RV220W - Content Filtering and Tivo

After using an RV220W in the Office fdr some time I decided to upgrade my old WRVS4400N V1 with one - in line with Cisco recommendations. I am using the latest firmware 1.0.4.17.
One problem I have is that a Tivo device will not connect to its contect servers in the outside world when any Content Filtering is active. I have tried setting up a firewall rule to give complete outbound access for the device for all services but that did not help. The only thing that allows the Tivo to connect properly is to either turn off Content filtering completely  - in which case some of the router protection is lost, or to select some other port in the HTTP port selection box (I tried port 79) - in which case content protection functionality on port 80 is also lost. I have also tried turning off (deselecting) all the other content filtering options but the device can still cannot connect if Content Filtering is enabled.
It seems to me that setting a firewall rule to allow ALL outbound from the device should be enough to allow connection. What is Content Filtering doing that prevents this device from connecting? And why can't I override it with the firewall rules? This seems to be the same as an old thread many releases of firmware ago:   RV220W - Connecting to TiVo mothership w/ ProtectLink
Why is this the only router that seems to have this problem? Will it cause other issues?
If this is because of some internal behaviour of the ruleset then Content Filtering needs to be able to be excluded for a "trusted" internal IP address.
thanks,
David Wyatt

Hello,
I've opened case # 621056469. The support engineer told me that he'll try to reproduce the problem on his side, and contact me back for remote testing on my own router. If the issue is already known, does it have some kind of ref number so that I can inform him ? Is a fix already planned for  a future firmware release ?
Thanks for your help.

Similar Messages

  • How do I create Outgoing Mail Policie,Outgoing content filters and individual content filters?

    IronPort C160.
    async OS 6.5.3
    Server 1 and server 2 are communicating through ironport.( and also scanning)
    Server 1 we have setup domain abc.lk and yy.abc.lk in same server, this reside on DMZ. same segment ironport is connected,
    Server 2: we have setup separate server int.abc.lk which is resided on internal lan.
    Server 1 and server 2 should have to communicate internally, but server2 should not communicate to outside the world (eg. [email protected])
    How do I create "Outgoing Mail Policies, Outgoing content filters and the individual content filters?
    Note: Now server 1 and server2 are communicating internal and also communicating external ([email protected]), I need server 2 not to communicate external ([email protected]) it should be block and also do not block server 2 communicating to server1
    I have attached diagram also.
    Thanks.
    sumathi.

    /* Style Definitions */
    table.MsoNormalTable
    {mso-style-name:"Table Normal";
    mso-tstyle-rowband-size:0;
    mso-tstyle-colband-size:0;
    mso-style-noshow:yes;
    mso-style-parent:"";
    mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
    mso-para-margin:0cm;
    mso-para-margin-bottom:.0001pt;
    mso-pagination:widow-orphan;
    font-size:10.0pt;
    font-family:"Times New Roman";
    mso-ansi-language:#0400;
    mso-fareast-language:#0400;
    mso-bidi-language:#0400;}
    Hello Sumathi,
    (Thanks for adding a diagram, that helps understanding your situation)
    I think the simplest solution is to create a filter that allows server 2 (based on it's IP) to communicate with the internal domains, and drop the messages when they are targeted to any other domain
    so:
    filter source IP = servers
    condition: message to: is NOT abc.lk or yy.abc.lk
    action: drop message
    hope this helps!
    Steven

  • Rv220w- content filtering ignoring firewall rules

    Hello,
    I face a strange bahavior with my rv220w router : I set up access rules to deny all outbound trafic for a particular IP range. It seems to work fine .... but when I enable content filtering, HTTP  access on port 80 works again (and other ports are denied). It seems that activating content filtering makes the router ignore firewall rule. Bug ? Or did I miss someting ?
    Thanks in advance for your help.

