Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 25, 2013, 11:38:54 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
664094
Posts
70638
Topics
145272
Members
Latest Member:
iqhancpu458
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
Help - CIS
Firewall Help - CIS
continual blocking of ip
« previous
next »
Pages:
[
1
]
2
Author
Topic: continual blocking of ip (Read 4615 times)
worldwidewiretap
Comodo Member
Offline
Posts: 43
continual blocking of ip
«
on:
March 25, 2010, 05:26:35 PM »
hello all...I am having a few issues I need help with..
I am using the version 4.0138377.779 CIS
my firewall continues every few seconds to block an ip on a network in the house here...
the event shown reads like this
Application = windows operating system
Action = Blocked
Direction = In
Protocal = ICMP
Source Ip = the router being used in the house (192.168.2.1)
Source = Type 3
Destination IP = An IP that is hardwired through the router that is listed above (192.168.2.1) (which leads to my second issue..I am trying to go to ipconfig in order to verify the ip on a pc..and the window disappears as soon as it pops up)
Destination = Code 4
there are times when 5 minutes or so will go by...and the blocking will cease...then, back to blocking every minute or so. I tried to get live support twice..first time i was given advice to make a specific global rule, the blocking ceased for about an hour.....then only to return to the same behavior...
the second attempt of live help lead to being advised to run training mode...did nothing.
thanks for any advice.
Logged
CIS version 5.5.195786.1383 xpsp3 32bit / also using comodo time machine 2.5.129464.157 / Dell Dimension 2300 / 2 partitions internal 500g drive / numerous external hdd in all flavors / Ccleaner (wipe mft free space box unchecked) / Occasionally use defraggler / Multiple Music DAW's
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13188
Volunteer Moderator
Re: continual blocking of ip
«
Reply #1 on:
March 25, 2010, 05:34:56 PM »
Did you happen to upgrade from the previous V4.0.x.742 ?
Please verify your Firewall's Application rules and see if the "All applications" rule still has a "Block" rule present, if so please remove that.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
worldwidewiretap
Comodo Member
Offline
Posts: 43
Re: continual blocking of ip
«
Reply #2 on:
March 25, 2010, 06:31:33 PM »
this was a fresh install after a format Ronnie....
one thing I recall...recently I was looking in the CIS forums in which a member posted tweaking rules...one rule in particular was check the block all option in the stealth ports wizard....after I checked this option, my system would not allow certain programs to open or websites, etc...so, in thinking a tweak of the stealth ports wizard was this was the problem, I went to switch back to the default option in the stealth ports wizard (define a new trusted network & make my ports stealth for everyone else)....
there are two network zones listed in my advanced firewall settings...one the loopback zone ip adress which I believe to be the adress of the modem provided by the isp.....the other zone being the one I set up after the install of comodo CIS..which I named and believe to be the ip being blocked continuously..(the ip of the pc wired through the router connected to the modem..)
Another note...after the first online help conversation as listed in the first post in this thread...the helper advised me to make a rule...allow, ip, direction out, source any, destination zone / which is the one named and being blocked, ip any ///////// and allow ip, direction in, source zone, destination any, ip any..
this is curious to me, as the ip actions being blocked show the protocol being blocked is ICMP....
«
Last Edit: March 25, 2010, 06:44:44 PM by worldwidewiretap
»
Logged
CIS version 5.5.195786.1383 xpsp3 32bit / also using comodo time machine 2.5.129464.157 / Dell Dimension 2300 / 2 partitions internal 500g drive / numerous external hdd in all flavors / Ccleaner (wipe mft free space box unchecked) / Occasionally use defraggler / Multiple Music DAW's
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13188
Volunteer Moderator
Re: continual blocking of ip
«
Reply #3 on:
March 26, 2010, 04:18:41 AM »
Before we find the solution it's good to know something about the messages send:
ICMP Type 3 - Code 4 means the router is telling your PC
Quote
3 Destination Unreachable 4 Fragmentation Needed and Don't Fragment was Set
Source =
http://www.iana.org/assignments/icmp-parameters
Basically the packet the PC send was to large for the Router to transport to it's destination.
This blocking of these packets was on v4.0.x.472 related to a bug caused by the "All Applications" block rule blocking this while the global rule allowed it.
So if you are still experiencing these blocks and you don't have the "All applications" rule or at least not the block rule under it present it's probably caused by the Global Rules.
Can you please verify if you have an
ALLOW ICMP IN ANY ANY Fragmentation Needed
present there?
Can you also maybe provide a screenshot of your global rules?
For the IP rule support suggested, IP is a group of protocol's like ICMP/UDP/TCP etc so IP will cover all those, and that rule could be valid.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
worldwidewiretap
Comodo Member
Offline
Posts: 43
Re: continual blocking of ip
«
Reply #4 on:
April 04, 2010, 04:43:17 PM »
sorry for delay..I've attempted unsuccessfully to implement a snapshot of my global rules and such, but I cannot get the photo service sites to work properly...maybe due to the firewall.....
in the global rules..the allow icmp in / any / any / fragmentation needed is present..
also...icmp in / any / any / time exceeded is present..
as for the "all applications rule bug" explained above...I'm not real sure what you mean..but If you are referring to a global rule...block ip in / any / any / where protocol is any...this rule is present also..
and yes..the blocking is still occurring as described initially..
ps...under the advanced tab in the firewall behavior settings..the block fragmented IP datagrams box is checked..
Logged
CIS version 5.5.195786.1383 xpsp3 32bit / also using comodo time machine 2.5.129464.157 / Dell Dimension 2300 / 2 partitions internal 500g drive / numerous external hdd in all flavors / Ccleaner (wipe mft free space box unchecked) / Occasionally use defraggler / Multiple Music DAW's
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16723
Re: continual blocking of ip
«
Reply #5 on:
April 04, 2010, 08:22:17 PM »
You can try uploading images to the Comodo forums as you can attach images to posts. Follows is a little tutorial about it.
How to post a screenshot?
To copy a screenshot of the active window push alt+print screen to copy the active window to the clipboard (pushing print screen will copy the complete window to the clipboard not just the active window). The window is now copied to the clipboard. Paste the image in any image editing program, Paint, Paint.net, the Gimp etc. Use the "crop" function to resize the canvas to size of the image. Now save the file as 32 bits png image.
At the forum push the reply button. Or when using the Quick reply type some text and push the preview button.
Underneath the text box click on Additional options. Push the Choose button and navigate to the file and select it. When you want to post more images click on the more attachments link.
When done typing push the Post or Preview button.
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
worldwidewiretap
Comodo Member
Offline
Posts: 43
Re: continual blocking of ip
«
Reply #6 on:
April 04, 2010, 10:35:55 PM »
attempting to post image per guideline..
Great..it worked..thanks for imput..and the image attached IS the current settings...
I did however delete the named network zone with the ip being blocked as described in first post..and the same ip address continues to be blocked with the same codes as said...
paint.png
(41.27 KB, 806x419 - viewed 12 times.)
paint2.png
(192.52 KB, 764x496 - viewed 9 times.)
«
Last Edit: April 04, 2010, 10:50:31 PM by worldwidewiretap
»
Logged
CIS version 5.5.195786.1383 xpsp3 32bit / also using comodo time machine 2.5.129464.157 / Dell Dimension 2300 / 2 partitions internal 500g drive / numerous external hdd in all flavors / Ccleaner (wipe mft free space box unchecked) / Occasionally use defraggler / Multiple Music DAW's
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13188
Volunteer Moderator
Re: continual blocking of ip
«
Reply #7 on:
April 05, 2010, 02:35:08 AM »
Can you please open the Network Security Policy, and verify your on the Application rules tab.
Now try to find the rules for "All Applications" and verify if there is a block rule beneath it, if so please remove the block rule that belongs to the "All Applications" group.
Then apply and the problem should be gone.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
worldwidewiretap
Comodo Member
Offline
Posts: 43
Re: continual blocking of ip
«
Reply #8 on:
April 05, 2010, 05:55:24 PM »
thanks for detailed instructions to all responders...
[at] Ronnie...I did verify under the "network security policy" tab ..then "all applications" custom.. there was a "block and log all unmatching requests" (in bold print).. So I removed that rule...I will restart and watch the Firewall log..
Also..just below the "all applications" line..there is a line for "comodo internet security" Outgoing Only....below it are two rules similar to the "all applications" custom line...(they are allow all outgoing request)&(block and log all unmatching requests), however..these are not in bold print..kinda light gray...Should I also remove the "block and log all unmatching requests" there???
Logged
CIS version 5.5.195786.1383 xpsp3 32bit / also using comodo time machine 2.5.129464.157 / Dell Dimension 2300 / 2 partitions internal 500g drive / numerous external hdd in all flavors / Ccleaner (wipe mft free space box unchecked) / Occasionally use defraggler / Multiple Music DAW's
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13188
Volunteer Moderator
Re: continual blocking of ip
«
Reply #9 on:
April 06, 2010, 01:30:41 AM »
Quote from: worldwidewiretap on April 05, 2010, 05:55:24 PM
Also..just below the "all applications" line..there is a line for "comodo internet security" Outgoing Only....below it are two rules similar to the "all applications" custom line...(they are allow all outgoing request)&(block and log all unmatching requests), however..these are not in bold print..kinda light gray...Should I also remove the "block and log all unmatching requests" there???
Hi,
No please leave those, they belong to Comodo Internet Security not to "All Applications".
This should do the trick you should be no longer seeing those ICMP packets logged/dropped.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
joeythekangaroo
Comodo Loves me
Offline
Posts: 116
Re: continual blocking of ip
«
Reply #10 on:
April 06, 2010, 09:50:25 AM »
Same thing happens to me sometimes Ronny, I did a fresh install too like him, and now after a days work it says 5000 threats blocked(By the firewall) and it's always 192.168.0.1 and my ISP but idk how to fix it, please help
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13188
Volunteer Moderator
Re: continual blocking of ip
«
Reply #11 on:
April 06, 2010, 12:42:21 PM »
Please remove the indicated rule from the Network Security Policy.
AllApplications.jpg
(114.48 KB, 787x451 - viewed 8 times.)
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
worldwidewiretap
Comodo Member
Offline
Posts: 43
Re: continual blocking of ip
«
Reply #12 on:
April 06, 2010, 01:07:42 PM »
After 30 some hours of intermittent checking, the suggestions by Ronny have currently stopped the issue I was experiencing initially in the thread... Thanks for the help..I found the setting in "all applications" set to "block and log all..etc" was causing the firewall to block signal FROM the router being used in the network TO the pc I was experiencing this issue (ie..when using router..all pc's are assigned ip addresses unless you do otherwise). Since I have changed the setting..I have noticed certain things working better and particularly windows updates seem to giving me a higher influx of update notifications that I did not experience before (which I'm glad for...I'm just not totally sure this coincedence or not)
Another Note..after resolving my "continual blocking of ip" issue...I went around to all computers sharing the network (all using the same versions of CIS), and I noticed silmilar blocking of IP logs on those PC's too, but these PC's also have different events listed (ie..different source ip's..different source ports and different destination ports etc..) I even noticed the firewall on one PC connected on the network was actually blocking the ip of the PC I started this thread about...weird, because I do not have sharing events enabled on any of the PC's on the network..(no one shares printers or anything like that)...
FIRST OF ALL I will go to all PC's sharing the SAME network using the same version of CIS and go to "all appllications" tab under "network security policy" and make sure the block all...request is removed..then I will continue to check firewall logs on all the PC's using CIS sharing the network and I'll touch base in a bit..
«
Last Edit: April 06, 2010, 01:18:01 PM by worldwidewiretap
»
Logged
CIS version 5.5.195786.1383 xpsp3 32bit / also using comodo time machine 2.5.129464.157 / Dell Dimension 2300 / 2 partitions internal 500g drive / numerous external hdd in all flavors / Ccleaner (wipe mft free space box unchecked) / Occasionally use defraggler / Multiple Music DAW's
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13188
Volunteer Moderator
Re: continual blocking of ip
«
Reply #13 on:
April 06, 2010, 01:17:05 PM »
Maybe good to know that Comodo dropped this rule in a clean install of version 4.0.x.779 already so it's only present on "migrated" from previous versions systems.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
worldwidewiretap
Comodo Member
Offline
Posts: 43
Re: continual blocking of ip
«
Reply #14 on:
April 06, 2010, 01:19:42 PM »
noted Ronny thanks...however I think I was modifying my previous post when you read it...
Logged
CIS version 5.5.195786.1383 xpsp3 32bit / also using comodo time machine 2.5.129464.157 / Dell Dimension 2300 / 2 partitions internal 500g drive / numerous external hdd in all flavors / Ccleaner (wipe mft free space box unchecked) / Occasionally use defraggler / Multiple Music DAW's
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.051 seconds with 23 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com