Can I trust it

G

Guest

Guest
Archived from groups: rec.games.computer.ultima.dragons (More info?)

OK, now I've installed a broadband router with a 4p switch(SMC Barricade).
It comes with a firewall, which I have enabled.

Now for the all-important-question. Is this enough, or do I need a SW
firewall as well. I have the ZoneAlarm Pro but since I no longer have a
dedictated NIC for internet access, it's not possible to discriminate
between the trusted and the internet zones.

Advice?

pibbur
--
Using Opera's revolutionary e-mail client: http://www.opera.com/mail/
 
G

Guest

Guest
Archived from groups: rec.games.computer.ultima.dragons (More info?)

Words to the wise, pibbur <oopsREMOVETHISANDxx.000xx@tele2xx.xxno>
wrote:

>OK, now I've installed a broadband router with a 4p switch(SMC Barricade).
>It comes with a firewall, which I have enabled.
>
>Now for the all-important-question. Is this enough, or do I need a SW
>firewall as well. I have the ZoneAlarm Pro but since I no longer have a
>dedictated NIC for internet access, it's not possible to discriminate
>between the trusted and the internet zones.
>
>Advice?

Install Kerio the free version, and just allow your programs to go
outside which should go outside and also receive traffic, block all
the rest. The "zone" idea is definitely not usable in my opinion.
 
G

Guest

Guest
Archived from groups: rec.games.computer.ultima.dragons (More info?)

On Thu, 19 May 2005 20:42:28 +0200, Claus Dragon
<claus@ultima-dragons.org> wrote:

>Words to the wise, pibbur <oopsREMOVETHISANDxx.000xx@tele2xx.xxno>
>wrote:
>
>>OK, now I've installed a broadband router with a 4p switch(SMC Barricade).
>>It comes with a firewall, which I have enabled.
>>
>>Now for the all-important-question. Is this enough, or do I need a SW
>>firewall as well. I have the ZoneAlarm Pro but since I no longer have a
>>dedictated NIC for internet access, it's not possible to discriminate
>>between the trusted and the internet zones.
>>
>>Advice?
>
>Install Kerio the free version, and just allow your programs to go
>outside which should go outside and also receive traffic, block all
>the rest. The "zone" idea is definitely not usable in my opinion.

I agree. HW firewalls are a good 1st defense but they don't stop trojans
or other stuff that might get onto your computer from illicitly
communicating out with your private data.

--
The Polychromic Dragon of the -=={UDIC}==-
http://home.comcast.net/~macecil/
http://home.comcast.net/~safehex/
RGCUD Photo Gallery: http://home.comcast.net/~rgcud/
 
G

Guest

Guest
Archived from groups: rec.games.computer.ultima.dragons (More info?)

On Thu, 19 May 2005 23:13:56 +0200, Polychromic <macecil@comcast.net>
wrote:

> On Thu, 19 May 2005 20:42:28 +0200, Claus Dragon
> <claus@ultima-dragons.org> wrote:
>
>> Words to the wise, pibbur <oopsREMOVETHISANDxx.000xx@tele2xx.xxno>
>> wrote:
>>
>>> OK, now I've installed a broadband router with a 4p switch(SMC
>>> Barricade).
>>> It comes with a firewall, which I have enabled.
>>>
>>> Now for the all-important-question. Is this enough, or do I need a SW
>>> firewall as well. I have the ZoneAlarm Pro but since I no longer have a
>>> dedictated NIC for internet access, it's not possible to discriminate
>>> between the trusted and the internet zones.
>>>
>>> Advice?
>>
>> Install Kerio the free version, and just allow your programs to go
>> outside which should go outside and also receive traffic, block all
>> the rest. The "zone" idea is definitely not usable in my opinion.
>
> I agree. HW firewalls are a good 1st defense but they don't stop trojans
> or other stuff that might get onto your computer from illicitly
> communicating out with your private data.
>
OK, thanks for the advice.

