Importante: eseguire l’aggiornamento Kerio Control 9.2.8
03/12/18 gatti Update
Riportiamo di seguito l’avviso inoltrato a tutti Partner da GFI.
--------------------------------------------------------------
Dear Valued GFI Partner,
On October 16, 2018 GFI was alerted by Sec Consul on a serious vulnerability in Kerio Control VPN. This vulnerability allows an attacker to replace any content of the VPN traffic. Such vulnerability discloses how one can actually perform such action. This is due to weak cryptography that has been there since the initial release of Kerio Control VPN.
Our Engineering teams have upgraded Kerio Control VPN encryption to a later standard from BlowFish to AES 128.
For this reason we suggest everybody to upgrade their Kerio Control software to the latest version 9.2.8. This new version apart from having a secure VPN without the disclosed vulnerability also has an increased performance of 40% in VPN traffic.
Please note that even the Kerio Control VPN client needs to be updated. This new client will trigger the new encryption channel. The new Kerio Control VPN client will not work with older Kerio Control software.
For further assistance, please open a support ticket with GFI Support by accessing the GFI Support portal on accounts.gfi.com.
Please make sure you refer to the below guidance when speaking to resellers:
How to Identify if vulnerable VPN Clients are connecting to Kerio Control

- Open Kerio Control administrative console
- Click Status from left sidebar
- Click VPN Clients
- Here you have displayed the list of VPN Clients (if the version column is not visible right-click on the header, click Columns and click Version)
- Vulnerable clients are version 9.2.7 or earlier
Updating Kerio Control VPN
- Download the latest version of Kerio Control VPN software for the OS of choice (Download Page)
- Make sure it's version 9.2.8 or higher
- Run the installer (Instructions Page)
How to create alerts in case a client is still using the old Kerio control client
- Go to Logs (left tab)
- Select Debug log
- Right click on log text and select Messages
- In the Messages dropdown scroll down to Kerio VPN
- Select VPN clients
- Click on OK
- Now go to Settings (left tab)
- Select Accounting and Monitoring
- Select tab Alert Settings
- Click on Add
- Enter email address to receive the alert
- Click Log Message
- In Name enter: BlowFish VPN Client Connect
- Log select Debug
- Condition type in: .*?Cipher configured. Cipher Type:BLF User:.*
- Tick Use Regular Expression
- Click OK

- Click OK in Edit Alerts dialog
This week we will send out communications to GFI resellers and Kerio Control customers globally.
For detailed information please read our knowledgebase article (https://go.gfi.com/?pageid=KCL_vpnvul)
If you have any questions, please reach out to your Distribution Account Manager.
GFI Software, Aurea SMB Solutions
Eventi su KerioControl
09/02/23 Dai una prima occhiata in esclusiva a GFI Kerio Control SaaS!07/04/20 Kerio Control - Working with a VPN - Virtual Private Network17/09/19 Sicurezza perimetrale, Networking avanzato, IDS/IPS e Alert Monitoring07/05/19 Kerio Control HA – Scopri la funzione High Availability03/04/19 Kerio Control 9.3 con High Availability27/03/19 Basi di Rete: Che cos'è e come si configura un Firewall05/12/18 Kerio Control - configurazione per il GDPR, raccogliere i log e identificare il data breach30/03/18 Kerio Control - configurazione per il GDPR, raccogliere i log e identificare il data breach16/02/18 Kerio Control - gestione amministrativa Livello Base25/01/18 Kerio Control - gestione amministrativa Livello Base20/11/17 Kerio Control - gestione amministrativa Livello Base30/10/17 Kerio Control - gestione amministrativa Livello Base11/09/17 Kerio Control - gestione amministrativa Livello Base16/06/17 Kerio Control - gestione amministrativa Livello Base06/04/17 Kerio Control - gestione amministrativa Livello Base20/03/17 Kerio Control - gestione amministrativa Livello Base09/02/17 Kerio Control - gestione amministrativa Livello Base25/10/16 Kerio Control Certification Day30/09/16 Kerio Control - comparativa con i principali competitors e i vantaggi offerti da Kerio Control26/09/16 Kerio Control - come attivare un certificato SSL e quali certificazioni utilizzare12/09/16 Kerio Control - gestione amministrativa Livello Base27/06/16 Kerio Control 9.1 - Application Filtering17/06/16 Kerio Control per Ambienti Cloud21/04/16 Kerio Control - comparativa con i principali competitors e i vantaggi offerti da Kerio Control18/04/16 Kerio Control - gestione amministrativa Livello Base04/04/16 Virtual Private Networking (VPN) con Kerio Control04/04/16 Kerio Control Statistics and Reporting25/03/16 Kerio Control - come attivare un certificato SSL e quali certificazioni utilizzare17/03/16 Kerio Control - gestione amministrativa Livello Base11/02/16 Kerio Control Certification Day21/09/15 Configura un Firewall virtuale su VMware e a seguire Utilizza il firewall Kerio Control in ambiente virtualizzato13/07/15 Configura un Firewall virtuale su VMware11/05/15 Configura un Firewall virtuale su VMware e a seguire Utilizza il firewall Kerio Control in ambiente virtualizzato16/03/15 Kerio Control, ottimizzazione del Traffico Internet09/03/15 Firewall Kerio Control Panoramica generale, analisi dei log.12/12/14 Firewall Kerio Control Panoramica generale, analisi dei log e ultime novità16/06/14 Firewall Kerio Control Panoramica generale e Novità dell'ultima versione 8.323/05/14 Firewall Kerio Control Panoramica generale e novità ultima versione 8.318/04/14 Firewall Kerio Control - Panoramica generale , Gestione delle Minacce e Network Intelligence28/03/14 Webinar Kerio Control Base20/02/14 Webinar Kerio Control Base20/01/14 Webinar Kerio Control Base14/11/13 Webinar Networking / Firewall: Regole di Traffico - Log e Debug31/10/13 Corso in Aula Kerio Control e GuestSurf, 2 semplici e potenti sistemi Firewall & Hotspot18/07/13 Webinar Kerio Control | VPN IP SEC, Connessioni sicure per Mobile Phone e Tablet12/10/12 Webinar Corner Bowl Log Manager28/09/11 Webinar Nuove possibilità di gestire la Larghezza di Banda con Kerio Control 7.2 Scopri le ultime features di Kerio Control! Rilasciato Kerio Control 9.0 Nuovi modelli a listino: Kerio Control NG300 e Kerio Control NG500 Kerio Control 9.1 Beta OFFERTA TRADE IN KERIO CONTROL Kerio Control Upgrade Program - Risparmia fino al 30% Rilasciato Kerio Control 8.6