CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Upgraded to Sunbelt from Kerio - broken proxy !
Goto page 1, 2  Next
 
Post new topic   Reply to topic       All -> FavForums -> Sunbelt KerioPF [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
f6030ltd

Cadet
Cadet


Joined: Jul 03, 2007
Posts: 8
Location: UK

PostPosted: Tue Jul 03, 2007 3:52 pm    Post subject: Upgraded to Sunbelt from Kerio - broken proxy !
Reply with quote

As strap line.
Am now running Sunbelt (System Service 4.5.916.0).
My proxy (privoxy) has served me well. Trouble is that I canot access the web through my browsers (Opera and Firefox) now. Unless I direct connect instead of going through privoxy. As it is both browsers and the only change is the firewall it has to be related to the firewall I think.
Privoxy runs on same machine BTW.
O/S is Win XP Pro Sp2+

This is not good. Sad

the install seems to have ported over all my rules etc. and privoxy has greem tricks across the board in the rules.

Am stumped - any clues for resolution/diagnosis please ?

I swear I did not change anything else ( I know everyone says that..).

TIA

Steve

Back to top
View users profile Send private message
f6030ltd

Cadet
Cadet


Joined: Jul 03, 2007
Posts: 8
Location: UK

PostPosted: Wed Jul 04, 2007 9:48 am    Post subject:
Reply with quote

I unclicked "Enable Network security module" In
Network Security -> Applications and privoxy get invoked and works fine.

So it it looks like it is the sungate firewall which is denying my proxy.

So I suppose the only question is this an under the covers feature that canniot be fixed or is it in the rules. As the rules are ported by Sungate upon upgrade from my previous working Kerio setup the question is somewhat important.
Running with no Network security enabled in a firewall is a waste of time IMV.

Anyone ? ?

Back to top
View users profile Send private message
f6030ltd

Cadet
Cadet


Joined: Jul 03, 2007
Posts: 8
Location: UK

PostPosted: Wed Jul 04, 2007 11:18 am    Post subject:
Reply with quote

failing a fix where can get the last version of the Kerio firewall so I can back level to a fully functioning configuration ?

Back to top
View users profile Send private message
Graham1

Captain
Captain


Joined: Dec 21, 2005
Posts: 340


PostPosted: Wed Jul 04, 2007 11:32 pm    Post subject:
Reply with quote

Have you tried deleting all your current "network security" rules and starting from scratch. Before doing this, export your configuration first (so it can be imported back if nothing works Smile ).

Btw, Are you using application or packet filter rules?

Smile

Back to top
View users profile Send private message
f6030ltd

Cadet
Cadet


Joined: Jul 03, 2007
Posts: 8
Location: UK

PostPosted: Thu Jul 05, 2007 10:04 am    Post subject:
Reply with quote

Thanks for response.
I see your point - is it a known problem that the Sunbelt version does not translate existing rules correctly ?
Starting from scratch woul be a right pain - have packet filtering rules and lots of application control rules etc etc. Would take me best part of a day re-run everything to set up the rules as they are now and it would be hard to guyrantee they woul be complete even then. they are just not being obeyed as they they should be.
I did export the ruleset from kerio version before the upgrade so to hget back functionality all I need to do is re-install the kerio firewall and import my saved ruleset.
The kerio version seems the way to go - would stay with that and wait for an update to two to have happened to Sunbelt before trying the upgrade again then.

Back to top
View users profile Send private message
chimplyirresistible

Private
Private


Joined: Jun 06, 2007
Posts: 38
Location: USA

PostPosted: Thu Jul 05, 2007 2:24 pm    Post subject:
Reply with quote

Are you noticing anything in the logs that a connection might be blocked? You may have also received a new set of rules from Sunbelt
(the rules get downloaded separately from the application) which prevent Privoxy from being connected to. I suggest you contact technical support first and let them get a copy of your rules and configurations to determine what is occurring.

