PDA

View Full Version : settaggi firewall


Vegeteo
03-12-2002, 20:07
ho messo come consigliato dal mod il firewall kerio ma non so cosa devo settare per renderlo al meglio e sopratutto se qualcuno tenta l'accesso al mio pc vengo avvertito?o devo vederlo da qualche parte?

Bilancino
03-12-2002, 21:02
Se clicchi sull'icona c'่ il men๙ logs con le info di eventuali attacchi. Io all'inizio lascio il livello medio e creo le regole poi quando tutti i programmi che accedono ad internet hanno la regola alzo al massimo la sicurezza.......inoltre ho bloccato diversi servizi di windows xp che volevano uscire.

Ciao

Vegeteo
04-12-2002, 07:03
ma come me lo indica il lv di attacchi?io vedo 2 strisce verdi per icq e una rossa ma come faccio a bloccarli se volessi?ma non vengo avvertito in caso di attacchi?

Bilancino
04-12-2002, 08:23
Se abiliti l'uso del file log nelle impostazioni avrai:

Filter.log file
The filter.log file is used for logging Kerio Personal Firewall actions on a local computer. It is created in a directory where Personal Firewall is installed (typically C:\Program Files\Kerio\Personal Firewall). It is created upon the first record.

Filter.log is a text file where each record is placed on a new line. It has the following format:

1,[08/Jun/2001 16:52:09] Rule 'Internet Information Services': Blocked: In TCP, richard.kerio.cz [192.168.2.38:3772]->localhost:25, Owner: G:\WINNT\SYSTEM32\INETSRV\INETINFO.EXE

How to read this line:

1 — rule type (1 = denying, 2 = permitting)

[08/Jun/2001 16:52:09] — date and time that the packet was detected (we recommend checking the correct setting of the system time on your computer)

Rule 'Internet Information Services' — name of a rule that was applied (from the Description field)

Blocked: / Permittted: — indicates whether the packet was blocked or permitted (corresponds with the number at the beginning of the line)

In / Out — indicates an incoming or outgoing packet

IP / TCP / UDP / ICMP, etc. — communication protocol (for which the rule was defined)

richard.kerio.com [192.168.2.38:3772] — DNS name of the computer, from which the packet was sent, in square brackets is the IP address with the source port after a colon

locahost:25 — destination IP address (or DNS name) and port (localhost = this computer)

Owner: — name of the local application to which the packet is addressed (including its full path). If the application is a system service the name displayed is SYSTEM


Sinceramente io non l'ho attivato perch่ tanto gli attacchi non mi interessano......

Ciao

Vegeteo
04-12-2002, 16:27
in effetti nei test ha fallito miseramente:D