Poly - you don't know it, but - you ARE my guru regarding PC HW/Windows. I
will try Kerio as adviced by the respectable Claus, but I haven't heard
anything about it. Have you any recommendations?

pibbur


--
Using Opera's revolutionary e-mail client: http://www.opera.com/mail/
 
G

Guest

Guest
Archived from groups: rec.games.computer.ultima.dragons (More info?)

On Fri, 20 May 2005 08:43:29 GMT, pibbur
<oopsREMOVETHISANDxx.000xx@tele2xx.xxno> wrote:

>On Thu, 19 May 2005 23:13:56 +0200, Polychromic <macecil@comcast.net>
>wrote:
>
>OK, thanks for the advice.
>
>Poly - you don't know it, but - you ARE my guru regarding PC HW/Windows. I
>will try Kerio as adviced by the respectable Claus, but I haven't heard
>anything about it. Have you any recommendations?

Kerio 2.15 is the one I use. It's lightweight and allows me to explicitly
create the rules I need. It takes a bit of configuring - start with the
basic rule set and add a rule to "block everything" to the bottom. Then
each time you set up a new approved application, toggle off the "block
everything" rule and it will prompt you through creating a rule for the
new app. Once each new rule is made you can toggle the "block everything"
rule back on.

If you need it, I can go into detail on my own rules.

--
The Polychromic Dragon of the -=={UDIC}==-
http://home.comcast.net/~macecil/
http://home.comcast.net/~safehex/
RGCUD Photo Gallery: http://home.comcast.net/~rgcud/
 
G

Guest

Guest
Archived from groups: rec.games.computer.ultima.dragons (More info?)

On Fri, 20 May 2005 11:52:34 +0200, Polychromic <macecil@comcast.net>
wrote:

> On Fri, 20 May 2005 08:43:29 GMT, pibbur
> <oopsREMOVETHISANDxx.000xx@tele2xx.xxno> wrote:
>
>> On Thu, 19 May 2005 23:13:56 +0200, Polychromic <macecil@comcast.net>
>> wrote:
>>
>> OK, thanks for the advice.
>>
>> Poly - you don't know it, but - you ARE my guru regarding PC
>> HW/Windows. I
>> will try Kerio as adviced by the respectable Claus, but I haven't heard
>> anything about it. Have you any recommendations?
>
> Kerio 2.15 is the one I use. It's lightweight and allows me to
> explicitly
> create the rules I need. It takes a bit of configuring - start with the
> basic rule set and add a rule to "block everything" to the bottom. Then
> each time you set up a new approved application, toggle off the "block
> everything" rule and it will prompt you through creating a rule for the
> new app. Once each new rule is made you can toggle the "block
> everything"
> rule back on.
>
> If you need it, I can go into detail on my own rules.
>
If it's not too much trouble, I'd like that.

pibbur


--
Using Opera's revolutionary e-mail client: http://www.opera.com/mail/
 
G

Guest

Guest
Archived from groups: rec.games.computer.ultima.dragons (More info?)

On Fri, 20 May 2005 10:17:08 GMT, pibbur <oopsREMOVETHISANDxx.000xx@tele2xx.xxno> wrote:

>On Fri, 20 May 2005 11:52:34 +0200, Polychromic <macecil@comcast.net>
>wrote:

>> Kerio 2.15 is the one I use. It's lightweight and allows me to
>> explicitly
>> create the rules I need. It takes a bit of configuring - start with the
>> basic rule set and add a rule to "block everything" to the bottom. Then
>> each time you set up a new approved application, toggle off the "block
>> everything" rule and it will prompt you through creating a rule for the
>> new app. Once each new rule is made you can toggle the "block
>> everything"
>> rule back on.
>>
>> If you need it, I can go into detail on my own rules.
>>
>If it's not too much trouble, I'd like that.

Hmmm, I guess I will make my linelength longer so my table stays nice. I hope
your newsreader can do >80 chars and handles tabs okay.

Okay, after you install Kerio 2.15 <http://www.kerio.com/dwn/kpf2-en-win.exe>
it will want to reboot. After that, it you should have a little blue shield
icon in the systray. Right click on that and choose administration, then
click on the advanced button to get to the screen where you can enter the rules.
If you want the manual, you can get it here: http://eu.download.kerio.com/dwn/kpf/kpf21-en-v1.pdf.
Also, a very useful FAQ is here: http://www.dslreports.com/faq/security/2.5.1.%20Kerio%20and%20pre-v3.0%20Tiny%20PFW

Since I use a rule to block everything, I only add rules for things I want to allow.
Remember, rule order is critical - the rules at the top are followed first. That's why the
catchall "block everything" rule is last.

Rule name Protocol Dir Local Port Remote IP Remote Port Application
========= ======== === ========== ========= =========== ===========
Loopback udp/tcp both any 127.0.0.1 any any
(standard loopback rule).
DNS 1 udp both any (DNS server IP) 53 any
DNS 2 udp both any (DNS server IP) 53 any
(allow PC connect to DNS servers).
DHCP server/router udp both 68 192.168.1.1 67 any
DHCP broadcast udp out 68 255.255.255.255 67 any
(allow PC to get DHCP lease from server or router - replace 192.168.1.1 as needed).
Ping (outgoing) ICMP 8 out any any any any
Ping (reply) ICMP 0 both any any any any
(some online games, websites, ftp, etc need ping to work.)
Tracert (incoming) ICMP 11 in any any any any
(if you want to be able to run tracert).
LSA Shell (Kerberos) udp both any any 88 c:\windows\system32\lsass.exe
LDAP (Winlogon) tcp out any any 389 c:\windows\system32\winlogon.exe
LSA Shell (LDAP) udp both any any 389 c:\windows\system32\lsass.exe
Userinit Logon (LDAP) tcp out any any 389 c:\windows\system32\userinit.exe
Microsoft-DS tcp out any any 445 system
Gen Host Prc for W32 udp/tcp out any any any c:\windows\system32\svchost.exe
Gen Host Prc for W32 udp in any any any c:\windows\system32\svchost.exe
App Layer Gateway tcp out any any 21 c:\windows\system32\alg.exe
NTP Time Sync udp both 123 any 123 c:\windows\system32\svchost.exe
(various Windows processes that need to work).
<apps follow here>
Eudora tcp out any any 110,25,995,465 c:\program files\eudora\eudora.exe
..
.. etc
..
Firefox tcp out any any 80,443 c:\program files\firefox\firefox.exe
<final and most important rule>
Block all any both any any any any <-set to deny

That's it for my basic rules. Obviously there are more bells and whistles on KPF to figure out though.

--
The Polychromic Dragon of the -=={UDIC}==-
http://home.comcast.net/~macecil/
http://home.comcast.net/~safehex/
RGCUD Photo Gallery: http://home.comcast.net/~rgcud/
 
G

Guest

Guest
Archived from groups: rec.games.computer.ultima.dragons (More info?)

On Fri, 20 May 2005 06:55:02 -0500, Polychromic <macecil@comcast.net>
wrote:

>Okay, after you install Kerio 2.15 <http://www.kerio.com/dwn/kpf2-en-win.exe>
>it will want to reboot. After that, it you should have a little blue shield

Also, if you want to kill the splash screen you can either use a resource
editor like ResHack or get the program here:
http://www.brightnova.com/kpf/ to do that for you.

--
The Polychromic Dragon of the -=={UDIC}==-
http://home.comcast.net/~macecil/
http://home.comcast.net/~safehex/
RGCUD Photo Gallery: http://home.comcast.net/~rgcud/
 
G

Guest

Guest
Archived from groups: rec.games.computer.ultima.dragons (More info?)

On Fri, 20 May 2005 13:55:02 +0200, Polychromic <macecil@comcast.net>
wrote:

> On Fri, 20 May 2005 10:17:08 GMT, pibbur
> <oopsREMOVETHISANDxx.000xx@tele2xx.xxno> wrote:
>
>> On Fri, 20 May 2005 11:52:34 +0200, Polychromic <macecil@comcast.net>
....
> That's it for my basic rules. Obviously there are more bells and
> whistles on KPF to figure out though.
>

Thank you very much.

pibbur

--
Using Opera's revolutionary e-mail client: http://www.opera.com/mail/
 
G

Guest

Guest
Archived from groups: rec.games.computer.ultima.dragons (More info?)

