<?xml version="1.0" encoding="iso-8859-1"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:admin="http://webns.net/mvcb/"
xmlns="http://purl.org/rss/1.0/">
<channel rdf:about="http://aplawrence.com//rss/fullKerio.rdf">
<title>Kerio Site News at A.P.Lawrence.com</title>
<link>http://aplawrence.com/</link>
<description>
Kerio feed at aplawrence.com: Thousands of articles, reviews, consultants listings, skills tests, opinion, how-to's for Unix, Linux and Mac OS X, networking, web site maintenance and more.. 
</description>
<sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>6</sy:updateFrequency>
<sy:updateBase>2008-01-01T00:00+00:00</sy:updateBase>
<dc:language>en</dc:language>
<dc:publisher>A.P. Lawrence</dc:publisher>
<dc:rights>Copyright  A.P. Lawrence</dc:rights>
<dc:creator>A.P. Lawrence (mailto:rssfeeds@aplawrence.com)</dc:creator>
<dc:date>2017-02-01T09:55:26+00:00</dc:date>
<image rdf:resource="http://aplawrence.com/image21.gif">
</image>
<items>
<rdf:Seq>
<rdf:li rdf:resource="http://aplawrence.com/Kerio/AD-address.html" />
<rdf:li rdf:resource="http://aplawrence.com/Kerio/google-dns-truncates.html" />
<rdf:li rdf:resource="http://aplawrence.com/Kerio/slow-folder-response-outlook.html" />
<rdf:li rdf:resource="http://aplawrence.com/Kerio/packets-on-wan-interface.html" />
<rdf:li rdf:resource="http://aplawrence.com/Forum/archive-folder-not-seen.html" />
<rdf:li rdf:resource="http://aplawrence.com/Kerio/expired-no-check.html" />
<rdf:li rdf:resource="http://aplawrence.com/Forum/Maximal-authentication-attempts.html" />
<rdf:li rdf:resource="http://aplawrence.com/Forum/two-outlook-accounts.html" />
</rdf:Seq>
</items>
</channel>
<image rdf:about="http://aplawrence.com/image21.gif">
<title>A.P.Lawrence Logo</title>
<url>http://aplawrence.com/image21.gif</url>
<link>http://aplawrence.com</link>
</image>


<item rdf:about="http://aplawrence.com/Kerio/AD-address.html">
<title>Changing mail addresses with Active Directory in Kerio Connect  </title>
<description>
<![CDATA[

<!-- <html><head><title>Changing mail addresses with Active Directory in Kerio Connect</title></head><body> -->

<!-- 2016/06/17 -->

<p>A customer using Active Directory with Kerio Connect needed to change the email addresses for several users. He coukdn't simply use an alias as another piece of software needed to authenticate and send with these names.</p>
<p>He tried just changing the names in AD, but that removed the old addresses from view.  Kerio Support suggested this:</p>
<p>Stop Kerio Connect Server.

Navigate to the store, and locate each user's folder in turn.

<br />There will be a folder for the new username, and a folder for the old username.

<br />Rename the new user folder to something along the lines of newADusername_error

<br />Rename the old user folder to EXACTLY the new AD username.

<br />Start Kerio Connect Server, and the software should hook up to the "old" folders.
</p>



<p style="word-break: break-word; max-width: 100%; color: rgb(70, 70, 70); font-family: -apple-system-font; font-size: 17px; font-style: normal; font-variant: normal; font-weight: 300; letter-spacing: normal; line-height: 24px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-tap-highlight-color: rgba(26, 26, 26, 0.301961); -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;">-- This feed and its contents are the property of A.P. Lawrence, and use is subject to our terms. It may be used for personal consumption, but may not be distributed on a website.</p><br class="Apple-interchange-newline">

]]>
</description>
<link>http://aplawrence.com/Kerio/AD-address.html</link>
</item>
<item rdf:about="http://aplawrence.com/Kerio/google-dns-truncates.html">
<title>Odd DNS issue with Google  </title>
<description>
<![CDATA[

