PROFESSIONAL FIGHTERS LEAGUE

PROFESSIONAL FIGHTERS LEAGUE

PFL Brussels

  • d
  • :
  • h
  • :
  • m
  • :
  • s
EVENT INFO

Kerio Control 942 Upd -

Because the 942 is an appliance, you cannot use the generic ISO installer (which is for PC installations). You need the appliance update file.

In the world of network security, the firewall is your first line of defense. For over a decade, Kerio Control (now owned by GFI Software) has been a staple for small to medium-sized businesses (SMBs), offering enterprise-grade features without the complexity or cost of high-end Cisco or Palo Alto solutions.

Among its hardware appliances, the Kerio Control 942 holds a special place. Known for its robust throughput (up to 1.8 Gbps firewall throughput) and deep packet inspection (DPI) capabilities, the 942 is a desktop-sized workhorse. However, like any security appliance, its effectiveness depends entirely on its software.

This article focuses entirely on the Kerio Control 942 UPD—where "UPD" typically refers to Update, Upgrade, or the Update Package Download process. We will cover everything from finding the correct firmware to troubleshooting failed updates, ensuring your appliance remains secure and performant.


If your KC942 is struggling to apply the latest UPD (frequent disk full errors), it is a sign of hardware aging. Plan to migrate to:


Kerio Control has historically been targeted by attackers. Notable past vulnerabilities (e.g., CVE-2019-13450, CVE-2017-9147) were patched via incremental updates. If your 942 is running a version from 2018, your network is exposed to remote code execution (RCE) and cross-site scripting (XSS) flaws.

If you are currently running Kerio Control 9.4.0 or 9.4.1, you should upgrade to 9.4.2 immediately. The security fixes alone warrant the update, and the improved VPN stability will reduce helpdesk tickets from remote users.

However, if you are running an older, stable branch (such as 9.3.x) and do not require the specific features of 9.4, standard IT prudence applies: wait until you have a maintenance window, though you should plan to migrate soon to maintain support eligibility.

Rating: 8/10 (A solid, necessary maintenance release that does exactly what it promises: fixes bugs and secures the network).

This "story" follows a fictional IT manager, Leo, as he navigates the critical importance of keeping network security software updated, specifically highlighting the real-world features and update details of Kerio Control 9.4.2. The Guardian of the Gateway: A Kerio Control Story

was the IT lead for a growing marketing firm. His "silent partner" in keeping the company’s data safe was GFI KerioControl, a Next-Generation Firewall (NGFW) designed specifically for small and medium businesses. The Vulnerability

One morning, Leo reviewed his system health and noticed his team was relying on an older build. While the firewall's intrusion prevention system was still active, he knew that staying current was the only way to combat evolving cyber threats. He decided it was time to move the firm to Kerio Control 9.4.2. The Mission: Updating to 9.4.2

Leo headed to the Kerio Software Archive to pull the latest build. He noted that this version brought critical stability, especially for their virtualized environment. kerio control 942 upd

Virtual Fixes: A known issue where virtual network adapters became unavailable on VMware deployments was resolved in the latest patches (9.4.2p1).

Kernel Strength: Version 9.4.x builds are based on Linux kernel 4.19, a significant step up from the older 3.16 kernel used in previous versions, offering better hardware compatibility and performance. Strengthening the Perimeter

Once updated, Leo leveraged the full suite of tools available in the 9.4.2 ecosystem:

Remote Access: He ensured the Kerio Control VPN Client was updated for his remote designers, providing them an encrypted tunnel to the private office network.

Content Management: He refined the Web Filter to block high-risk categories while allowing legitimate creative research.

Deep Monitoring: To troubleshoot a minor connection lag, Leo enabled SSH access by holding the Shift key while navigating to Status > System Health—a "secret" admin shortcut to reach the shell interface. The Result

By evening, the firm was running on Build 7290. Leo checked the logs one last time, confirming that all records were saving correctly to the disk. With the 9.4.2 update complete, he had successfully patched the "leaks" in his virtual infrastructure and bolstered the firm's defense against the next wave of attacks. System Requirements for Kerio Control - GFI

Kerio Control 9.4.2 represents a critical maintenance and performance update for GFI’s unified threat management (UTM) solution. Released on October 11, 2022, this version focused on core infrastructure stability and security enhancements to support modern network environments. Key Features and Enhancements

The 9.4.2 update introduced several foundational improvements designed to increase system security and administrative control:

Kernel Upgrade: A major system kernel update was implemented to improve hardware compatibility and overall system stability.