On Fri, 20 May 2005 12:05:01 GMT, pibbur
<oopsREMOVETHISANDxx.xx000@tele2xx.xxno> wrote:

>On Fri, 20 May 2005 13:55:02 +0200, Polychromic <macecil@comcast.net>
>wrote:
>
>> On Fri, 20 May 2005 10:17:08 GMT, pibbur
>> <oopsREMOVETHISANDxx.000xx@tele2xx.xxno> wrote:
>>
>>> On Fri, 20 May 2005 11:52:34 +0200, Polychromic <macecil@comcast.net>
>...
>> That's it for my basic rules. Obviously there are more bells and
>> whistles on KPF to figure out though.
>>
>
>Thank you very much.

Welcome. Let us know how you like it.

--
The Polychromic Dragon of the -=={UDIC}==-
http://home.comcast.net/~macecil/
http://home.comcast.net/~safehex/
RGCUD Photo Gallery: http://home.comcast.net/~rgcud/
 
G

Guest

Guest
Archived from groups: rec.games.computer.ultima.dragons (More info?)

Words to the wise, Polychromic <macecil@comcast.net> wrote:

>On Fri, 20 May 2005 06:55:02 -0500, Polychromic <macecil@comcast.net>
>wrote:
>
>>Okay, after you install Kerio 2.15 <http://www.kerio.com/dwn/kpf2-en-win.exe>
>>it will want to reboot. After that, it you should have a little blue shield
>
>Also, if you want to kill the splash screen you can either use a resource
>editor like ResHack or get the program here:
>http://www.brightnova.com/kpf/ to do that for you.

host not found?
 
G

Guest

Guest
Archived from groups: rec.games.computer.ultima.dragons (More info?)

On Fri, 20 May 2005 16:38:22 +0200, Claus Dragon
<claus@ultima-dragons.org> wrote:

> Words to the wise, Polychromic <macecil@comcast.net> wrote:
>
>> On Fri, 20 May 2005 06:55:02 -0500, Polychromic <macecil@comcast.net>
>> wrote:
>>
>>> Okay, after you install Kerio 2.15
>>> <http://www.kerio.com/dwn/kpf2-en-win.exe>
>>> it will want to reboot. After that, it you should have a little blue
>>> shield
>>
>> Also, if you want to kill the splash screen you can either use a
>> resource
>> editor like ResHack or get the program here:
>> http://www.brightnova.com/kpf/ to do that for you.
>
> host not found?

Don't know why, but I had no problem connecting.

If I were you I would of course take this personnally.

pibbur
 
G

Guest

Guest
Archived from groups: rec.games.computer.ultima.dragons (More info?)

Words to the wise, pibbur <oopsREMOVETHISANDxx.000xx@tele2xx.xxno>
wrote:

>> host not found?
>
>Don't know why, but I had no problem connecting.
>
>If I were you I would of course take this personnally.

I try to give people and things a second chance :)
 
G

Guest

Guest
Archived from groups: rec.games.computer.ultima.dragons (More info?)

On Mon, 23 May 2005 01:38:49 +0200, Claus Dragon
<claus@ultima-dragons.org> wrote:

> Words to the wise, pibbur <oopsREMOVETHISANDxx.000xx@tele2xx.xxno>
> wrote:
>
>>> host not found?
>>
>> Don't know why, but I had no problem connecting.
>>
>> If I were you I would of course take this personnally.
>
> I try to give people and things a second chance :)

A second change at pestering you?

pibbur the misanthrope

--
Using Opera's revolutionary e-mail client: http://www.opera.com/mail/
 
G

Guest

Guest
Archived from groups: rec.games.computer.ultima.dragons (More info?)

Words to the wise, pibbur <oopsREMOVETHISANDxx.000xx@tele2xx.xxno>
wrote:

>> I try to give people and things a second chance :)
>
>A second change at pestering you?

Even that, sometimes.