Kaspersky Anti-Virus 6.0 R2 for Windows Workstations


Functional features of the Anti-Hacker component in Kaspersky Anti-Virus 6.0 for Windows Workstations MP4

Back to "Settings / How to"
2012 Oct 16 ID: 2540

This article explains some functional features of the Anti-Hacker component which is a part of Kaspersky Anti-Virus 6.0 for Windows Workstations MP4 application:

  • Rules for packet filtering have a higher priority than Rules for applications.
  • If you create a rule for applications or a rule for packet filtering and enter into the Remote IP address field a name of a PC/host which is not in the network at the moment, such a name will not be accepted and the PC/host will not be added. You will get the following error:

    however if you enter its IP Address, the PC/host will be added correctly.
  • Anti-Hacker rules do not affect IDS (Intrusion Detection System).

    This subsystem serves to analyze incoming connections, detect attempts to scan your PC ports, and filter out network packets aiming to exploit software vulnerabilities. If triggered, intrusion detection subsystem blocks all incoming connections from the attacking PC for a certain period of time and informs the user about an attempt of a network attack on his PC.
  • ICMP packets are always allowed for the Local network zone.
    Zones rules have a higher priority than blocking packet rules.

    For example, if you select Local network status, packet exchange and access to common folders will be allowed regardless of existing packet blocking rules.
  • High Security mode blocks all network activity not covered by existing allowing rules.
  • You do not need to reboot the PC after switching Firewall mode between Maximum compatibility and Maximum speed!
  • When working in the Maximum compatibility mode, rules for applications have a higher priority than the stealth mode.
  • When working in the Maximum speed mode, rules for applications have a lower priority than the stealth mode.

    For example:
    • You have Kaspersky Anti-Virus 6.0 for windows Workstations MP4 installed on your PC.
    • A network game server is running on the same PC.
    • Rules for applications allow any network activity for this game process.
    • You have Stealth mode enabled.
    • You have Maximum speed mode enabled.

Result: Clients cannot connect to the server.

Solution: You have to switch to Maximum compatibility mode.

Regardless of the Anti-Hacker component security mode, when in Maximum speed mode with Stealth mode enabled, all packets sent from clients to the server are blocked, the server “keeps silent”.

  • When you have Stealth mode enabled, it is recommended to use Maximum compatibility mode.

    By default, Maximum compatibility mode is enabled.

  • If you have Stealth mode disabled, it is recommended to:
    • switch to Maximum speed mode for network games.
    • switch to Maximum compatibility mode for P2P clients.
Did the provided info help you?
Yes No

Applies To:

  • Kaspersky Anti-Virus 6.0 R2 for Windows Workstations