<!-- <html><head><title>Odd DNS issue with Google</title></head><body> -->

<!-- 2015/11/30 -->

<p>A customer in Ohio called me early this morning. Mail was not working and browsing was also intermittently failing. This had also happened to him two days earlier, but before I could locate a cause, it had mysteriously fixed itself. But here it was again.</p>
<div style="text-align:center">

<p><a href="http://aplawrence.com/cgi-bin/showpic.pl?image=google-dns-truncates_lg.jpg&amp;mytitle=DNS%20failures&amp;returnpage=Kerio/google-dns-truncates.html&amp;returntitle=Odd%20DNS%20issue%20with%20Google"><img src="http://aplawrence.com/images/google-dns-truncates.jpg" alt="DNS failures" title="DNS failures (click for larger view)" /></a></p>

</div>
<p>Notice my email in that log: it says my aplawrence.com domain does not exist. Well, that's wrong..</p>
<p>I first logged into his email server with ssh and confirmed that it could not resolve hosts.  His /etc/resolv.conf pointed at the Kerio Control firewall, so I checked there.  Oddly, Ip Tools there could resolve hosts. What could be wrong?</p>
<p>I turned on DNS debugging and could see that it was contacting Google's public servers as it was configured to. However, it was saying that responses were truncated.  I tried switching the DNS to their ISP's DNS, but nothing changed. At that point, I called Kerio.</p>
<p>After some false starts and rechecking of things I had already done, Vladimir at Kerio suggested trying a Czech DNS server: 195.113.144.194.  That started working instantly.</p>
<p>So what's going on?  I'm not sure. I think maybe Google is having a local problem there and maybe IP Tools ignores the truncate bit?  Maybe the ISP is using Google DNS itself? I do not know. I have posted to Google's public DNS forum to notify them of the error; I've seen no response yet.</p>



<p style="word-break: break-word; max-width: 100%; color: rgb(70, 70, 70); font-family: -apple-system-font; font-size: 17px; font-style: normal; font-variant: normal; font-weight: 300; letter-spacing: normal; line-height: 24px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-tap-highlight-color: rgba(26, 26, 26, 0.301961); -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;">-- This feed and its contents are the property of A.P. Lawrence, and use is subject to our terms. It may be used for personal consumption, but may not be distributed on a website.</p><br class="Apple-interchange-newline">

]]>
</description>
<link>http://aplawrence.com/Kerio/google-dns-truncates.html</link>
</item>
<item rdf:about="http://aplawrence.com/Kerio/slow-folder-response-outlook.html">
<title>Slow loading folders in Outlook with Kerio Connect  </title>
<description>
<![CDATA[

<!-- <html><head><title>My Outlook folders are  slow loading, slow to search and slow to change</title></head><body> -->

<!-- 2015/11/19 -->


<p>Anonymous asks: <br />
<p><i>I'm running Kerio Connect Mail Server and my Outlook folders are  slow loading, slow to search and slow to change.</i></p>
<p>The solution to this is to turn on caching. By default, only your INBOX is cached, which leaves everything else to be reloaded whenever you want access.</p>
<p><a href="http://kb.kerio.com/product/kerio-connect/email-clients/kerio-outlook-connector/synchronizing-microsoft-outlook-with-kerio-connect-1467.html">Synchronizing Microsoft Outlook with Kerio Connect</a> explains:</p>
<pre>
The default synchronization works as follows:

Inbox — whole messages are synchronized.
Other email folders — only message headers and body in plain text are synchronized.
Events — whole events are synchronized.
Contacts — whole contacts are synchronized.
Tasks — whole tasks are synchronized.
Notes — whole notes are synchronized.

Upon each startup of Microsoft Outlook, Kerio Outlook Connector synchronizes the currently opened folder first.

