Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
June 19, 2013, 03:02:47 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
669023
Posts
71136
Topics
145746
Members
Latest Member:
JarJar
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Discontinued Products
Comodo Firewall
Feedback/Comments/Announcements/News
Trialling Comodo
« previous
next »
Pages:
[
1
]
Author
Topic: Trialling Comodo (Read 2643 times)
scrawl
Newbie
Offline
Posts: 2
Trialling Comodo
«
on:
July 19, 2007, 09:08:53 AM »
Hi all,
I'm currently trialling Comodo firewall after reading some positive reviews and personal recommendations. Like many others, my firewall experience started with ZA and for the past few years I've been firmly entrenched in the Kerio camp.
One feature I'm struggling with Comodo is simply and quickly configuring allow/deny rules per application that are different for the Internet and Trusted zone.
Eg - in Kerio, I can allow inbound and outbound connections for the trusted zone but can set it up to only allow outbound connections to the internet zone. All of this is nicely presented in a tick/cross style table with five columns - Application name, Trusted Inbound, Trusted Outbound, Internet Inbound, Internet Outbound.
Using Comodo, the closest I can replicate this style of functionality is by defining a trusted zone. However, this seems to allow all inbound/outbound connections without prompting me for permission.
While I realise this sort of behaviour can be recreated by creating custom firewall rules per application in Comodo, I was hoping this sort of functionality could be achieved by allowing/denying access from popup boxes as they appear. Perhaps I have missed something obvious?
Thanks in advance.
Logged
Raccoon
Comodo Member
Offline
Posts: 49
Re: Trialling Comodo
«
Reply #1 on:
July 21, 2007, 08:04:30 PM »
These features are indeed available in Comodo. It's just different, and in my opinion, more flexible than Keiro and certainly ZA.
You can do two main things in Comodo. Set up rules that are Application based (Application Monitor), and set up general rules that are global to your network (Network Monitor). Play around in both of these areas until you get a feel for where everything is at.
A "Zone" is nothing more than an IP Address/Mask given a name for quick reference.
A "Trusted Zone" is nothing more than the above Zone given a Network Monitor rule to allow all inbound/outbound traffic (eg, to your networked computers).
You can specify these Zones under "Security > Tasks > Add/Remove/Modify a Zone" and you can specify and modify these rules under "Security > Network Monitor". If you already added a Trusted Zone via "Security > Tasks > Define a new Trusted Network", you will find that rule appear at the top of "Security > Network Monitor". And you can modify this rule to be more specific or general as you desire.
As you are testing new Network Monitor rules, add a checkmark to "Create an alert if this rule is fired" (at the top of the Rule Edit display) and you can monitor all traffic that matches that rule under "Activity > Logs".
Enjoy!
Logged
Raccoon
Comodo Member
Offline
Posts: 49
Re: Trialling Comodo
«
Reply #2 on:
July 21, 2007, 08:20:07 PM »
Oh, and as you requested...
Setting up application permissions to a specific zone:
Goto "Security > Application Monitor", then select an application rule and "Edit" (or double-click),
Click the "Destination IP" tab and tick "Zone" from the bullet list,
Then select the Zone from the drop-down list.
This will only permit outbound connections to that specified Zone.
See this screenshot:
http://i9.tinypic.com/4mvrdx3.png
«
Last Edit: July 21, 2007, 08:23:25 PM by Raccoon
»
Logged
scrawl
Newbie
Offline
Posts: 2
Re: Trialling Comodo
«
Reply #3 on:
July 26, 2007, 04:26:41 AM »
Thanks for your reply Racoon, much appreciated.
While I understand the power/flexibility of writing custom rules, in my case it's unfortunately somewhat beyond the level of the intended users (family members, relatives).
I guess this is one area where ZA/Kerio is a little more accessible for the not-so computer literate. When setting up a PC for a family member, I typically define trusted zones which usually consists of a LAN range, DNS address and localhost.
Currently, I have been able to teach family members how to differentiate between a trusted zone and an internet zone, the popups themselves being nicely differentiated with green and red, which they can simply allow/deny. I suspect messing around with custom rules is a little beyond the realms of ease of use for the average user.
Regardless, having heard so many good things about Comodo, I'm keeping it on my PC for a little longer.
Maybe this should be a feature request for a future version of Comodo: Have the popup alerts detect pre-defined zones and when the user allows/denies, create an application rule specific to the detected zone.
Logged
Little Mac
Forum Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 6303
The Colonel told me to.
Re: Trialling Comodo
«
Reply #4 on:
July 26, 2007, 10:49:57 AM »
scrawl,
I think part of the thing is learning to think differently... "Internet zone" is a term seemingly related to 'security' settings in Internet Explorer, and picked up/propagated by some other software (such as Zone Alarm). It means nothing more than applications connecting to the internet, as compared to an intranet (ie, your LAN).
CFP does not, by default, define the "internet" as a zone of any sort. The network monitor functions in a similar way as a router, filtering all communication attempts based on the existing rules and advanced protocols. This is the first layer of security for inbound communications, the last for outbound. The application monitor provides another layer of security and control, by controlling which/how applications are allowed to connect. Any application connecting can only do so within the context of the Network monitor.
It may help you to read the explanation of CFP's layered rules,
in this thread.
As I read your question, it sounds like the thing you would need to do on these other computers would probably be along the lines of the "set and forget" setup tutorial found within the above link. Once the Network Monitor rules are configured, the only thing for users to allow is application-based. At an Alert Frequency of Very Low, and utilizing the Safelist, these alerts will be minimized, and the level of detail minimal; this will probably be best for those not "into" computers.
Hope this helps,
LM
Logged
These forums are focused on providing help and improvement for Comodo products. Please treat other users with respect and make a positive contribution. Thanks.
Forum Policy
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.045 seconds with 22 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com