Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 07, 2009, 10:29:48 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
340497
Posts
37677
Topics
85515
Members
Latest Member:
nulldev
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Help - CIS
Firewall Help
99 percent of blocked intrusion attempts from one source
« previous
next »
Pages:
[
1
]
Author
Topic: 99 percent of blocked intrusion attempts from one source (Read 754 times)
viper
Comodo Family Member
Offline
Posts: 74
99 percent of blocked intrusion attempts from one source
«
on:
July 03, 2009, 10:54:24 PM »
When i look in the firewall events log I noticed that 99 percent of the blocked intrusion attempts are from the following:
Application: windows Operating system
Protocal: UDP
Source IP: 10.118.220.1
Source Port: 67
I noticed the same thing on my friends computer who also has comodo.
Logged
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2730
Follow the White Rabbit...
Re: 99 percent of blocked intrusion attempts from one source
«
Reply #1 on:
July 03, 2009, 11:37:30 PM »
Are you on a cable network?
The IP address space 10.0.0.0 - 10.255.255.255 is reserved and is not valid on the Internet. UDP port 67 is bootps . Basically this is part of the DHCP process, generally a response from a DHCP server to a request for a DHCP lease. I imagine the destination port is 68.
Dependent upon your configuration you could create a rule to block and not log these events.
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
viper
Comodo Family Member
Offline
Posts: 74
Re: 99 percent of blocked intrusion attempts from one source
«
Reply #2 on:
July 04, 2009, 01:43:58 AM »
Yes the destination port is 68. So this is bad and should be blocked? Is this a hacker attempt to get into my system? Its been blocked 700 times in a couple of hours.
Logged
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2730
Follow the White Rabbit...
Re: 99 percent of blocked intrusion attempts from one source
«
Reply #3 on:
July 04, 2009, 01:54:48 AM »
No, it's not a hacker attempt, it's relatively normal network activity, but for some reason there always seems to be a great many of these packets on cable networks.
You could ask your ISP the reason for there being so many datagrams flooding the network, but I doubt you'll get much of an answer.
You can block and not log these, but you need to make sure you don't stop your system acquiring an IP address. Without one you won't be able to do anything.
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
bluesjunior
Comodo's Hero
Offline
Posts: 353
Re: 99 percent of blocked intrusion attempts from one source
«
Reply #4 on:
July 04, 2009, 02:36:24 AM »
I am on a cable broadband service through virgin media here in the UK. My PC connects to the Internet through the Virgin supplied Fast Ethernet connector cable modem and there is no router on my system. The rule in regards to ports 67 and 68 I have for allowing my ISP to renew my address is as follows.
Go into Firewall>Advanced>Network Security Policy>Global Rules. In Global Rules highlight the top rule and click add and in the box that comes up enter the following.
Action = Allow
Protocol = UDP
Direction = In / Out
Source = Any
Destination = Any
Source Port = Choose Range and enter Start = 67, End = 68
Destination Port = Choose Range and enter Start = 67, End = 68
You can also check the box saying " log if this rule is fired", then click apply /ok and it is very important that once back in Global Rules you must drag and drop the new rule to the top of the list.
Logged
viper
Comodo Family Member
Offline
Posts: 74
Re: 99 percent of blocked intrusion attempts from one source
«
Reply #5 on:
July 04, 2009, 03:49:11 PM »
With 3.10 these don't get blocked. I guess that's why the number of blocked intrusions drops so much between 3.9 and 3.10. Most of the blocked intrusions was this network traffic that really is nothing. I am using 3.9 right now and in one hour comodo has blocked 320 intrusion attempts. All of them are this network traffic we have discussed above.
How many intrusion attempts does comodo block for you guys in an hour?
Logged
bluesjunior
Comodo's Hero
Offline
Posts: 353
Re: 99 percent of blocked intrusion attempts from one source
«
Reply #6 on:
July 04, 2009, 04:22:24 PM »
I have been on the PC now about one hour and I have 47 intrusion attempts. I have just updated Mozilla Forefox to the latest version v3.5 and noticed that in the same hour I have 37 outbound connections even though I only have the tab to this site open at the moment. I tend to open each new site I visit in a new tab and delete the previous tab but it seems that Comodo is slow to recognize I am no longer at that address.
