Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 07, 2008, 10:13:29 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
197997
Posts
22786
Topics
54749
Members
Latest Member:
bingocn
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Feedback/Comments/Announcements/News
Overall viewpoint of a new user
« previous
next »
Pages:
[
1
]
Author
Topic: Overall viewpoint of a new user (Read 1842 times)
Rik
Newbie
Offline
Posts: 4
Overall viewpoint of a new user
«
on:
May 08, 2007, 12:46:17 PM »
My last firewall is Outpost. I also know Zone Alarm (too simple) ad CoreSecurity (too detailed to be handy, is almost a debugger!). I also know Ashampoo and many others.
I was giving a try to Comodo. This is my opinion at a first glance.
I see these problems (maybe I'm wrong):
(1)
When Comodo alert for an inbound/outbound of an application on a specific port, the rule is set ANY on address/ports. This is equivalent to trusted application on other firewalls. This is not very good.
(2)
In the case 1, if you try to edit the rulee (e.g. Outlook port 25), if the OL try to exit on other ports (e.g. 80), Comodo alert "Comodo is trying to exit on port 80" correctly but if you say "Yes is right, remember", Comodo invalidate the limit of port 25 deleting that rule or in other cases creating a new rule that say "Go wherever you want!" (ANY for address/ports). This is even still worst than case 1 because destroy security without advice!
(3)
So, I can't make rules based on ports unless I decide to never say "remember" if a Comodo alert arise (because if I do, that could change existing trimmed rules).
(4)
If on the contrary I want to create limitation with specific rules (e.g. Outlook not able to exit on port 80) I encounter another problem: rules priority. What Do I mean? Let's say I accept the auto-rule of Outlook any/any. I create a new rule where OL is blocked on destination Any, port 80. Until this rule stay on top of OL rules it works, BUT, if you touch manually or automatically another rule of OL, this lock on port 80 stop working because the other rules come first.
(5)
Related to point 4, to make the lock rule be on the top of other rule of that application, the only way is touching (open/save) all the other rules (the touched go bottom). There are not arrow like those in
security-network monitor (move up/move down). It should be simple to implement and very useful to have.
In other word, at a first glance it looks manually unmanageable.
Logged
pandlouk
I love Comodo
Comodo's Hero
Offline
Posts: 2240
Panagiotis
Re: Overall viewpoint of a new user
«
Reply #1 on:
May 08, 2007, 12:50:51 PM »
Welcome at the forum
You must change the
Frequency alert level
from
low
to
High
.
CFP is the most configurable firewall that I have ever used. It is good for novice users and e great toy for the advanced ones.
Logged
Rik
Newbie
Offline
Posts: 4
Re: Overall viewpoint of a new user
«
Reply #2 on:
May 09, 2007, 03:31:23 AM »
I don't see how it could help with the 5 problems above.
Yes is configurable, but it is also auto-sconfigurable!
And the rules it auto-creates don't respect what is asked in the alert!
If it say:
- "Hey guy, Firefox is outputting on port 80. Is that right?"
and I say
- "Yes and remember",
and looking the rule saved I see the statement
- "Let Firefox exit on ANY ports for any Address",
it doen't seem something sound!!!
It is the first firewall I encounter that act this way (letting apart those like Zone Alarm Free that don't manage ports by design).
So, to me, it seem a half way from a very simple firewall like Zone Alarm Free and a complete firewall that really manage the application ports like Outpost.
Logged
grampa
Comodo's Hero
Offline
Posts: 383
Re: Overall viewpoint of a new user
«
Reply #3 on:
May 09, 2007, 06:36:12 AM »
Quote from: pandlouk on May 08, 2007, 12:50:51 PM
You must change the
Frequency alert level
from
low
to
High
.
Very true!!!
Quote from: Rik on May 09, 2007, 03:31:23 AM
I don't see how it could help with the 5 problems above.
If you set the "Alert Frequency Level" to "low" (default), CPF will only display alerts for unknown applications (if "Component Monitor" is turned on, it will also alert you if an allowed application contains a new, not yet allowed component). Thus it will create quite general rules in "Application Monitor" when you say "allow and remember".
If you set the "AFL" to "high", CPF will show alerts for outgoing and incoming connection requests for both UDP and TCP protocols on specific ports for an application. If you then tick "allow and remember" your rules will be more specific. You can also set the "AFL" to "very high" and get even more specific rules in AM.
If you leave the "AFL" set to "low" you can edit a respective "application control rule" to make it more specific.
Thus:
Quote from: pandlouk on May 08, 2007, 12:50:51 PM
CFP is the most configurable firewall that I have ever used. It is good for novice users and e great toy for the advanced ones.
is very true indeed.
Hope that helps.
Cheers,
grampa.
«
Last Edit: May 09, 2007, 06:39:32 AM by grampa
»
Logged
"It is a mistake to think you can solve any major problems just with potatoes." (Douglas Adams)
pandlouk
I love Comodo
Comodo's Hero
Offline
Posts: 2240
Panagiotis
Re: Overall viewpoint of a new user
«
Reply #4 on:
May 09, 2007, 08:42:44 AM »
Quote from: Rik on May 09, 2007, 03:31:23 AM
I don't see how it could help with the 5 problems above.
Yes is configurable, but it is also auto-sconfigurable!
And the rules it auto-creates don't respect what is asked in the alert!