    Hello,
    I've opened case # 621056469. The support engineer told me that he'll try to reproduce the problem on his side, and contact me back for remote testing on my own router. If the issue is already known, does it have some kind of ref number so that I can inform him ? Is a fix already planned for  a future firmware release ?
    Thanks for your help.

  • RV220W - Content filtering not working (?)

    Hello, I bought a router model RV200W fw 1.0.1.0... nice toy.
    It all works very well with the exception of content filtering. The rule only works if connections are made with the HTTP protocol, but if the user connects with HTTPS, then the rule is not considered... (???)
    f.e.:
    http://facebook.com (content filtered)
    https://facebook.com (content NOT filtered)...
    What the hell ! where I'm wrong ?
    Does anyone is experiencing the same ?

    Yes, the correct title was "URL FILTERING NOT WORKING"...thanks abudef000
    I do not want be polemical, but I do not understand where I went wrong.
    Before I buy I looked @
    http://www.cisco.com/en/US/prod/collateral/routers/ps9923/ps11025/data_sheet_c78-630461.html
    Check it out.
    Could you assume that HTTPS URLs are not in the sentence "Static URL blocking, keyword blocking, approved URL" as stated in the product sheet ?

  • Content filters and SL/BL

    I have been working on an problem that I cannot seem to get an answer to.
    I have a c300 set up with local quarantine. I turned on the EUQ and the SL/BL options.
    I have a content filter;
    Spam_Review: if (dictionary-match("Spam_Review", 2)) { strip-header("Subject"); insert-header("Subject", "[Possible Spam-MX1] $Subject"); alt-mailhost ("the.euq.queue"); }
    The problem is that the SL/BL is not working. I have an address in my SL and when I send an email that triggers the content filter the items still gets quarantined even though the address is in my SL.
    I Have checked the message headder information when I release the message from the quarantine and it shows the following:
    X-SLBL-Result: SAFE-LISTED
    My question is, can the content filter be used to quarantine messages and still work with the SL/BL?

    Hi rnarvaez,
    Unfortunately the answer to your question is NO. IronPort filters, quarantines and SL/BL are architectured such that admin always get the final say over user preference.
    So, if a user has an entry for an address or a domain listed in SL but the message triggers a filter setup by the admin then message will have the action setup in the filter.
    -Kishore

  • DHCP reservation & DNS for content filtering

    Hi All,
    I am working around with server 2008 for quite a while and facing a problem as below,
    1.DHCP reservation error
    Server Ip:192.168.0.254 (configured as DNS server for local use only with AD & DHCP)
    DHCP scope: 192.168.0.100 to 192.168.0.200 excluded 192.168.0.100 to 192.168.0.110
    earlier the same scope was 192.168.0.10 to 192.168.0.100. I was facing a error when I make a IP reservation against a MAC number error was " The unique identifier may not be correct do you want to use the identifier anyway" when I click yes "DHCP
    server received a message from a client that is not valid" and by this error I am not able to make any reservations now against MAC numbers.
    The same error was also on the earlier scope and that's why changed to a new scope but did not work. Any solutions will me much appreciated
    2.DNS fine tuning. 
    I have an open DNS account on which my WAN IP number is configured to do a content filtering. I have two LAN ports with the below IP number
    Local : 192.168.0.254 ( configured with no gateway and DNS as loopback (127.0.0.1)
    ISP: 192.168.0.253 (with ISP gateway and DNS as loop back adapter & open DNS)
    I have did a content filtering and things are working fine. But I got to open up some machines out of this content filtering and when I try to give the IP number in this below fashion.
    192.168.0.115
    255.255.255.0
    192.168.0.1
    DNS
    192.168.0.254
    ISP DNS to avoid filtering
    I find that 192.168.0.254 does the resolving and things are still filtered as per the schedule. Is there a way where we can configure 192.168.0.254 (Local DNS server) to stop resolving web requests and only cater to resolving local names for connectivity.
    I do know its too long but solutions for the same will be help me out to solve it. Thanks in advance.
    Regards,
    Vaschell