</pre>
<p>This can be changed; the link explains how. Don't neglect the "Set also to all subfolders".</p>
<div style="text-align:center">

<p><img src="http://aplawrence.com/images/slow-folder-response-outlook.jpg" alt="Synchronizing other folders" title="Synchronizing other folders " /></a><br /></p>

</div>
<p>Of course this does require additional local storage. You might also want to know the cached data is not encrypted.</p>



<p style="word-break: break-word; max-width: 100%; color: rgb(70, 70, 70); font-family: -apple-system-font; font-size: 17px; font-style: normal; font-variant: normal; font-weight: 300; letter-spacing: normal; line-height: 24px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-tap-highlight-color: rgba(26, 26, 26, 0.301961); -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;">-- This feed and its contents are the property of A.P. Lawrence, and use is subject to our terms. It may be used for personal consumption, but may not be distributed on a website.</p><br class="Apple-interchange-newline">

]]>
</description>
<link>http://aplawrence.com/Kerio/slow-folder-response-outlook.html</link>
</item>
<item rdf:about="http://aplawrence.com/Kerio/packets-on-wan-interface.html">
<title>Packets on wrong interface  </title>
<description>
<![CDATA[

<!-- <html><head><title>Packets on wrong interface</title></head><body> -->

<!-- 2015/11/18 -->

<p>I had an interesting exercise earlier this week. I'm going to simplify things to make it easier to understand, but the basic idea is that the customer had his ISP's equipment installed some 300 feet from where all the computing equipment was.  His Kerio router therefore got its WAN connection at the end of a long wire.</p>
<p>That connection was slow, so he recently had a new, higher speed connection put in.  He couldn't just switch over, so temporarily he'd need both.  Running a new wire from Kerio Control would have been a major project, but fortunately there was one other unused wire running from where the ISP connections were. Unfortunately that connection did not go near the Kerio but instead reached a LAN switch that serviced exactly one piece of equipment and then joined the rest of the network.  Would that work, he asked?</p>
<p>I said it would but it could cause some issues.  It wasn't entirely clear to me where this switch was and how everything would flow, but as it turned out most things worked and he was able to test out the new connection using load balancing.</p>
<p>But some computers did not work.  The problem was obvious when we looked at the logs.</p>
<pre>
[13/Nov/2015 06:24:00] from WAN2, proto:TCP, len:52, 192.168.141.103:54315 -> 104.25.139.21:80, flags:[ SYN ], seq:3723491087 ack:0, win:8192, tcplen:0
[13/Nov/2015 06:24:03] from WAN2, proto:TCP, len:52, 192.168.141.103:54314 -> 104.25.138.21:80, flags:[ SYN ], seq:1889551147 ack:0, win:8192, tcplen:0
[13/Nov/2015 06:30:54] from LAN Switch, proto:TCP, len:1489, 192.168.130.101:50185 -> 104.25.139.21:80, flags:[ ACK PSH ], seq:1910086646 ack:73727308, win:4096, tcplen:1437
</pre>
<p>Packets from 192.168.x.x should not be "from WAN2"; they should always be "from LAN Switch".  A managed switch could make sure that never happens, but he didn't have that ability.  What to do?</p>
<p>I really couldn't think of anything.  It wasn't really critical as the new circuit is intended to replace the old in a few weeks, but it woould be easier if he could keep this working until then.</p>
<p>Then it hit me. Why on earth was the Kerio router 300 feet from the two ISP drops? I called the customer back and asked him how difficult it would be to move the router to that space and connect it to the ISP's there? There was a short pause and he answered that yes, of course, that was the way to do it and no it would not be difficult. </p>
<p>Sometimes you have to back up and look at the bigger picture.</p>



<p style="word-break: break-word; max-width: 100%; color: rgb(70, 70, 70); font-family: -apple-system-font; font-size: 17px; font-style: normal; font-variant: normal; font-weight: 300; letter-spacing: normal; line-height: 24px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-tap-highlight-color: rgba(26, 26, 26, 0.301961); -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;">-- This feed and its contents are the property of A.P. Lawrence, and use is subject to our terms. It may be used for personal consumption, but may not be distributed on a website.</p><br class="Apple-interchange-newline">

]]>
</description>
<link>http://aplawrence.com/Kerio/packets-on-wan-interface.html</link>
</item>
<item rdf:about="http://aplawrence.com/Forum/archive-folder-not-seen.html">
<title>Archive folder not seen in Kerio Connect  </title>
<description>
<![CDATA[

<!-- <html><head><title>Archive folder not seen in Kerio Connect</title></head><body> -->

