Welcome, Guest. Please login or register.
December 23, 2009, 09:16:16 AM

Login with username, password and session length

344596 Posts
38075 Topics
86420 Members

Latest Member: jdw00d

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Archive Boards
| |-+  Comodo Firewall
| | |-+  Bug Reports
| | | |-+  New My Network Zones entry not working
« previous next »
Pages: [1] Go Down Print
Author Topic: New My Network Zones entry not working  (Read 5415 times)
bladeanon
Newbie
*
Offline Offline

Posts: 10


« on: June 19, 2008, 02:51:12 PM »

In CFP 3.0.25.378 I just added a new entry to My Network Zones:
 - Name: My IP
 - Address Type: Single
 - Address: 192.168.1.1

I then added the Zone (My IP) to the destination address of a network policy rule. When trying to connect to the address Comodo passes the rule and prompts me to Allow/Deny the connection.

If I edit the policy rule and change the destination address to a Single IP (192.168.1.1) instead of a Zone (My IP) , it works just fine.

Funny thing is; I have a bunch of existing single address zones that seem to be working fine.

Any ideas?  Thanks.
Logged
bladeanon
Newbie
*
Offline Offline

Posts: 10


« Reply #1 on: June 19, 2008, 03:00:47 PM »

In CFP 3.0.25.378 I'm trying to set up a network policy rule for comms between safe networks:

My Network Zones
 - Name: Safe Networks
 - Address Type: Range
 - Address Start: 192.168.0.0
 - Address End: 192.168.255.255

I then added the Zone (Safe Networks) to the source and destination addresses of a network policy rule:

Network Control Rule
 - Action: Allow
 - Log: No
 - Protocol: IP
 - Direction: In/Out
 - Source Address: Zone: Safe Networks
 - Destination Address: Zone: Safe Networks
 - Source Port: Any
 - Destination Port: Any

This doesn't seem to work, even though the local and remote addresses for my connections are both in the Safe Network address range.  If I create two rules; one for inbound and one for outbound, it works.

Network Control Rule
 - Action: Allow
 - Log: No
 - Protocol: IP
 - Direction: In
 - Source Address: Zone: Safe Networks
 - Destination Address: Any
 - Source Port: Any
 - Destination Port: Any

Network Control Rule
 - Action: Allow
 - Log: No
 - Protocol: IP
 - Direction: Out
 - Source Address: Any
 - Destination Address: Zone: Safe Networks
 - Source Port: Any
 - Destination Port: Any

Any ideas?  Thanks.
Logged
gibran
Average User
Comodo's Hero
*****
Offline Offline

Posts: 5063


A bad workman always blames his tools


« Reply #2 on: June 19, 2008, 03:19:11 PM »

Network Control Rule
 - Action: Allow
 - Log: No
 - Protocol: IP
 - Direction: In/Out
 - Source Address: Zone: Safe Networks
 - Destination Address: Zone: Safe Networks
 - Source Port: Any
 - Destination Port: Any

This doesn't seem to work, even though the local and remote addresses for my connections are both in the Safe Network address range. 

Does Windows XP say your network adapter has limited or no connectivity?
Can you reset  your log and take a screenshoot of blocked packets in your logs and other global rules?
« Last Edit: June 19, 2008, 03:51:45 PM by gibran » Logged

"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams
bladeanon
Newbie
*
Offline Offline

Posts: 10


« Reply #3 on: June 19, 2008, 06:23:14 PM »

Thanks for combining my two reported issues - though I believe they separate problems...

Okay, regarding the In/Out to same Zone issue - No - my adapter does not have limited connectivity.

Attached screen shots for your reference.  Thanks.