    Hello,
    I have found something strange on the DHCP reservation. When I try to add a MAC number out of the network its able to make out a reservation.
    Is there any way to clear the MAC number cache or something else which I can try.
    A copy of the ipconfig /all for the server is below,
    C:\Users\Administrator>ipconfig /all
    Windows IP Configuration
       Host Name . . . . . . . . . . . . : server
       Primary Dns Suffix  . . . . . . . : xyzabc.com
       Node Type . . . . . . . . . . . . : Hybrid
       IP Routing Enabled. . . . . . . . : Yes
       WINS Proxy Enabled. . . . . . . . : No
       DNS Suffix Search List. . . . . . : xyzabc.com
    Ethernet adapter LOCAL:
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Intel(R) I210 Gigabit Network Connectio
    #2
       Physical Address. . . . . . . . . : 00-1E-67-A4-F4-DC
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       IPv4 Address. . . . . . . . . . . : 192.168.0.254(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Default Gateway . . . . . . . . . :
       DNS Servers . . . . . . . . . . . : 127.0.0.1
       NetBIOS over Tcpip. . . . . . . . : Enabled
    Ethernet adapter ISP:
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Intel(R) I210 Gigabit Network Connectio
       Physical Address. . . . . . . . . : 00-1E-67-A4-F4-DB
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       IPv4 Address. . . . . . . . . . . : 192.168.0.253(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Default Gateway . . . . . . . . . : 192.168.0.1
       DNS Servers . . . . . . . . . . . : 127.0.0.1
                                           208.67.222.222
                                           208.67.220.220
       NetBIOS over Tcpip. . . . . . . . : Enabled
    PPP adapter RAS (Dial In) Interface:
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : RAS (Dial In) Interface
       Physical Address. . . . . . . . . :
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       IPv4 Address. . . . . . . . . . . : 192.168.0.205(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.255
       Default Gateway . . . . . . . . . :
       NetBIOS over Tcpip. . . . . . . . : Disabled
    Tunnel adapter Local Area Connection* 8:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : isatap.{0602F6CF-4B32-491F-994A-3C0952D
    B54}
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 9:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : isatap.{6A14710B-A078-4AF9-BD7A-989767F
    377}
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 11:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
       Physical Address. . . . . . . . . : 02-00-54-55-4E-01
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 12:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter #3
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    C:\Users\Administrator>
    Thanks,
    Vaschell

  • Cisco Content Engine for Content Filtering

    Hi All,
    I am looking for a low end solution for Content Filtering and would like to use Cisco Content Engine.
    1. The documentation said that Websense, Secure Computing SmartFilter (does not require separate SmartFilter) & N2H2 support is there on the CE. I used configurator on CE 510, but it did not give me option for any of those. I would appreciate any input in this regard.
    2. Also, I assume that once I get a Content Engine, I don't need to use Microsoft Proxy any more, please confirm.
    regards,
    Ahmer Ghazi

    You would have to Install the Smartfilter software on the Content engine that would work with the ACNS software running on the CE. SmartFilter software operates inside your network to control user access to external Internet resources and allows you to restrict access to World Wide Web pages, newsgroups, and FTP sites.
    For more details refer:
    http://www.cisco.com/univercd/cc/td/doc/product/webscale/uce/acns41/smrtfltr/sf_chap1.htm
    The Content Engine does the job of storing content locally and serving it to the users, so you would not need to use the Microsoft Proxy.

  • Content filtering after quarantine

    Hi,
    does anyone know if it's possible to reapply the content filtering to a mail that has been quarantine by one content filter.
    For example if I setup 10 content filters and the 2nd one quarantine the message because of a particular content, the administrator check the mail and after accept it, the mail need to pass trough the remaining 8 content filters and not been immediately delivered to the recipients.
    Is it possible?
    Thank you.