Back to top
View users profile Send private message
f6030ltd

Cadet
Cadet


Joined: Jul 03, 2007
Posts: 8
Location: UK

PostPosted: Thu Jul 05, 2007 4:53 pm    Post subject:
Reply with quote

thanks for reply.
Checked logs when this started (and again since) and nothing shows.
Sunbelt update MY firewall rules under the covers without asking or telling me ? this is a horse of a different colour ! (and not one I like the look of to be honest)

Gave me an idea though - tried to export rules from the sunbelt version so I can compare with the rules set I exported from Kerio. (shoulda done that sooner but had no inkling at all that sunbelt would or could update my ruleset sub rosa)

get msg 'error generating digest for the config file' in a msg box.

hmm. seems there is problem here. (and I can't do the potentially handy dandy ruleset compare).. arrghhh

and yes I tried importing the ruleset I exported infrom kerio into Sunbelt - and that isn't working either ...

anyone got the last vesion of the Kerio f/wall pre sunbelt ?
(Filehippo ends up leading back to the sunbelt version I am having probs with)

Back to top
View users profile Send private message
chimplyirresistible

Guest
IP: 65.35.*.*






PostPosted: Thu Jul 05, 2007 5:21 pm    Post subject:
Reply with quote

No the rules wont get updated without you approving them. There were bugs with the import/export feature of previous builds of Kerio that have been fixed in the 916 build. The problem was that the earlier configuration files no longer seem to work.

If you wish, I can import your configuration files and attempt to reproduce the issue to see if it is just you or if a particular rule is causing the issue.

Back to top
f6030ltd

Cadet
Cadet


Joined: Jul 03, 2007
Posts: 8
Location: UK

PostPosted: Thu Jul 05, 2007 5:29 pm    Post subject:
Reply with quote

yes please - will see if I can pm them to you through the board.
Have been through the hits here on export and import but though this latest level solved that issue.

P.s found kerio-kpf-4.2.2-911-win.exe on filehippo - when I put my proper glasses on !! - so have that as an option... would sooner get this working though. will make a zip and try the PM after posting this.

Thanks.

Back to top
View users profile Send private message
chimplyirresistible

Private
Private


Joined: Jun 06, 2007
Posts: 38
Location: USA

PostPosted: Thu Jul 05, 2007 7:06 pm    Post subject:
Reply with quote

PM sent.

Back to top
View users profile Send private message
f6030ltd

Cadet
Cadet


Joined: Jul 03, 2007
Posts: 8
Location: UK

PostPosted: Fri Jul 06, 2007 11:28 am    Post subject:
Reply with quote

and responded.
many thanks for this - am most grateful.

l

Back to top
View users profile Send private message
chimplyirresistible

Private
Private


Joined: Jun 06, 2007
Posts: 38
Location: USA

PostPosted: Fri Jul 06, 2007 1:15 pm    Post subject:
Reply with quote

One more thing, is your copy of Kerio registered? The reason I ask is certain features like Web filtering and HIPS are disabled if it is not, depending on if your trial is expired.

Also, are you using Tor with Privoxy, or just Privoxy alone?

Back to top
View users profile Send private message
chimplyirresistible

Private
Private


Joined: Jun 06, 2007
Posts: 38
Location: USA

PostPosted: Fri Jul 06, 2007 1:38 pm    Post subject:
Reply with quote

Ah, ok...so one of the things I noticed was you have "Broadcasts" turned off/denied under Network Security > Predefined.
I tried it with Tor/Privoxy and was unable to get a connection unless I specifically allowed Broadcasts to be turned on. Try it and see what happens.

Back to top
View users profile Send private message
f6030ltd

Cadet
Cadet


Joined: Jul 03, 2007
Posts: 8
Location: UK

PostPosted: Mon Jul 09, 2007 12:30 am    Post subject:
Reply with quote

Many thanks.
it is the free version.
Thsat rule you spotted has been like that for 'ever'. it must not have been enforced on the old version. I did look at that page of setting but obviously didn't look too hard as nothing had changed....
Switched it to allow for trusted and am using privoxy again.

You sir are a scholar and a gentleman.
Kudos and thanks go to you in abundance. Smile Smile

Back to top
View users profile Send private message
chimplyirresistible

Private
Private


Joined: Jun 06, 2007
Posts: 38
Location: USA

PostPosted: Mon Jul 09, 2007 12:34 am    Post subject:
Reply with quote

Glad I could have helped.

Best wishes.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Sunbelt KerioPF All times are GMT
Goto page 1, 2  Next
Page 1 of 2

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer