Wow. Thanks Keith. I find this amazing. Especially given most people use a 192.168.0.x network. It looks like too many would trust 192.168.0.3, for example.
It wouldn't be as bad if Kerio would allow to specify the mac address or name of a peer on the network. Computer names would work for me as I use DDWRT to DNS masquerade the local machines into the DNS domain. Mac addresses would be manageable for say < 4 machines but even tha becomes unmanageable after about 6.
I moved the trusted range into something obscure, and made it as narrow as possible.
Can machines keep changing their IP address and theorectically step through likely addresses looking for holes in other's firewalls?
Main Topics
Browse All Topics





by: keith_alabasterPosted on 2006-12-30 at 09:52:30ID: 18219372
Not really, no. Once you open the hole in the firewall then in principle you are at risk. If you do it by IP address then ovbiously anything that matches that IP is assumed as trusted.