<!-- 2015/11/16 -->

<p>Anonymous asks: <br />
<p><i>I Unzipped July of 2015 in the archive directory..  Waited an hour and it still complains about missing folders..  Had it rebuild but still complains..</i></p>
<p></p>
<div style="text-align:center">

<p><img src="http://aplawrence.com/images/archive-folder-not-seen.jpg" alt="Archive folder not seen in Kerio Connect" title="Archive folder not seen in Kerio Connect" /></a><br /></p>

</div>
<p>It would be very unlikely for folders to be missing from an archive - almost impossible.</p>
<p>Did you stop Kerio Connect before unzipping the folder? While it is often possible to get away with shoving things into a running server and letting it fix things up, that's not the best chance of success. If you repeat this with the server stopped, it likely will be correct.</p>



<p style="word-break: break-word; max-width: 100%; color: rgb(70, 70, 70); font-family: -apple-system-font; font-size: 17px; font-style: normal; font-variant: normal; font-weight: 300; letter-spacing: normal; line-height: 24px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-tap-highlight-color: rgba(26, 26, 26, 0.301961); -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;">-- This feed and its contents are the property of A.P. Lawrence, and use is subject to our terms. It may be used for personal consumption, but may not be distributed on a website.</p><br class="Apple-interchange-newline">

]]>
</description>
<link>http://aplawrence.com/Forum/archive-folder-not-seen.html</link>
</item>
<item rdf:about="http://aplawrence.com/Kerio/expired-no-check.html">
<title>My license has expired. Didn't you get our payment?  </title>
<description>
<![CDATA[

<!-- <html><head><title>My license has expired. Didn't you get our payment?</title></head><body> -->

<!-- 2015/11/11 -->


<p>Yes, I probably did and I most likely renewed your license the same day or the day after. I then would have sent you an email saying this:</p>
<blockquote>
<p>We have processed your order for  (license number)</p>
<p>
This license should update automatically and the correct dates and users should appear in your administration screen.  If it does not, you will need to register the license from the web administration interface or at https://secure.kerio.com/reg/ to create the license file that will activate your Kerio product.
</p>
</blockquote>
<p>Did you notice the word "should" and the sentence that follows?  The reason that I put that in is that sometimes your server doesn't make the proper communication with Kerio to activate the license. It should happen automatically, but it may not. This might be because you haven't upgraded your version recently or it might be because a firewall is blocking that communication. Whatever the reason, you need to either fix that or register your license as explained above. That's a simple process and of course I'm right here at the other end of your phone line if you have any problem. You can also call Kerio directly if it is two A.M my time and you really need to get this done!</p>

<div style="text-align:center">

<p><a href="http://aplawrence.com/cgi-bin/showpic.pl?image=expired-no-check_lg.jpg&amp;mytitle=downloading%20kerio%20license&amp;returnpage=Kerio/expired-no-check.html&amp;returntitle=My%20license%20has%20expired.%20Didn't%20you%20get%20our%20payment?"><img src="http://aplawrence.com/images/expired-no-check.jpg" alt="downloading kerio license" title="downloading kerio license (click for larger view)" /></a></p>

</div>



<p style="word-break: break-word; max-width: 100%; color: rgb(70, 70, 70); font-family: -apple-system-font; font-size: 17px; font-style: normal; font-variant: normal; font-weight: 300; letter-spacing: normal; line-height: 24px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-tap-highlight-color: rgba(26, 26, 26, 0.301961); -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;">-- This feed and its contents are the property of A.P. Lawrence, and use is subject to our terms. It may be used for personal consumption, but may not be distributed on a website.</p><br class="Apple-interchange-newline">

]]>
</description>
<link>http://aplawrence.com/Kerio/expired-no-check.html</link>
</item>
<item rdf:about="http://aplawrence.com/Forum/Maximal-authentication-attempts.html">
<title>Maximal amount of unsuccessful authentication attempts reached, IP address is blocked  </title>
<description>
<![CDATA[

<!-- <html><head><title>Maximal amount of unsuccessful authentication attempts reached, IP address is blocked</title></head><body> -->

