CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Is ok to block 2 internal addresses of the pc in kerio?

 
Post new topic   Reply to topic       All -> FavForums -> Sunbelt KerioPF [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
IP: 83.39.*.*

Guest






PostPosted: Sat Oct 28, 2006 1:24 pm    Post subject: Is ok to block 2 internal addresses of the pc in kerio?
Reply with quote

Hello,

I´ve created two rules for kerio, since I receive many connections from these two addresses, and maybe they are not legit,

remote: 127.0.0.1
direction both deny

remote 255.255.255.255
direction both deny

there was a day I received the connection from the remote address 255.255.255.255, continously, and I thought that it was not very normal

and for the 127.0.0.1, I get it mostly when I connect to a web browser, mozilla or ie,

notice that they are remote connections, not local, is for that reason that I have denied, since I know that they are internals addresses from the pc

am I doing right creating these rules?

Thanks and greetz

Back to top
Graham1

Captain
Captain


Joined: Dec 21, 2005
Posts: 340


PostPosted: Sat Oct 28, 2006 5:42 pm    Post subject:
Reply with quote

I would allow both these rules Smile.

Loopback rules (127.0.0.1) are required by many applications (i.e Firefox, Internet Explorer, etc). Although this address appears as remote, it will only appear from your computer (not another computer). When creating a loopback rule, remember to remove the port number (as this will change often).

Your second rule (255.255.255.255) is some kind of broadcast. Guessing, I would say from a DHCP server. Do these ports appear as 67 and 68? If so, then I would allow (as this gives you your IP address). If not, post back with the port numbers.

Hope this helps.

Smile

Back to top
View users profile Send private message
IP: 66.98.*.*

Guest






PostPosted: Thu Nov 02, 2006 2:17 pm    Post subject:
Reply with quote

so then these connections when I open firefox are correct?

local point: 0.0.0.0:1159 remote: 127.0.0.1, port 1158 outgoing tcp
local point 0.0.0.0:1161 remote:127.0.0.1, port 1160 outgoing tcp

The strange thing is that the 255.255.255.255 address sometimes doesn´t show at all, and many times shows in the right moment I connect, I connect through a modem not by a router, so I´m not sure if in this case I connect throuht a DHCP server...... I guess that this connection from 255.255.255.255 would have to show every time I connect, and in ocassions doesn´t show at all

well, I´m going to remove that rule denying loopback then, thanks for answering Wink

Back to top
Graham1

Captain
Captain


Joined: Dec 21, 2005
Posts: 340


PostPosted: Thu Nov 02, 2006 5:30 pm    Post subject:
Reply with quote

Anonymous wrote:
so then these connections when I open firefox are correct?

local point: 0.0.0.0:1159 remote: 127.0.0.1, port 1158 outgoing tcp
local point 0.0.0.0:1161 remote:127.0.0.1, port 1160 outgoing tcp


I would say so. The port numbers (local and remote) will always change. Locally, anything after 1024 (depending on services running) and the protocol will always be TCP (this seems similar to a proxy setting). Usually, loopback addresses are UDP (that I've noticed).

Quote:
The strange thing is that the 255.255.255.255 address sometimes doesn´t show at all, and many times shows in the right moment I connect, I connect through a modem not by a router, so I´m not sure if in this case I connect throuht a DHCP server...... I guess that this connection from 255.255.255.255 would have to show every time I connect, and in ocassions doesn´t show at all


As mentioned, check the port number(s). This will indicate which service (i.e DHCP) that is being addressed. If your not using a static IP then you will be accessing a DHCP from somewhere (probably your ISP).

Smile

Back to top
View users profile Send private message
IP: 80.39.*.*

Guest






PostPosted: Fri Nov 03, 2006 1:42 am    Post subject:
Reply with quote

I see, then I´m using DHCP, since my ip is dinamic

Thanks for your help Very Happy

Back to top
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Sunbelt KerioPF All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer