30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Administrative settings<br />

firewall’s system time. The time zone also includes information about daylight saving<br />

time settings.<br />

<strong>Kerio</strong> Technologies offers the following free NTP servers for this purpose:<br />

0.kerio.pool.ntp.org, 1.kerio.pool.ntp.org, 2.kerio.pool.ntp.org and<br />

3.kerio.pool.ntp.org.<br />

17.2 Setting Remote Administration<br />

Remote administration is connection to the firewall, its monitoring and configuration changes<br />

with the Administration Console or with the Administration web interface from another host<br />

that the one on which <strong>Kerio</strong> Control is installed.<br />

If <strong>Kerio</strong> Control includes only traffic rules created automatically by the wizard (see chapter 7.1),<br />

access to the remote administration is allowed via all trustworthy network interfaces (see<br />

chapter 5). This means that remote administration is available from all local hosts.<br />

To allow or deny remote administration via the Internet (non-trusted networks), define<br />

a corresponding traffic rule. Traffic between <strong>Kerio</strong> Control and Administration Console is<br />

performed by TCP and UDP protocols over port 44333. The definition can be done with<br />

the predefined service <strong>Kerio</strong> Control Admin. The secured version of the Administration web<br />

interface uses TCP protocol, on port 4081 — predefined <strong>Kerio</strong> Control WebAdmin service.<br />

How to allow remote administration from the Internet<br />

In the following example we will demonstrate how to allow <strong>Kerio</strong> Control remote<br />

administration from some Internet IP addresses.<br />

• Source — group of IP addresses from which remote administration will be allowed (see<br />

chapter 15.1).<br />

For security reasons it is not recommended to allow remote administration from an<br />

arbitrary host within the Internet (this means: do not set Source as Any or as Internet)!<br />

• Destination — Firewall (host where <strong>Kerio</strong> Control is installed).<br />

• Service — <strong>Kerio</strong> Control Admin (connection with the Administration Console) and <strong>Kerio</strong><br />

Control WebAdmin (secured version of the Administration web interface).<br />

Please feel strongly discouraged from allowing access to the unsecured version of<br />

the Administration web interface! Unsecured traffic might be tapped and misused for<br />

assaulting the firewall and local hosts behind it.<br />

• Action — Permit (otherwise remote administration would be blocked)<br />

• Translation — Because the engine is running on the firewall there is no need for<br />

translation.<br />

240

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!