Enhanced 2FA for VPN: Administrators gained the ability to configure specific 2FA token expiration times for VPN sessions, providing a better balance between security and user convenience.

Reverse Proxy Redirection: The update added support for HTTP/S redirection within the reverse proxy settings, simplifying traffic management for hosted web services. Because the 942 is an appliance, you cannot

IPsec Improvements: Significant updates were made to the IPsec VPN and SNAT (Source Network Address Translation) modules to ensure more reliable encrypted tunnels. Performance Fixes

Beyond new features, version 9.4.2 addressed several legacy issues that affected performance:

Mac Upload Speeds: Resolved specific issues where macOS users experienced significant upload speed degradation.

RADIUS Authentication: Fixed authentication errors occurring when using RADIUS servers for Wi-Fi or VPN access.

Hyper-V Compatibility: Addressed a display issue where Hyper-V virtual appliances would incorrectly show interface details as "Legacy Network Adapter". Important: Kerio Control 9.4.2 Patch 1 (9.4.2p1)

Shortly after the initial release, GFI issued 9.4.2 Patch 1 (Build 7290) on October 17, 2022, to resolve critical bugs found in the initial rollout.

VMware Fix: Fixed a critical bug where virtual network adapters became unavailable on VMware deployments.

GRO Performance: Some users noted low internet throughput after the update, which can be resolved by adjusting the Generic Receive Offload (GRO) settings in the advanced configuration. How to Upgrade

To install this update, administrators can use the following methods through the GFI Kerio Control Web Administration: Kerio Control 9.4.2 Release Notes - GFI

Overview. Kerio Control 9.4. 2 has been released and is available for download. Release date: Oct 11, 2022. Build ID: 7279. support.keriocontrol.gfi.com Kerio Control 9.4.2p1 Release Notes - GFI

Kerio Control 9.4.2 is a maintenance update for GFI Software’s edge router and firewall solution, primarily focused on stability, security patches, and minor functional refinements. As a mid-cycle "update" (upd), it ensures the appliance remains compatible with evolving web standards and hardware environments. Key Features and Improvements Enhanced Security:

Includes updated VPN protocols and engine fixes to protect against the latest localized vulnerabilities. Improved Web Content Filtering: If your KC942 is struggling to apply the

Refinements to the Kerio Control Web Filter ensure more accurate categorization of URLs, helping administrators enforce corporate usage policies effectively. Stability Patches:

This version addresses known bugs from the 9.4.1 branch, particularly regarding memory management and high-availability (HA) sync issues. VPN Client Compatibility:

Provides better support for the latest versions of Windows, macOS, and Linux, ensuring remote workers maintain a stable connection to the corporate network. Why Upgrade to 9.4.2?

Staying current with the 9.4.2 update is critical for several reasons: Performance:

Optimized traffic inspection engines reduce latency during heavy packet inspection (DPI). Compliance:

Updated logging and reporting features help IT managers meet data security compliance requirements. Hardware Support:

Better driver integration for Kerio Control hardware appliances (NG series), reducing boot times and improving interface reliability. Installation Notes Before applying the 9.4.2 update, it is recommended to: Perform a Configuration Backup: Export your settings to MyKerio or a local file. Check Subscription Status:

Ensure your GFI Software maintenance is active to access the update files. Plan for Downtime:

While the update is generally quick, it requires a system reboot, which will temporarily interrupt internet connectivity. upgrade guide

for your specific deployment, such as a physical appliance or a virtual machine?


Legacy versions of Kerio Control (v7, v8) have a notoriously slow web admin interface. Updates significantly improve the HTML5 response time and the REST API reliability.


| Pros | Cons | | :--- | :--- | | Critical Security Fixes: Closes vulnerabilities found in the 9.4 branch. | No New Features: purely a maintenance release; no new UI or major functionalities. | | VPN Reliability: Significant reduction in random VPN tunnel drops. | Client Compatibility: Some older legacy VPN client versions may need to be updated on user workstations to match the server. | | Stability: Reduces system crashes and kernel panics on virtualized environments. | Licensing Checks: Some users report stricter licensing validation checks during the upgrade process. |

Log into the Web administration interface (https://your-firewall-ip:4040) and go to: Status → System Information Note the exact build number (e.g., 9.4.2 build 6248).