    A quarantine action on a content filter does not immediately deliver the message to the quarantine as it is a non-final action (unless you have included a deliver() action on the filter) it only flags it for quarantine - the message will pass through the rest of the email pipeline (including any other content filters) - assuming that it does not get any other final actions (drop, bounce, deliver) the email will then be quarantined (and it can be quarantined in multiple quarantines depending on results from other filters). When the message is released it will be rescanned for viruses if you have antivirus scanning enabled before it is delivered but not be subject to any other filters.

  • Content filtering, I think...

    So I listen to Bubba the Love Sponge on Radioio.com.  There web browser player uses Adobe Flash and there desktop players uses Air.  I can listen to all of the radioio music stations with no problem, but when I try to listen to Bubba's 2 stations the player won't work.  I've contacted the Radioio support team and they have no idea why only the bubba stations are being blocked.  I'm running Windows 7 Pro.  I've checked the content filter on Windows 7 and it's not turned on.  I've check both Internet Explorer's and Firefox content filtering and they are set to the lowest setting possible.  I've tested it on a comple computers in the office that are running XP pro and it work's fine,  I've tested his channels on my home computer that has windows 7 home and it works fine.  So there is something on my windows 7 pro computer at work that is stopping the feed.  I've checked every other part out and I'm down to it either being Adobe Flash or Adobe Air.  I really hope someone knows what's going on.
    Thanks for you help
    Jeffr

    In article <[email protected]>, Sjdimare wrote:
    > But if it would be difficult to remove from NDS, then I am not sure it
    > will be worth it. It looks like it should be an easy removal but I
    > wanted to confirm that.
    >
    It doesn't really 'integrate with NDS'. You load it (and unload it)
    with an NCF file. You use it in BMgr by adding an access rule. Simply
    don't load the NCF file and remove the rule, and it doesn't run. To
    delete it entirely, you just delete the linkwall folder where it puts
    its files.
    Craig Johnson
    Novell Support Connection SysOp
    *** For a current patch list, tips, handy files and books on
    BorderManager, go to http://www.craigjconsulting.com ***

  • How can I set my content filtering to allow me to access all my email and applications

    I got an email and tried to view the information on the link but could not due to content filtering

    Hi ms.B,
    What are you using for content filtering?

  • BBSM and Content Filtering

    Is it possible to force web requests from a BBSM through an upstream (authenticated) web proxy running (which performs web filtering). I'm getting the impression that this isn't directly possible unless WCCP is utilised. The BBSM uses ISA server as its proxy server, but it's not clear whether this configuration can work in a chained proxy environment to provide filtered public access. Is this possible?

    Hello,
    Thanks for helping. I have attached the config-file. (Username and pwd for PPPoE has been edited though).
    The box came with firmware version 1.0.15. I upgraded to the latest version 1.1.42 in an attempt to solve the problem, but the behaviour is the same between these two versions wrt. the problem at hand.
    When trying to open up web pages that I perceived as "haning" or "blocked", they appear to be working now.
    Maybe that was "wrong user observation" :-) Nevertheless, the "Content Filtering" still has to be enabled to let anything at all through, so that observtaion is still valid. The default config is content filtering disabled. With this config, the firewall will not work "out of the box", and it is tricky to find why.
    Another observation I made is that when making one PPPoE profile, it is not possible to open this for editing. It works when you have two or more profiles. But as long as you have only one profile, it can't opened for editing. The workaround is to make a second profile.
    Thanks.

  • High Amount of Spam on Exchange 2013 - Content Filtering is Enabled but Pfizer Spam Filling Up Everyone's Mailboxes