PS - It's probably important to note that the 10.6.x.x addresses are from a Cisco VPN client and the 10.2.x.x addresses are part of the remote VPN network.
« Last Edit: June 19, 2008, 06:25:15 PM by bladeanon » Logged
sded
Guest
« Reply #4 on: June 19, 2008, 06:43:17 PM »

Take a look at http://forums.comodo.com/bug_reports/network_control_rule_cannot_only_change_the_description_3025378_x32-t23946.0.html and http://forums.comodo.com/bug_reports/bug_3025_x32_firewall_my_network_zones-t23520.0.html , other reccent 3.0.25 bug reports.  Seems to be related new issues in 3.0.25.  Suggestion would be to go back to 3.0.24 until the problem is fixed-I am still using that and have no such problems.  You can get it at http://filehippo.com/download_comodo/ .
Logged
gibran
Average User
Comodo's Hero
*****
Offline Offline

Posts: 5063


A bad workman always blames his tools


« Reply #5 on: June 19, 2008, 09:04:38 PM »

You may wish to export your configuration and revert back to a previous CFP version.

It looks that application rules have issues when a Network zone group is used.
Although the test cases are slightly different.

Does this issue affect Global rules in the same way?
Are non VPN networks affected in the same way?

On my machine here I setup a global rule to allow my LAN (one singe IP range) using allow IP IN/out source LAN dest LAN proto ANY followed by a block all IP in/out rule.

Lan connectivity was not affected.
Logged

"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams
AeoniAn
Comodo's Hero
*****
Offline Offline

Posts: 243


Protected & Armoured. COMODO is here!


« Reply #6 on: June 20, 2008, 07:56:27 PM »

I'm reverting too. v25.378 rules are not trustfull b/c they are forgotten...

THANK's for the advice.  And let's wait for a new version.  AGAIN!
Logged

CIS v574 full: Proactive, FW Custom, D+ Paranoid, IE normal, AV statf, heur med.
Sempron 3000+, MB MSI-7145, 1GB RAM
XP-SP3-Pro-BR x32 + W7-64 + Ubuntu LTS x64
ADM rights, Cable-PPPoA
PeerBlock v1.0+r
A-SquaredAM + MBAM + SAS (w/o any real-time)
Zero, Nada, No-one single infecction >49 months
bladeanon
Newbie
*
Offline Offline

Posts: 10


« Reply #7 on: June 20, 2008, 09:49:09 PM »

Okay - I seem to have figured it out - I had a pesky period '.' in one of my Predefined Firewall Policies.

It seemed to be affecting that applications' policy and at least some of the application policies that followed it.  Removing the period seems to have fixed everything.

It might be worthwhile for the CFP to validate these type of fields that obviously have naming restrictions.

I figured this out by setting up a very simple test configuration and things seemed to work okay.  Then I looked at my normal config to see what looked non-standard.  I guess I got lucky.

Thanks to everyone that replied!
Logged
Haos
Newbie
*
Offline Offline

Posts: 9


« Reply #8 on: June 26, 2008, 03:49:03 PM »

From what i tried, the problem happens with both global and application rulesets.
Logged
sergeyn
Newbie
*
Offline Offline

Posts: 9


« Reply #9 on: August 10, 2008, 12:37:55 PM »

Same here, new added network zones don't work
Logged
AndyWarrior
Newbie
*
Offline Offline

Posts: 13



« Reply #10 on: September 24, 2008, 12:18:46 PM »

Hi, if this can help, I have the same problem on my XP Pro sp3, Comodo firewall v. 3.0.25.378
It's interesting to see that any network zone added automatically by the firewall feature when it detects a new network is keeped and holded in memory, after rebooting too.
Any Network added manually or editing an existing one, added before automatically, is not keeped.
The program doesn't remember any manual entry/editing in this section, upon the next reboot...
Logged

Win XP Pro sp3 - 2Gb DDR3 Corsair XMS - 2,21Tb HDD's - Asus GeForge 8800GTS 512Mb GDDR3 - MB Asus P5E3 BIOS 1201
fOrTy_7
Comodo's Hero
*****
Offline Offline

Posts: 335


« Reply #11 on: September 25, 2008, 03:25:43 PM »

This bug has been fixed in CIS beta2 which include new version of CFP (3.5 beta2).
« Last Edit: September 25, 2008, 03:28:06 PM by fOrTy_7 » Logged

Windows XP Pro SP3 32-bit
Comodo Internet Security 3.13.121240.574
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.045 seconds with 17 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com