Kerio WinRoute Firewall 6.4

Administrator's Guide

Kerio Technologies


Release Date: December 12, 2007

This guide provides detailed description on the Kerio WinRoute Firewall, version 6.4.1. All additional modifications and updates reserved.

For current product version, check http://www.kerio.com/kwfdwn.

Information regarding registered trademarks and trademarks are provided in appendix A  Legal Presumption.


Table of Contents

1  Quick Checklist
2  Introduction
2.1  Kerio WinRoute Firewall
2.2  Conflicting software
2.3  Installation
2.4  WinRoute Components
2.5  WinRoute Engine Monitor
2.6  Upgrade and Uninstallation
2.7  Configuration Wizard
3  WinRoute Administration
3.1  Administration Window
3.2  View Settings
4  Product Registration and Licensing
4.1  License types and number of users
4.2  License information
4.3  Registration of the product in the Administration Console
4.4  Product registration at the website
4.5  Subscription / Update Expiration
4.6  User counter
5  Settings for Interfaces and Network Services
5.1  Network interfaces
5.2  Connection Failover
5.3  DNS Forwarder
5.4  DHCP server
5.5  Dynamic DNS for public IP address of the firewall
5.6  Proxy server
5.7  HTTP cache
6  Traffic Policy
6.1  Network Rules Wizard
6.2  How traffic rules work
6.3  Definition of Custom Traffic Rules
6.4  Basic Traffic Rule Types
7  Bandwidth Limiter
7.1  How the bandwidth limiter works and how to use it
7.2  Bandwidth Limiter configuration
7.3  Detection of connections with large data volume transferred
8  User Authentication
8.1  Firewall User Authentication
9  Web Interface
9.1  Web Interface Parameters Configuration
9.2  User logon and logout
9.3  Status information and user statistics
9.4  User preferences
10  HTTP and FTP filtering
10.1  Conditions for HTTP and FTP filtering
10.2  URL Rules
10.3  Global rules for Web elements
10.4  Content Rating System (ISS OrangeWeb Filter)
10.5  Web content filtering by word occurrence
10.6  FTP Policy
11  Antivirus control
11.1  Conditions and limitations of antivirus scan
11.2  How to choose and setup antiviruses
11.3  HTTP and FTP scanning
11.4  Email scanning
11.5  Scanning of files transferred via Clientless SSL-VPN
12  Definitions
12.1  IP Address Groups
12.2  Time Intervals
12.3  Services
12.4  URL Groups
13  User Accounts and Groups
13.1  Viewing and definitions of user accounts
13.2  Local user accounts
13.3  Local user database: external authentication and import of accounts
13.4  Active Directory domains mapping
13.5  User groups
14  Remote Administration and Update Checks
14.1  Setting Remote Administration
14.2  Update Checking
15  Advanced security features
15.1  P2P Eliminator
15.2  Special Security Settings
16  Other settings
16.1  Routing table
16.2  Dial On Demand
16.3  Universal Plug-and-Play (UPnP)
16.4  Relay SMTP server
17  Status Information
17.1  Active hosts and connected users
17.2  Show connections related to the selected process
17.3  Alerts
18  Basic statistics
18.1  Volume of transferred data and quota usage
18.2  Interface statistics
19  Kerio StaR — statistics and reporting
19.1  Monitoring and storage of statistic data
19.2  Settings for statistics and quota
19.3  Connection to StaR and viewing statistics
19.4  Accounting period
19.5  Overall View
19.6  User statistics
19.7  Users' Activity
19.8  Users by Traffic
19.9  Top Visited Websites
19.10  Top Requested Web Categories
20  Logs
20.1  Log settings
20.2  Logs Context Menu
20.3  Alert Log
20.4  Config Log
20.5  Connection Log
20.6  Debug Log
20.7  Dial Log
20.8  Error Log
20.9  Filter Log
20.10  Http log
20.11  Security Log
20.12  Sslvpn Log
20.13  Warning Log
20.14  Web Log
21  Kerio VPN
21.1  VPN Server Configuration
21.2  Configuration of VPN clients
21.3  Interconnection of two private networks via the Internet (VPN tunnel)
21.4  Exchange of routing information
21.5  Example of Kerio VPN configuration: company with a filial office
21.6  Example of a more complex Kerio VPN configuration
22  Kerio Clientless SSL-VPN
22.1  Configuration of WinRoute's SSL-VPN
22.2  Usage of the SSL-VPN interface
23  Troubleshooting
23.1  Detection of incorrect configuration of the default gateway
23.2  Configuration Backup and Transfer
23.3  Automatic user authentication using NTLM
23.4  FTP on WinRoute's proxy server
23.5  Partial Retirement of Protocol Inspector
23.6  User accounts and groups in traffic rules
23.7  Use of Full cone NAT
24  Network Load Balancing
24.1  Basic Information and System Requirements
24.2  Network Configuration
24.3  Configuration of the servers in the cluster
25  Technical support
25.1  Essential Information
25.2  Tested in Beta version
25.3  Contacts
A  Legal Presumption
B  Used open-source libraries
Glossary of terms
Index