    Hello
    Previously I used Exchange 2010 with Forefront Threat Protection installed and this used to do a good job of stopping all the spam.
    However since updating to Exchange 2013 earlier this year and enabling the integrated spam filtering everyone noticed a sudden increase in the amount of spam which was getting through which has been bad for a long time.
    We have been living with it but in the last 3 weeks everyone has started getting about 40 emails a day from Pfizer for Viagra. All these seem to defeat the content filtering as Viagra is spelt with an extra I and the email address is always different.
    Also images in emails are blocked by default but somehow all the images on these spam messages appear for everyone.
    I am not sure the spam filtering is working at all and I'm not sure how to tell as ForeFront gives you a nice graphical dashboard but I can find nothing similar to this in Exchange and PowerShell seems the only way to configure the limited functionality
    of the content filter.
    Is there any way to get rid of these messages as it doesn't look very good when they are constantly popping up for everyone?
    Thanks
    Robin
    Robin Wilson

    Hello ManU
    Thanks for the reply.
    I have checked the logs and see this quite often:
    AcceptMessage,,SCL,not available: policy is disabled
    But other times it says this:
    RejectMessage,550 5.7.1 Message rejected as spam by Content Filtering
    Which seems to indicate it is rejecting some.
    This is what one of the email headers look like:
    Received: from RWS-MAIL.rwsservices.net (192.168.2.151) by
    RWS-MAIL.rwsservices.net (192.168.2.151) with Microsoft SMTP Server (TLS) id
    15.0.775.38 via Mailbox Transport; Sat, 28 Dec 2013 10:59:26 +0000
    Received: from RWS-MAIL.rwsservices.net (192.168.2.151) by
    rws-mail.rwsservices.net (192.168.2.151) with Microsoft SMTP Server (TLS) id
    15.0.775.38; Sat, 28 Dec 2013 10:58:38 +0000
    Received: from [90.169.106.204] (90.169.106.204) by mail.rwsservices.net
    (192.168.2.151) with Microsoft SMTP Server id 15.0.775.38 via Frontend
    Transport; Sat, 28 Dec 2013 10:58:37 +0000
    Date: Sat, 28 Dec 2013 12:05:58 +0200
    From: US.Pfizer eStore <[email protected]>
    To: robin.wilson <[email protected]>
    Message-ID: <[email protected]>
    Subject: Dear robin.wilson up to 65% OFF!
    X-Mailer: Airmail (223)
    MIME-Version: 1.0
    Content-Type: multipart/mixed; boundary="dd2ee3ea_586bb9e4_6f04"
    Return-Path: [email protected]
    X-MS-Exchange-Organization-PRD: 001-taxis.co.uk
    X-MS-Exchange-Organization-SenderIdResult: Neutral
    Received-SPF: Neutral (rws-mail.rwsservices.net: 90.169.106.204 is neither
    permitted nor denied by domain of [email protected])
    X-MS-Exchange-Organization-Network-Message-Id: e8825204-1f32-48be-a331-08d0d1d30209
    X-MS-Exchange-Organization-SCL: 1
    X-MS-Exchange-Organization-PCL: 2
    X-MS-Exchange-Organization-Antispam-Report: DV:3.3.13223.464;SID:SenderIDStatus Neutral;OrigIP:90.169.106.204
    X-EXCLAIMER-MD-CONFIG: 079171ba-394f-46d5-a160-56e416712e8e
    X-MS-Exchange-Organization-AVStamp-Enterprise: 1.0
    X-MS-Exchange-Organization-AuthSource: rws-mail.rwsservices.net
    X-MS-Exchange-Organization-AuthAs: Anonymous
    The emails use a different sender email address every time and there is always a poem in very light grey writing in the body of the email. The drugs are always misspelt as well. Is this why these are getting through?
    Thanks
    Robin
    Robin Wilson

  • Exchange 2013 SP1 EDGE role content filtering ?

    Hello,
    Have Exchange 2013 SP1 with CU5 with antispam enabled on mailbox role server. And i wonder if i deploy 2013  Edge role, will i get more granular content filter control, like there is in Office 365? For example: i want to treat empty messages as not
    spam.
    I have read that control of Edge server is done ONLY by powershell. So if edge role is deployed, still there is no content filter control in ECP (like in office365) ??

