30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Administrative settings<br />

firewall’s system time. The time zone also includes information about daylight saving<br />

time settings.<br />

<strong>Kerio</strong> Technologies offers the following free NTP servers for this purpose:<br />

0.kerio.pool.ntp.org, 1.kerio.pool.ntp.org, 2.kerio.pool.ntp.org and<br />

3.kerio.pool.ntp.org.<br />

17.2 Setting Remote Administration<br />

Remote administration is connection to the firewall, its monitoring and configuration changes<br />

with the Administration Console or with the Administration web interface from another host<br />

that the one on which <strong>Kerio</strong> Control is installed.<br />

If <strong>Kerio</strong> Control includes only traffic rules created automatically by the wizard (see chapter 7.1),<br />

access to the remote administration is allowed via all trustworthy network interfaces (see<br />

chapter 5). This means that remote administration is available from all local hosts.<br />

To allow or deny remote administration via the Internet (non-trusted networks), define<br />

a corresponding traffic rule. Traffic between <strong>Kerio</strong> Control and Administration Console is<br />

performed by TCP and UDP protocols over port 44333. The definition can be done with<br />

the predefined service <strong>Kerio</strong> Control Admin. The secured version of the Administration web<br />

interface uses TCP protocol, on port 4081 — predefined <strong>Kerio</strong> Control WebAdmin service.<br />

How to allow remote administration from the Internet<br />

In the following example we will demonstrate how to allow <strong>Kerio</strong> Control remote<br />

administration from some Internet IP addresses.<br />

• Source — group of IP addresses from which remote administration will be allowed (see<br />

chapter 15.1).<br />

For security reasons it is not recommended to allow remote administration from an<br />

arbitrary host within the Internet (this means: do not set Source as Any or as Internet)!<br />

• Destination — Firewall (host where <strong>Kerio</strong> Control is installed).<br />

• Service — <strong>Kerio</strong> Control Admin (connection with the Administration Console) and <strong>Kerio</strong><br />

Control WebAdmin (secured version of the Administration web interface).<br />

Please feel strongly discouraged from allowing access to the unsecured version of<br />

the Administration web interface! Unsecured traffic might be tapped and misused for<br />

assaulting the firewall and local hosts behind it.<br />

• Action — Permit (otherwise remote administration would be blocked)<br />

• Translation — Because the engine is running on the firewall there is no need for<br />

translation.<br />

240

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!