Add the possibility of restrictions on the user's authorization, if it once logged in, then log into another computer, it is not possible. But of course leave the possibility of multiple inputs.333 votes
Please continue to vote if this is important to you.
It would be great to have support for most popular USB GPRS modems.268 votes
Great idea. We like it! No immediate plans, but we like it, and appreciate your feedback, votes and use cases on this.
Block entire country CIDR ranges. I recently did a trial of the Sophos UTM 9 software appliance and this was a feature it had that allowed the admin to tick off countries by name and flag that would be completely blocked which is something i'd love to see in kerio control. Our Firewall frequently gets attacked by Russia and China. Seeing as we do no business with either of these countries we block their entire IP range. An option to select one or more countries to block would be a great feature.247 votes
Thanks. Yes, we implemented blocking traffic from specific countries, but the request here is to allow it to be configured in the traffic rules. Thank you for the feedback.
We need filters, more searching and exporting possibilities, manuals, examples, etc.205 votesHeather P responded
Thanks for the idea. We haven’t assigned this idea to a release yet, but we welcome further comments and votes if this is important to you.
One can either enable or disable this feature.
The tresholds are set for 1-5 pitches.
>=3 attempts - blocked for 5 minutes
>=10 attempts - blocked for 30 minutes
>=20 attempts - blocked for 2 hours
>=30 attempts - blocked for 1 week
>=40 attempts - blocked for 1 month
This should be possible for all users and if possible for ftp/website access as well (additional to rdp/computer configurable for each intranet site?)186 votes
For MAC defined hosts, send a standard WOL packet from the web interface.185 votesHeather Paunet responded
Thanks for the feedback. No immediate plans, but let us know your use case, and please vote if this is important to you.
Be able to point local (internal) clients to Kerio control for time sync.158 votes
Would be fine option for UPS. Now if I connect UPS to Kerio computer and power failure occurs, it is no easy way to shutdown kerio OS properly. I must hope that power failure is short-time and UPS holds. Yes, reinstall Kerio from ISO image is thing for few minutes, but it is not professional solution and actual settings backup is needed. (And normal automatic backup is unc/ftp/email backup and NOT Samepage.io).157 votesHeather P responded
Great idea. We’d like to be able to do this, but haven’t assigned it to a release yet. We’ll leave it open for voting.
I think the title says it all.
We have already mentioned this about a year ago.
Our site to site VPN connection is much faster (10 MB/s instead of 4 MB/s) when we completely disable IDS / IPS in Kerio Control. This is off course undesireable because we would like to use IDS / IPS to protect against attacks from the Internet.
We would really appreciate it if IDS / IPS could be disabled for specifiek connections, of just in general for Kerio Site-to-Site VPN connections.
Head of IT
TJIP B.V.124 votes
have the ability to authenticate users as well as active directory or apple open directori with ldap standard server.107 votes
Welcome screen is very annoying think with mobile devices. Please add possibility to completely disable welcome screen.105 votes
Although CPU and RAM usage are excellent, I believe it would be beneficial to have CPU/motherboard temperature monitor.
And it shouldn't be too difficult to implement.
S.M.A.R.T. HDD data readout would be awesome too, but not as important as temperature (for me at the moment).102 votes
If it is possible. Add support https://letsencrypt.org/
"Let's Encrypt is a free, automated, and open certificate authority (CA), run for the public's benefit. Let's Encrypt is a service provided by the Internet Security Research Group (ISRG)."98 votes
automatic updates like Kerio Connect (KOFF) and Kerio Workspace Client95 votesRoman Jokl responded
Changes in the VPN client are rare and the protocol is backward compatible, so updating of the client is not necessary.
For example, we want to block all facebook sites, we could have an input box in which we would put something like:
and get a result:
This could simplify URL rules for large number of addresses to be blocked.
P.S. regexp would also be great.95 votes
Setting up IPSec on mobile devices is cumbersome. Juniper Networks and others brought their own clients to iOS. I would also like to see a Kerio client for mobile devices.89 votes
I would like to see Kerio to preform DHCP relaying. That way I only need one DHCP server (cluster) in my network.
Kerio Control is in the center of my Network, but it doesn't cover my entire network.
Also when kerio Control can relay, I can use my Windows DHCP server which is having more DHCP options then the Kerio control DHCP service, and has a much better Active Directory integration.89 votes
Kerio Control would check remote log and implement user defined filter and actions, like enforcing / enabling specific firewall rule if a matching log entry is discovered.89 votes
i whant to specify
source IP address AND user
if both are TRUE - the rule applies86 votes
Currently it is not possible to use any kind of IPTV on the LAN side of the control, as an IGMP proxy would be necessary to provide the multicast channel streams to the clients after NAT.
Many open source firewall distributions have plugins / modules to enable that feature.79 votes
- Don't see your idea?