    Hi,
    The Content Filter agent assigns a spam confidence level (SCL) rating to each message. The SCL rating is a number between 0 and 9. A higher SCL rating indicates that a message is more likely to be spam.
    Based on my knowledge, I'm afraid we can't filter the empty messages and treat them as not spam.
    Here is an article about content filtering in Exchange 2013 for your reference.
    Content Filtering
    http://technet.microsoft.com/en-us/library/bb124739(v=exchg.150).aspx
    Best regards,
    If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Belinda Ma
    TechNet Community Support

  • Conditions based on "EnvelopSender" in Content Filters

    When defining Content Filters, I need to define conditions based on the sender of an email. For example, if the sender is Jim or John, and Subject Line contains a tag [CONFIDENTIAL], the action should be to encrypt the mesasge.
    I realize this could easily be done using LDAP groups. But my problem is that for a number of opertaional reasons I cannot connect our IronPort to our corp LDAP. 
    An alternative is to directly code the user names in the condition statement. This is ugly and problematic for admins and possibly causes other problems as the number of users grows. Could anyone suggest an alternative?
    Is there any option of having the Condition statement open a file and read the "sender" names from the file maintained somewhere on the local or a remote disk? Any other option?
    Thanks.

    I would suggest looking at creating a dictionary that would list the addresses of the individuals. You can use that dictionary from which to base your planned action.  Using LDAP is by far the better option for keeping a list up to date, as the dictionary will need to be updated regularly as addresses change, added or removed.

  • Using Content filters (HTML Filter)

    Hello.
    I'm having problem displaying an html-page in the portal with an url-iview. The problem is that the portal is accessed using HTTPS, and the url-iview links to a html-page using http.
    This will generate a popup in internet explorer about unsecure content.
    I thought that a way to solve this could be to connect KM to the page and then let the url-iview show the html-page throw the KM Repository.
    This works fine, however there is still one problem.
    Inside the HTML page, there is <IMG src> tags that reffers to the http site.
    How can I configure HTML filters to rewrite all image and stylesheet references via KM instead of to the http-site?
    I've tried to understand the documentation on Content Filters (http://help.sap.com/saphelp_nw04/helpdata/en/55/921d7bb0c611d5993800508b6b8b11/content.htm), but I don't know what to write in "Base Tag" property, or ir this even works.
    Does anyone know if there is an example about this? Or perhaps know how to configure this?
    Regards, Mikael

    This can be done, but it might not be a optimal solution. You would basically parse each HTML file and replace the links before streaming the content. You can create your own version of com.sap.km.cm.docs component which streams the content of a HTML file by replacing the links. And you would use your own component for creating the KM doc iviews that way you will have altered HTML links.

Maybe you are looking for

  • IPod Nano: Error Message "The USB device has malfunctioned and Windows does not recognise it"

    Hi everyone, I just received 2 brand new iPod Nanos for my kids for Christmas, thought I'd be smart and sync them both now before wrapping them so I don't have to be messing around with them on the day. One synced without a problem, then using the sa

  • SRM 5.0 with XI 3.0

    Hi , Can I integrate SRM 5.0 with XI 3.0. Thanks & Regards, krian. Edited by: Kiran Ponnam on Jan 14, 2008 8:57 PM

  • Why is 'send' disabled for sending a message on my iPod touch?

    I can receive messages, browse the net, connect to iTunes so there is nothing wrong with my connection settings. I also have the latest iOS installed. I can type a response to a message, but can't send because the send button is disabled.

  • JSF tabbedPanel - nagivation by javascript?

    Hello all, I have got a tabbed panel which contains few static tabs, and few dynamic tabs. Users can add/remove those dynamic ones. I had a problem when users click on a link (command button link) on those dynamic one and jump to another page, when t

  • Saving documents in Pages

    I have Pages 09, version 4.2 running on OS X 10.7.5.  Once I open a new document I cannot close or save it.  the only function that works is the minimize button.  How can I fix this.  I am reasonably computer illiterate so simple is good  Thnx!