black list. It looks
> like a "white list", many svchost.exe rules allowed. But I've just seen
> an explicit rule to *deny* SSDP incoming - from any ip any port onto my
> machine's port 1900. If it's a whitelist, why should it be necessary
> to say that? And isn't it a silly thing to deny anyway, it should be
> permitted in the white list! I have amended it to permit it from my
> router any port. to my comp port 1900.
>
> If only sygate was fixed. It kicks kerio to pluto. Is there any way to
> nullify whatever security problem sygate has with the open windows?!!
>
>
> Actually, on trying to post this, Kerio gave 2 flashes of a red arrow
> poitning upwards, like giving me the finger. And it fails to post.
> Listing nothing under blocked. disabling kerio lets me send this
> post!! I guess that problem is unique, but the rest probably are
> typical.
>
>

How Kerio 2.1.5 works or doesn't work is totally dependant upon your
rule set. If something's not working, then your rules are to blame. As
a starting point, you might try BZ's rules. You can find them here:

http://www.dslreports.com/forum/remark,8023708

Read the thread and download the rule set and then modify them to suit
your own personal needs. Kerio 2 is great if you know what you're
doing, but if you don't, you can create a complete mess..

--
Kerodo

Similar ThreadsPosted
strange firewall behaviour March 19, 2005, 10:08 pm
Strange firewall behaviour April 13, 2006, 4:10 am
Trouble - Strange behaviour on VPN to China May 4, 2006, 10:29 am
freeware 'Internet Security' (firewall+anti virus) pack home version, Windows XP September 26, 2006, 3:20 pm
Unknown svchost.exe DNS port 53 network activity December 20, 2006, 4:09 pm
Strange port 20/21 problem with Netgear RT314 Router November 27, 2005, 12:14 am
Trojan / logger? September 19, 2006, 6:31 am
IP Tables related error July 8, 2005, 11:21 pm
Related to security projects July 31, 2008, 8:21 am
IPtables(time related options) July 2, 2005, 4:54 am

The site map in XML format XML site map

Contact Us | Privacy Policy