16.2 Setting Remote Administration
215
firewall’s system time. The time zone also includes information about daylight saving
time settings.
Kerio
Technologies
offers
the
following
free
NTP
servers
for
this
purpose:
0.kerio.pool.ntp.org
,
1.kerio.pool.ntp.org
,
2.kerio.pool.ntp.org
and
3.kerio.pool.ntp.org
.
16.2 Setting Remote Administration
Remote administration is connection to the firewall, its monitoring and configuration changes
with the
Administration Console
or with the
Web Administration
interface from another host
that the one on which
WinRoute
is installed.
If
WinRoute
includes only traffic rules created automatically by the wizard (see chapter
access to the remote administration is allowed via all trustworthy network interfaces (see
chapter
). This means that remote administration is available from all local hosts.
To allow or deny remote administration via the Internet (non-trusted networks), define a cor-
responding traffic rule. Traffic between
WinRoute
and
Administration Console
is performed
by TCP and UDP protocols over port
44333
. The definition can be done with the predefined
service
KWF Admin
. the secured version of the
Web Administration
interface use TCP protocol,
on port
4081
by default — predefined
KWF WebAdmin-SSL
service.
How to allow remote administration from the Internet
In the following example we will demonstrate how to allow
WinRoute
remote administration
from some Internet IP addresses.
•
Source
— group of IP addresses from which remote administration will be allowed (see
chapter
).
For security reasons it is not recommended to allow remote administration from an
arbitrary host within the Internet (this means: do not set
Source
as
Any
or as
Internet
)!
•
Destination
—
Firewall
(host where
WinRoute
is installed).
•
Service
—
KWF Admin
(connection with the
Administration Console
) and
KWF
WebAdmin-SSL
(secured version of the
Web Administration
interface).
It is not recommended to allow access via the unsecured version of the
Web Adminis-
tration
interface (the
KWF WebAdmin
service)! Unsecured traffic might be tapped and
misused for assaulting the firewall and local hosts behind it.
•
Action
—
Permit
(otherwise remote administration would be blocked)
•
Translation
— Because the engine is running on the firewall there is no need for trans-
lation.
Figure 16.2
Traffic rule that allows remote administration
Содержание KERIO WINROUTE FIREWALL 6
Страница 1: ...Kerio WinRoute Firewall 6 Administrator s Guide Kerio Technologies s r o...
Страница 157: ...12 3 Content Rating System Kerio Web Filter 157 Figure 12 7 Kerio Web Filter rule...
Страница 189: ...14 4 URL Groups 189 Description The item s description comments and notes for the administrator...
Страница 247: ...19 4 Alerts 247 Figure 19 14 Details of a selected event...
Страница 330: ...Chapter 23 Kerio VPN 330 Figure 23 55 The Paris filial office VPN server configuration...
Страница 368: ...368...