| View previous topic :: View next topic |
| Author |
Message |
f6030ltd
Cadet

 Joined: Jul 03, 2007 Posts: 8 Location: UK
|
Posted: Tue Jul 03, 2007 3:52 pm Post subject: Upgraded to Sunbelt from Kerio - broken proxy ! |
|
|
As strap line.
Am now running Sunbelt (System Service 4.5.916.0).
My proxy (privoxy) has served me well. Trouble is that I canot access the web through my browsers (Opera and Firefox) now. Unless I direct connect instead of going through privoxy. As it is both browsers and the only change is the firewall it has to be related to the firewall I think.
Privoxy runs on same machine BTW.
O/S is Win XP Pro Sp2+
This is not good.
the install seems to have ported over all my rules etc. and privoxy has greem tricks across the board in the rules.
Am stumped - any clues for resolution/diagnosis please ?
I swear I did not change anything else ( I know everyone says that..).
TIA
Steve
|
|
| Back to top |
|
 |
f6030ltd
Cadet

 Joined: Jul 03, 2007 Posts: 8 Location: UK
|
Posted: Wed Jul 04, 2007 9:48 am Post subject: |
|
|
I unclicked "Enable Network security module" In
Network Security -> Applications and privoxy get invoked and works fine.
So it it looks like it is the sungate firewall which is denying my proxy.
So I suppose the only question is this an under the covers feature that canniot be fixed or is it in the rules. As the rules are ported by Sungate upon upgrade from my previous working Kerio setup the question is somewhat important.
Running with no Network security enabled in a firewall is a waste of time IMV.
Anyone ? ?
|
|
| Back to top |
|
 |
f6030ltd
Cadet

 Joined: Jul 03, 2007 Posts: 8 Location: UK
|
Posted: Wed Jul 04, 2007 11:18 am Post subject: |
|
|
failing a fix where can get the last version of the Kerio firewall so I can back level to a fully functioning configuration ?
|
|
| Back to top |
|
 |
Graham1
Captain

 Joined: Dec 21, 2005 Posts: 340
|
|
| Back to top |
|
 |
f6030ltd
Cadet

 Joined: Jul 03, 2007 Posts: 8 Location: UK
|
Posted: Thu Jul 05, 2007 10:04 am Post subject: |
|
|
Thanks for response.
I see your point - is it a known problem that the Sunbelt version does not translate existing rules correctly ?
Starting from scratch woul be a right pain - have packet filtering rules and lots of application control rules etc etc. Would take me best part of a day re-run everything to set up the rules as they are now and it would be hard to guyrantee they woul be complete even then. they are just not being obeyed as they they should be.
I did export the ruleset from kerio version before the upgrade so to hget back functionality all I need to do is re-install the kerio firewall and import my saved ruleset.
The kerio version seems the way to go - would stay with that and wait for an update to two to have happened to Sunbelt before trying the upgrade again then.
|
|
| Back to top |
|
 |
chimplyirresistible
Private

 Joined: Jun 06, 2007 Posts: 38 Location: USA
|
Posted: Thu Jul 05, 2007 2:24 pm Post subject: |
|
|
Are you noticing anything in the logs that a connection might be blocked? You may have also received a new set of rules from Sunbelt
(the rules get downloaded separately from the application) which prevent Privoxy from being connected to. I suggest you contact technical support first and let them get a copy of your rules and configurations to determine what is occurring.
|
|
| Back to top |
|
 |
f6030ltd
Cadet

 Joined: Jul 03, 2007 Posts: 8 Location: UK
|
Posted: Thu Jul 05, 2007 4:53 pm Post subject: |
|
|
thanks for reply.
Checked logs when this started (and again since) and nothing shows.
Sunbelt update MY firewall rules under the covers without asking or telling me ? this is a horse of a different colour ! (and not one I like the look of to be honest)
Gave me an idea though - tried to export rules from the sunbelt version so I can compare with the rules set I exported from Kerio. (shoulda done that sooner but had no inkling at all that sunbelt would or could update my ruleset sub rosa)
get msg 'error generating digest for the config file' in a msg box.
hmm. seems there is problem here. (and I can't do the potentially handy dandy ruleset compare).. arrghhh
and yes I tried importing the ruleset I exported infrom kerio into Sunbelt - and that isn't working either ...
anyone got the last vesion of the Kerio f/wall pre sunbelt ?
(Filehippo ends up leading back to the sunbelt version I am having probs with)
|
|
| Back to top |
|
 |
chimplyirresistible
Guest IP: 65.35.*.*
|
Posted: Thu Jul 05, 2007 5:21 pm Post subject: |
|
|
No the rules wont get updated without you approving them. There were bugs with the import/export feature of previous builds of Kerio that have been fixed in the 916 build. The problem was that the earlier configuration files no longer seem to work.
If you wish, I can import your configuration files and attempt to reproduce the issue to see if it is just you or if a particular rule is causing the issue.
|
|
| Back to top |
|
 |
f6030ltd
Cadet

 Joined: Jul 03, 2007 Posts: 8 Location: UK
|
Posted: Thu Jul 05, 2007 5:29 pm Post subject: |
|
|
yes please - will see if I can pm them to you through the board.
Have been through the hits here on export and import but though this latest level solved that issue.
P.s found kerio-kpf-4.2.2-911-win.exe on filehippo - when I put my proper glasses on !! - so have that as an option... would sooner get this working though. will make a zip and try the PM after posting this.
Thanks.
|
|
| Back to top |
|
 |
chimplyirresistible
Private

 Joined: Jun 06, 2007 Posts: 38 Location: USA
|
Posted: Thu Jul 05, 2007 7:06 pm Post subject: |
|
|
PM sent.
|
|
| Back to top |
|
 |
f6030ltd
Cadet

 Joined: Jul 03, 2007 Posts: 8 Location: UK
|
Posted: Fri Jul 06, 2007 11:28 am Post subject: |
|
|
and responded.
many thanks for this - am most grateful.
l
|
|
| Back to top |
|
 |
chimplyirresistible
Private

 Joined: Jun 06, 2007 Posts: 38 Location: USA
|
Posted: Fri Jul 06, 2007 1:15 pm Post subject: |
|
|
One more thing, is your copy of Kerio registered? The reason I ask is certain features like Web filtering and HIPS are disabled if it is not, depending on if your trial is expired.
Also, are you using Tor with Privoxy, or just Privoxy alone?
|
|
| Back to top |
|
 |
chimplyirresistible
Private

 Joined: Jun 06, 2007 Posts: 38 Location: USA
|
Posted: Fri Jul 06, 2007 1:38 pm Post subject: |
|
|
Ah, ok...so one of the things I noticed was you have "Broadcasts" turned off/denied under Network Security > Predefined.
I tried it with Tor/Privoxy and was unable to get a connection unless I specifically allowed Broadcasts to be turned on. Try it and see what happens.
|
|
| Back to top |
|
 |
f6030ltd
Cadet

 Joined: Jul 03, 2007 Posts: 8 Location: UK
|
|
| Back to top |
|
 |
chimplyirresistible
Private

 Joined: Jun 06, 2007 Posts: 38 Location: USA
|
Posted: Mon Jul 09, 2007 12:34 am Post subject: |
|
|
Glad I could have helped.
Best wishes.
|
|
| Back to top |
|
 |
|
|