Author Topic: how to block application from connecting to the internet.  (Read 8291 times)

Offline zhon

  • Newbie
  • *
  • Posts: 14
how to block application from connecting to the internet.
« on: October 01, 2009, 08:24:43 AM »
I want an application to run smoothly over the network but no access to the internet. How do we do this in Comodo?

josedase

  • Guest
Re: how to block application from connecting to the internet.
« Reply #1 on: October 01, 2009, 08:45:53 AM »
Welcome to the forums.

You can do that in Firewall/Common Tasks/Define a New Blocked Application.
It's always a good idea to read "What do these settings do?" in the bottom left corner of the window.

Regards,
Jose.
« Last Edit: October 01, 2009, 10:59:25 AM by Jose_Lisbon »

Offline zhon

  • Newbie
  • *
  • Posts: 14
Re: how to block application from connecting to the internet.
« Reply #2 on: October 03, 2009, 06:39:48 AM »
Thanks Jose for the reply, this what this settings do gives basic information about a particular feature but perhaps what I really want to achieve in details is.

I want to prevent an application from connecting to the internet but maintain its connection over the LAN all throughout the LAN.

okay I will try these in " Define a new blocked application" and see the results.

Thanks

Offline Ronny

  • Product Translator
  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 13427
  • Volunteer Moderator
Re: how to block application from connecting to the internet.
« Reply #3 on: October 03, 2009, 11:32:14 AM »
Hello,
A blocked application will be fully blocked this is not what you are looking for.

What needs to be done is the following.

Define a network zone like "My Local Network(s)" that contain all ip ranges you need the application to have access to.

Once that's done you need to open the network policy and lookup the application in question.
Create rules like
Permit IP In/Out, Src Zone "My Local Network" Dst Zone "My Local Network".
Deny IP In/Out, Src Any, Dst Any.

This will allow the application to access all networks defined in the Zone "My Local Network" and block all other traffic, if you want to see what it blocks you can set Logging enabled on the Deny rule also.
Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!

josedase

  • Guest
Re: how to block application from connecting to the internet.
« Reply #4 on: October 03, 2009, 04:35:10 PM »
At zhon
   Sorry for having misguided you.

At Ronny
   What if you do choose Blocked Application and then go to Network Security Policy and:
      Allow__IP__In/Out__Ip Range__etc...

Regards,
Jose.

Offline zhon

  • Newbie
  • *
  • Posts: 14
Re: how to block application from connecting to the internet.
« Reply #5 on: October 04, 2009, 03:06:52 AM »
Ronny You are a Genius! I think thats indeed what im looking for. Im gonna go and check that out.

Offline zhon

  • Newbie
  • *
  • Posts: 14
Re: how to block application from connecting to the internet.
« Reply #6 on: October 04, 2009, 03:57:37 AM »
Ronny! it work! ha! Thanks a bunch man! your indeed a Comodo Hero!

Offline Ronny

  • Product Translator
  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 13427
  • Volunteer Moderator
Re: how to block application from connecting to the internet.
« Reply #7 on: October 04, 2009, 06:44:54 AM »
Thanks, Good to hear it works like you asked :-TU
Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!

Offline Ronny

  • Product Translator
  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 13427
  • Volunteer Moderator
Re: how to block application from connecting to the internet.
« Reply #8 on: October 04, 2009, 06:49:10 AM »
At zhon
   Sorry for having misguided you.

At Ronny
   What if you do choose Blocked Application and then go to Network Security Policy and:
      Allow__IP__In/Out__Ip Range__etc...

Regards,
Jose.
Hi Jose,

That should also work, if it's set before the block rule, and you only need access to one ip range.
If you need access to multiple ranges it's easier to use a Zone this will create only one rule on the policy instead of two/three/four etc...
Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!

Offline The_Dude

  • Newbie
  • *
  • Posts: 1
Re: how to block application from connecting to the internet.
« Reply #9 on: December 27, 2009, 05:55:37 PM »
Hello,
A blocked application will be fully blocked this is not what you are looking for.

What needs to be done is the following.

Define a network zone like "My Local Network(s)" that contain all ip ranges you need the application to have access to.

Once that's done you need to open the network policy and lookup the application in question.
Create rules like
Permit IP In/Out, Src Zone "My Local Network" Dst Zone "My Local Network".
Deny IP In/Out, Src Any, Dst Any.

This will allow the application to access all networks defined in the Zone "My Local Network" and block all other traffic, if you want to see what it blocks you can set Logging enabled on the Deny rule also.

I need to do this but I'm lost, can someone please elaborate on how exactly I specify all Local Network IP ranges for the application?

Offline Ronny

  • Product Translator
  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 13427
  • Volunteer Moderator
Re: how to block application from connecting to the internet.
« Reply #10 on: December 28, 2009, 06:54:34 AM »
Hi The_Dude,

Open GUI select Firewall -> My Network Zones -> Add, A New Network Zone, Give it a name and press Apply

Right mouse click on the new name and select "An ip address mask" fill in the ip address and subnet mask and press Apply, now repeat this for the remaining ip ranges.

If you are done you can use this "Zone" in your firewall policy to allow the above mentioned construction.
Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!

 

Seo4Smf 2.0 © SmfMod.Com | Smf Destek