Do you just install Comodo as default or what is your procedure. Since Comodo v3.5 as soon as the install is finished I tend to open all my regular used programs and set them either as custom, trusted, web browser, outgoing only etc etc. As soon as I have done that I come here and follow the instructions for the Firewall and Defence+ Kyle gives in the Guides section here. The only other thing I do after that is set the Global DHCP Rule for ports 67 and 68 as mentioned above. The traffic I see seems to be no more or no less than in previous versions as far as I can see.
Logged
viper
Comodo Family Member
Offline
Posts: 74
Re: 99 percent of blocked intrusion attempts from one source
«
Reply #7 on:
July 04, 2009, 04:57:57 PM »
So its better not to block this network traffic?
According to bluesjunior he sets his rules not to block this network traffic.
Is there a link on advice on how to set firewall for best results? My knowledge on firewalls is not that good.
Logged
Jim__
Comodo Family Member
Offline
Posts: 99
Re: 99 percent of blocked intrusion attempts from one source
«
Reply #8 on:
July 04, 2009, 06:41:54 PM »
Viper
What is the destinatiion IP? If it is broadcast traffic then CIS is hyperventilating about it being an "attack".
Logged
bluesjunior
Comodo's Hero
Offline
Posts: 353
Re: 99 percent of blocked intrusion attempts from one source
«
Reply #9 on:
July 05, 2009, 02:11:43 AM »
Quote
Is there a link on advice on how to set firewall for best results? My knowledge on firewalls is not that good.
http://forums.comodo.com/guides_cis-b130.0/
Logged
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2730
Follow the White Rabbit...
Re: 99 percent of blocked intrusion attempts from one source
«
Reply #10 on:
July 05, 2009, 02:32:20 AM »
Quote
I have just updated Mozilla Forefox to the latest version v3.5 and noticed that in the same hour I have 37 outbound connections even though I only have the tab to this site open at the moment.
This is more than likely due to DNS prefetching, which is a new feature of fx 3.5 and above.\
Quote
According to bluesjunior he sets his rules not to block this network traffic.
First, your system needs to be able to aquire an IP address, it then needs to be able to renew that address.
To facilitate this you need one or more rules. How many will depend upon your current configuration. At the very least you will need to let svchost.exe outbound connectivity in Applications rules.
If you have used stealth ports, you will also need to allow DHCP traffic IN via global rules.
Once you have implemented these rules and you have assured your system can maintain DHCP connectivity, you may safely block and not log all other similar traffic. For some reason, on cable networks, there always seems to be quite high levels of this kind of DHCP renewal traffic.
«
Last Edit: July 05, 2009, 08:44:51 PM by Toggie
»
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
viper
Comodo Family Member
Offline
Posts: 74
Re: 99 percent of blocked intrusion attempts from one source
«
Reply #11 on:
July 06, 2009, 02:19:39 AM »
I set my firewall as follows:
- I add my network in my network zones
- Then i stealth my ports (Block all incoming connections - third option)
Logged
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2730
Follow the White Rabbit...
Re: 99 percent of blocked intrusion attempts from one source
«
Reply #12 on:
July 06, 2009, 03:00:52 AM »
The answer to whether you will need more rules to accommodate DHCP will depend upon where you obtain your DHCP lease.
From what you said above, your current Global Rule configuration allows communication on your LAN but blocks all other inbound traffic.
For DHCP to function correctly, you will need, as I said before, an Application rule for svchost.exe and you will also need to allow, at the least, DHCP IN. In Global Rules.
To understand what this means, you have to understand how DHCP works. Typically, whcn you start your computer your DHCP client (controlled by svchost) sends a multicast request to locate a DHCP server:
Your client:
UDP 0.0.0.0:68 ---> 255.255.255.255:67
If a DHCP server is found and it responds correctly it will send:
The DHCP server:
UDP (some ip address appropriate for your computer):67 ---> 255.255.255.255:68
Here you can see the basic requirement, UDP on port 67 needs outbound access and UDP on port 68 needs inbound access.
On an occasional basis your computer will attempt to renew it's IP address (called a lease) this also needs to ba catered for but should work correctly, assuming you have created rules that allow the above.
Hope this helps
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.046 seconds with 21 queries.
Powered by SMF 1.1.10
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com