9.2. System Security Rules

These rules allow startup of various components of the operating system on which the Kerio Personal Firewall is installed. Internal system security rules can be found in the System Security / Applications section (see chapter 13.2. Application Rules). These rules cannot be removed, however, users can set actions, logging or/and notices for them.

Some of these internal rules are applied only in certain versions of Windows operating systems (some system components differ in individual versions).

Rules for Operating System components

The following symbols are used in the description of system component rules to define file path:

  • WIN_DIR — the main directory of the Windows operating system (typically, C:\WINNT for Windows NT/2000, C:\WINDOWS for other versions)

  • SYS_DIR — system directory of Windows (typically, C:\WINDOWS\SYSTEM for Windows 98/Me, C:\WINNT\SYSTEM32 for Windows NT/2000, and C:\WINDOWS\SYSTEM32 for Windows XP)

  1. Rules which are common to all versions of Windows

    ApplicationDescriptionStartModifyLaunch another
    WIN_DIR\explorer.exeWindows ExplorerPermitAskPermit
  2. Special rules for Windows 98/ME operating systems

    ApplicationDescriptionStartModifyLaunch another
    SYS_DIR\systray.exeSystem TrayPermitAskPermit
  3. Special rules for Windows NT/2000/XP operating systems

    ApplicationDescriptionStartModifyLaunch another
    SYS_DIR\services.exeServices app.PermitAskPermit
    SYS_DIR\winlogon.exeLogon app.PermitAskPermit
  4. Special rules for Windows 2000/XP operating systems

    ApplicationDescriptionStartModifyLaunch another
    SYS_DIR\svchost.exeGeneric Host Proc.PermitAskPermit
  5. Special rules for Windows XP operating system

    ApplicationDescriptionStartModifyLaunch another
    SYS_DIR\logonui.exeLogon UIPermitAskPermit
    SYS_DIR\csrss.exeClient ServerPermitAskPermit
    SYS_DIR\smss.exeClient ServerPermitAskPermit
    SYS_DIR\svchost.exeGeneric Host Proc.PermitAskPermit

Rules for Kerio Personal Firewall components

These rules allow running individual Kerio Personal Firewall applications using special auxiliary programs. The following rules are common to all supported versions of Windows.

*) The KPF_DIR expression represents a directory (path) where the Kerio Personal Firewall is installed (typically, C:\Program Files\Kerio\Personal Firewall 4).

ApplicationDescriptionStartModifyLaunch another
KPF_DIR\kpf4gui.exe*KPF GUIPermitPermit + logPermit
KPF_DIR\kpf4ss.exe*KPF ServicePermitPermit + logPermit
KPF_DIR\assist.exe*Core dumperPermitPermit + logPermit
KPF_DIR\cfgconv.exe*Conf. conv.PermitPermit + logPermit