some web application firewall on top of the reverse proxy. a break and Inspect function with WAF functionality6 votes
It would be great to have an option to configure automatic termination of VPN session by timeout (when user connected via VPN Client).
For this moment, it can be done only manually (Web Admin--->Status--->VPN Clients--->Right Click on the connection and disconnect)1 vote
more realtime information / widgets for dashboard with better reporting functions3 votes
It would be nice if kerio control recognizes wireless cards and 3G cards so we can use this solution in remote locations. In other firewal they are already recognized, including on motherboards that already come by default6 votes
Add the function of detecting the real file format attached to the letter, regardless of the recorded extension of its name. MS Office files that may have macros-viruses, may have a recorded ".doc" extension instead of ".docm". Thus, it is impossible to block in "Attachment Filter" the receiving of the files with macros using filtration by filename extension or MIME type.3 votes
The GeoIP filter is great until it isn't. The current block all traffic is offering a hammer when we need a scalpel. Please look to offering a better set of controls.
Simply add an "Override/Ignore GeoIP Filter" checkbox to every rule.
This way I can define known servers in otherwise blocked countries and allow specific/all traffic from trusted computers.
A user could also use this override to allow specific types of traffic like mail from everywhere in the world without allowing other more secure traffic.
I would like to ask if it's possible to change behaviour of the Kerio Control in case of IPv6 Router Advertisements. Router Advertisements are not configurable in the Kerio Control at all and we have a problem with that. We are running IPv6 network and we need to assign IP addresses to devices only from our DHCPv6 server (stateful configuration). We need to set flags like this to perform stateful configuration:
'M' bit (Managed address configuration flag) - 1
'O' bit (Other configuration flag) - 0
'A' bit (Autonomous address autoconfiguration flag) - 0
Best regards1 vote
when i make traffic rule to make any authentication user login to internet if any one try to open any site not open
few sites only go to authentication login and redirect to the site again
but if i open google , yahoo,msn, not open
shortly i want any one try to open any site or serves on internet login firstly on kerio control
whether any authentication user or not6 votes
I work on a vessel where we move from location to location. Altering the interfaces we are connected to frequently and the subsequent bandwidth available for a specific interface. I quite often have to run a speed test from a PC but to get a true test i have to remove any bandwidth rules applied. It would be nice if the Kerio could run a speed test from the firewall where it has full bandwidth. Possible it runs automatically and (if enabled) can adjust the bandwidth of an interface based on the tested average?6 votes
It should be nice to have a customizable login and disclaimer page.
On the login page, the ability to specify some text (now can only add a little image).
The disclaimer page should be displayed after successful authentication and can be used to explain users that traffic is monitored/filtered/etc. Of course, that page should also be customizable.
The disclaimer page should also contain an "accept" flag to be sure user have read the disclaimer text.2 votes
We have increasing number of costumers who are switching fiber connection. It would be nice to offer SFP as other firewalls do.
please add a Reload button in control panel. sometimes I have to push a power button physically in order to restart a server because some bugs. Of course I can reload by terminal but the server doesn't have a monitor, keyboard and mouse. It takes much times to connect them.1 vote
Ipsec ESP Phase 2 SHA256
I can't build VPN to parental company and has to spend 4000$ for suggested router by them. Can't change ESP in case of corporate policies.3 votes
Since I have a lot of created traffic rules, a good solution would be to create subgroups. I mean, I have some rules that refer to a certain group of hosts. It would be a good idea to create a parent rule in which the child rules are included. This group (the parent rule) could be rolled up (hidden) or developed (discovered) if needed. This would limit the amount of information displayed in the book window. The principle of operation of the system would be as before. The dam goes from top to bottom through all the rules contained in subgroups and groups. This would not change the rules of the rule list. For now, it's too long to find the right one because I have to search a very long list.
I have seen the use of subgroups in the FORTIGATE firewall. Great deal.
One more question. I need to implement Polish language in the logs. If Polish is in the interface then why can not it be in the logs.
Sorry for my english but I used google translator to write this test.
Since I have a lot of created traffic rules, a good solution would be to create subgroups. I mean, I have some rules that refer to a certain group of hosts. It would be a good idea to create a parent rule in which the child rules are included. This group (the parent rule) could be rolled up (hidden) or developed (discovered) if needed. This would limit the amount of information displayed in the book window. The principle of operation of the system would be as before. The dam goes from top to bottom through all the rules contained in…1 vote
Choose nic board to test WAN link using MTR.1 vote
all network support concept result congrtaes setting than jr. firstname.lastname@example.org votes
add new permission for Kerio Control users (checkbox) "when user log in through vpn, send WOL packet for 1 MAC address"3 votes
Adding SAML support to Kerio Control will allow it to exchange authentication and authorization information with other systems.1 vote
Sometime could be useful enable/disable Safe Search on a specific search engine.3 votes
Everything start to move on cloud and one of the is also AD services. If you can support to Active Directory Premium services we can use our users over Kerio Control and also if you can suppot their vpn protocol the remote site user can access the cloud server over kerio control directly.3 votes
- Don't see your idea?