<!-- 2015/10/30 -->


<p>Anonymous asks: <br />
<p><i>How do you unblock IP’s in the firewall?  Our California Warehouse VPN got locked out. Log says "Maximal amount of unsuccessful authentication attempts reached, IP address is blocked."</i></p>
<p>
This happens because of a setting you probably forgot all about.  It's particularly easy to forget if you aren't authenticating through a domain controller, because it's in that section of your control configuration.</p>
<div style="text-align:center">

<p><a href="http://aplawrence.com/cgi-bin/showpic.pl?image=Maximal-authentication-attempts_lg.jpg&amp;mytitle=locking%20out%20vpn%20connnections&amp;returnpage=Forum/Maximal-authentication-attempts.html&amp;returntitle=Maximal%20amount%20of%20unsuccessful%20authentication%20attempts%20reached,%20IP%20address%20is%20blocked"><img src="http://aplawrence.com/images/Maximal-authentication-attempts.jpg" alt="locking out vpn connnections" title="locking out vpn connnections (click for larger view)" /></a><br /></p>

</div>
<p>It also says nothing about VPN's, so you are forgiven if you did not think to look here. Ordinarily, blocking goes away after five minutes, but if your VPN connection kept trying with a bad password, it will get locked out again and again.</p>
<p>Fix the password or add that address to a "Never Block" group.</p>



<p style="word-break: break-word; max-width: 100%; color: rgb(70, 70, 70); font-family: -apple-system-font; font-size: 17px; font-style: normal; font-variant: normal; font-weight: 300; letter-spacing: normal; line-height: 24px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-tap-highlight-color: rgba(26, 26, 26, 0.301961); -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;">-- This feed and its contents are the property of A.P. Lawrence, and use is subject to our terms. It may be used for personal consumption, but may not be distributed on a website.</p><br class="Apple-interchange-newline">

]]>
</description>
<link>http://aplawrence.com/Forum/Maximal-authentication-attempts.html</link>
</item>
<item rdf:about="http://aplawrence.com/Forum/two-outlook-accounts.html">
<title>Is it possible to have two email accounts on the same Outlook?  </title>
<description>
<![CDATA[

<!-- <html><head><title>Is it possible to have two email accounts on the same Outlook?</title></head><body> -->

<!-- 2015/10/09 -->


<p>Anonymous asks: <br />
<p><i>Is it possible to have two email accounts on the same Outlook? One of our users needs to periodically check another's account.</i></p>
<p>With or without Kerio, yes, it's possible, though if it were me, I'd just forward one to the other, leaving the original. You could create an Outlook rule to store those messages in a different folder if you like.</p>
<p>If you really want two accounts, there are two ways to do it. One is simply to create another profile and switch to that when you want to use the other account.  The other way lets you add multiple accounts to a single profile.  That requires Outlook 2010 and Kerio 8.3 or newer and manual configuration of the additional accounts.  Kerio has a KB article that covers all that.</p>
<p><a href="http://kb.kerio.com/product/kerio-connect/email-clients/kerio-outlook-connector/adding-multiple-accounts-in-a-single-profile-in-microsoft-outlook-1598.html">Adding multiple accounts in a single profile in Microsoft Outlook</a></p>
<p><a href="http://kb.kerio.com/product/kerio-connect/email-clients/kerio-outlook-connector/creating-profiles-in-ms-outlook-1465.html#sect-createprofilemanual">Manually creating profiles in MS Outlook</a></p>





<p style="word-break: break-word; max-width: 100%; color: rgb(70, 70, 70); font-family: -apple-system-font; font-size: 17px; font-style: normal; font-variant: normal; font-weight: 300; letter-spacing: normal; line-height: 24px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-tap-highlight-color: rgba(26, 26, 26, 0.301961); -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;">-- This feed and its contents are the property of A.P. Lawrence, and use is subject to our terms. It may be used for personal consumption, but may not be distributed on a website.</p><br class="Apple-interchange-newline">

]]>
</description>
<link>http://aplawrence.com/Forum/two-outlook-accounts.html</link>
</item>
</rdf:RDF>
