Welcome, Guest. Please login or register.
December 25, 2009, 08:32:51 AM

Login with username, password and session length

345129 Posts
38104 Topics
86515 Members

Latest Member: Lyrickcze

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  Defense+ Help
| | | | |-+  Trusting an Application for Defense+ gives it Network rights also for FireWall
« previous next »
Pages: [1] Go Down Print
Author Topic: Trusting an Application for Defense+ gives it Network rights also for FireWall  (Read 641 times)
r_honey
Newbie
*
Offline Offline

Posts: 3


« on: November 12, 2009, 12:35:01 AM »

I have been using CIS for sometime now. I remember, in previous version, when I marked an application as trusted, it was given Desktop rights only, with no automatic permissions for Firewall.

However, in current versions, when I mark an Application as trusted (so that I dont have to give it Keyboard, Registry rights separately each time), it also gets all Firewall rights automatically.

I have edited the "Trusted Application" policy to remove the "Loopback Networking", and "DNS Client Service" rights. However, this is of no use, and tn application marked as trusted still gets Firewall rights automatically. How can I prevent this??
Logged
Kyle
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 3273



WWW
« Reply #1 on: November 12, 2009, 02:22:20 AM »

IMO It makes Sense.. If you mark an application as Trusted then it should let it do it's thing without a peep.
This way it's reducing alerts/improving usability.
Logged

E5200 2.5ghz [at] 3.33ghz, POV 9800gt 512mb, 2gb DDR2 RAM.  500gb. HDD


~~~
Trying to see if I can completely switch to linux Cheesy
layman
Comodo's Hero
*****
Offline Offline

Posts: 362


« Reply #2 on: November 12, 2009, 04:33:14 AM »

I would disagree with Kyle. For e.g. I use Ccleaner and would like to give it all permissions and would not mind giving it 'trusted application' status for desktop. However, for updates, I would like to do it manually once in a while, so that my internet usage is not disrupted often by programs trying to update itself.

Any way, CIS will not give access rights of 'internet' to a 'trusted application' in Defense+ unless the Firewall Security level is kept at 'Safe Mode'. If you want alerts for all programs, you can keep Firewall Security level at 'Custom Policy Mode'.

Right Click CIS tray icon - Firewall Security Level - Custom Policy Mode.

This way you will get alerts for all the programs which try to connect internet if 'permission rules' does not already exist under 'Network Security Policy'.

CIS-Firewall-Advanced-Network Security Policy

You can delete the entry of the program you are referring to, from Network Security Policy and re-check the same.
Logged
r_honey
Newbie
*
Offline Offline

Posts: 3


« Reply #3 on: November 12, 2009, 07:48:19 AM »

For e.g. I use Ccleaner and would like to give it all permissions and would not mind giving it 'trusted application' status for desktop. However, for updates, I would like to do it manually once in a while, so that my internet usage is not disrupted often by programs trying to update itself.

Exactly, I use a multitude of programs including Visual Studio, Sql Enterprise Studio, etc. etc. Each of these tools perform task that can better be flagged as "Trusted Application". However, they also unnecessarily call back home (their Vendor's site) every now & then for tasks that are useless to me.

Now layman, yes I am using Safe Mode. Are you sure switching to Custom Policy Mode would not create any holes relative to Safe Mode?? Isn't there a better way available??
And I have already deleted that entry for that application before posting!!!
Logged
layman
Comodo's Hero
*****
Offline Offline

Posts: 362


« Reply #4 on: November 13, 2009, 03:59:00 AM »

Not at all. Custom Policy Mode just means giving 'permissions' for internet connectivity as per user's will i.e. this is meant only for 'Firewall' activity

CIS will not use its safe list for 'internet' in this mode. So, you will get alerts even for Comodo's programs like CSC, if it's policy is not created. At the same time you are free to retain 'trusted application' status for defense+, which will give it sweeping powers within your desktop.

Further, when the alert is shown, if you prefer to use 'remember my action' by giving 'permission' or 'block' that program will not bother you there after. Also, you can any time review your decision at 'network security policy' mentioned in my last post.

Unlike a configuration policy change, firewall security level only affects the firewall activity, nothing else.

Hope this helps
Logged
r_honey
Newbie
*
Offline Offline

Posts: 3


« Reply #5 on: November 13, 2009, 04:12:25 AM »

Thanx layman
Logged
-[NHATZ_JADE]-
Comodo's Hero
*****
Offline Offline

Posts: 283


2G/3G Rigger & Radio Access Field Officer [HUAWEI]


WWW
« Reply #6 on: November 13, 2009, 04:27:54 AM »

IMO It makes Sense.. If you mark an application as Trusted then it should let it do it's thing without a peep.
This way it's reducing alerts/improving usability.

Fantastic Answer Kyle... I agree with that.

 Cheers Cheers Cheers
        Cheers Cheers Cheers
                Cheers Cheers Cheers
Logged

OS
- [XP PRO sp2]
PROCESSOR
- [CELERON-D single]
BROADBAND ANTENNA
- [Motorola Canopy with Surge & Lightning Arrester]
UPS
- [Liebert Emerson ItOn]
ON-DEMAND SCANNER
- [MBAM] [SAS] [SPYBOT] [A-SQUARED]
http://www.facebook.com/home.php?#/nhatz.jaja?ref=profile
layman
Comodo's Hero
*****
Offline Offline

Posts: 362


« Reply #7 on: November 17, 2009, 03:02:02 AM »

Yes, in 'Safe Mode' of Firewall Mode CIS do just that. Trust those which can be trusted, no more alerts.
Logged
Tags: Defense+  Firewall 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.037 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com