Firewall SettingsOverviewNetwork routing equipment and wireless routing devices typically include firewall features that can be configured to forward or block network packets. The latest desktop OS versions (both Windows and Macintosh) also include "personal firewall" features that can be configured to block or forward packets from the individual computer. Many third party "security" products may also include firewall features (e.g. Norton Personal Firewall, ZoneAlarm, etc). Special firewall rules must be configured on the KeyServer host to allow communication from its clients . Response packets from KeyServer to its clients will generally be allowed by default client settings, but connection timeouts for personal firewalls, wireless routers, and NAT routers may need to be changed to achieve best reliability and efficiency (e.g. see rule 1 and the Windows XP, Service Pack 2 note below). PortsThe KeyServer process listens for incoming UDP and TCP packets on port 19283. Response packets are sent from port 19283 back to the requesting address and port. Port 19283 is registered through ICANN to Sassafras Software so there should be no need to specify a different port - however, it can be changed using the TCP/IP item in KeyConfigure's Locations window.
KeyConfigure initiates admin communication to the KeyServer process on dynamically allocated TCP and UDP ports (with destination UDP 19283 and TCP 19283 at the KeyServer host address). A dynamic UDP port is also used to interrogate shadows (if any) for status information (with destination port UDP 19315). KeyConfigure also uses the HTTP protocol (with destination port TCP 80) to check for newer versions. If HTTP access is blocked, KeyConfigure's version check feature should be turned off in order to avoid an excessive delay when launching (use the Admin menu). Communication from KeyConfigure to KeyReporter also uses the HTTP protocol directed to port 80 unless KeyReporter has been configured to use a non-standard port. ksODBC is an ODBC driver component that can be installed on any Windows or Macintosh computer in order to support third party SQL reporting tools (e.g. Crystal Reports, MS Access, FileMaker, etc.). When an external reporting tool is used, ksODBC initiates communication to the KeyServer process on a dynamically allocated TCP port (with destination port 19283). KeyReporter initiates a connection to the KeyServer process on dynamically allocated port with destination port TCP 19283 on the KeyServer host. KeyReporter listens for web browser connections on the standard http port 80 and standard https port 443. If KeyReporter is hosted on a computer that is already running a web server, this default must be changed as explained in the KeyReporter documentation. Connections from KeyConfigure for access to archive reports are accepted on this same port. If the KeyServer process is specially configured to use external authentication services, to export its databases, or to backup onto a remote volume, additional dynamic ports will be opened to support these underlying network services. You may have to configure some firewall rules according to the documentation for each of these services. The "Send KeyServer Status/Warning Messages" option (from KeyConfigure's Admin menu) initiates packets from KeyServer (and KeyShadows, if any) to a specified mail server address (TCP destination port 25 from a dynamic source port). Firewall Configuration Rules
Windows XP (Service Pack 2) and Vista - "Personal Firewall"
Starting with Windows XP Service pack 2, a "personal firewall" service is enabled by default when upgrading from a previous system version. In addition to ignoring most incoming packets, the default firewall configuration will ignore response packets to outgoing UDP requests unless the response is received within 90 seconds. Use the Control Panel called "Windows Firewall" to make sure that special Exception rules have been added for K2:
|
Related TopicsK2 Getting Started- Installation Authentication Exporting Backup Reports Help Index |
Windows XP (Service Pack 2) and Vista - "Personal Firewall"