If it say:
- "Hey guy, Firefox is outputting on port 80. Is that right?"
and I say
- "Yes and remember",
and looking the rule saved I see the statement
- "Let Firefox exit on ANY ports for any Address",
it doen't seem something sound!!!
It is the first firewall I encounter that act this way (letting apart those like Zone Alarm Free that don't manage ports by design).
So, to me, it seem a half way from a very simple firewall like Zone Alarm Free and a complete firewall that really manage the application ports like Outpost.
If you set the alert frequency level at high, CFP changes the mode of controlling the rules and instead of automatic it goes in manual mode. The rules will not be generic but very specific. And CFP will not change the rules that you create.
If you want even more control you can use very high, but you will have to create rules for specific IPs too. This one is a "paranoid" level of security and CFP will bombard you with popups until you configure it.
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6017
Re: Overall viewpoint of a new user
«
Reply #5 on:
May 09, 2007, 01:05:56 PM »
One thing to note, in regards to the Alert Frequency...
By default, AF is set to Low; this will provide only details of Application, and Direction of traffic (ie, Out or In). If you leave it there, and create a rule in the Application Monitor that contains more information detail (such as Protocol or Port), the next time you check "Remember" and click Allow for that application on a popup alert, the detailed rule you created will be overwritten by a more generic rule, as the rules are written based on your AF level. If you want more detail, you have to increase the AF level, as grampa and pandlouk have noted.
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Rik
Newbie
Offline
Posts: 4
Re: Overall viewpoint of a new user
«
Reply #6 on:
May 10, 2007, 02:55:35 AM »
GREAT!!!
I suspect I must lack something because everywhere I see great score to Comodo FW.
However, I think these "problems" must be consider because many other users, advanced people I know, uninstall Comodo for this problem! Beeing a freeware and looking simple, nobody suspect it could have such important features in submenus. I have spent 2 minute looking for it after reading your answer, and finally found it using "Search: alert frequency" in the help.
(...and Alert frequency sound like "Change the timing I alert". It should be more clear "Alert level" erasing Frequency that is only a consequence).
However this main feature of the FW shoul be in main window, not in Security-Advanced-Miscellaneous!!!!!!
With this simple grafic restyling I thing Comodo will get MANY more users, avoiding many uninstall after a little try.
Thank you very much for your help!
Logged
grampa
Comodo's Hero
Offline
Posts: 383
Re: Overall viewpoint of a new user
«
Reply #7 on:
May 10, 2007, 03:45:37 AM »
Glad to hear that you are happy with CPF.
I agree that Comodo is "hiding" some of it's real potential from the first time user. I've been using it for quite some time now and can still learn a lot about this magnificent firewall.
However, IMO that's the price you'll have to pay if you want a firewall that offers the best possible protection: it's bound to be more complicated to set / to discover all its features.
I think it's great that you didn't give up and posted your observations.
If you have any further questions, plz do not hesitate to ask.
We're always happy to help.
Cheers,
grampa.
Logged
"It is a mistake to think you can solve any major problems just with potatoes." (Douglas Adams)
Rik
Newbie
Offline
Posts: 4
Re: Overall viewpoint of a new user
«
Reply #8 on:
May 10, 2007, 04:29:44 AM »
I will help others first users of CPF here in Italy avoiding them to uninstall after the first try!
Putting the Alert Frequency Level in the main windows should anyway be a great solution for the first user. I'm sure will avoid many uninstall.
Logged
grampa
Comodo's Hero
Offline
Posts: 383
Re: Overall viewpoint of a new user
«
Reply #9 on:
May 10, 2007, 04:32:39 AM »
Quote from: Rik on May 10, 2007, 04:29:44 AM
I will help others first users of CPF here in Italy avoiding them to uninstall after the first try!
Putting the Alert Frequency Level in the main windows should anyway be a great solution for the first user. I'm sure will avoid many uninstall.
Logged
"It is a mistake to think you can solve any major problems just with potatoes." (Douglas Adams)
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6017
Re: Overall viewpoint of a new user
«
Reply #10 on:
May 10, 2007, 10:34:53 AM »
A couple more things to keep in mind, Rik...
1. There is an Italian forum here; that may be useful to you as well
2. In this thread:
http://forums.comodo.com/index.php/topic,6167.0.html
you will find "Set & Forget" configuration information that may be helpful, as well as some other good info, all in one nice neat place.
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
OD
Forum Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 506
"To live is to dance, to dance is to live."
Re: Overall viewpoint of a new user
«
Reply #11 on:
May 17, 2007, 04:38:43 PM »
After playing with it quite a bit and studying Application rules sets both in the forums and using the Application I have found that Whan adjusting the order of the ruls in one set the order of anouther set will automatically readjust itself.
While I think Comodo is potentially one the best Firewalls available to the general consumer, that can be puchased or freeware.
These problems also make it more difficult for the advanced users. After reading this Thread I have moved The (AFL) Alert Frequancy Level to high and will
continue
to play with it some more.
I was just disapointed when I saw the great potential that Comodo has. Perhaps I have not worked wih it enough yet. Also V3 could change everything
I think
And I have great hopes for V3
Opus
«
Last Edit: May 17, 2007, 05:01:22 PM by Opus Dei
»
Logged
"Sometimes when I get up in the morning, I feel very peculiar. I feel like I've just got to bite a cat! I feel like if I don't bite a cat before sundown, I'll go crazy! But then I just take a deep breath and forget about it", then again sometimes you just have to bite a cat
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.161 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com