Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
November 30, 2009, 04:53:48 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
338852
Posts
37506
Topics
85113
Members
Latest Member:
2711
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Help - CIS
Firewall Help
My only global firewall rule
« previous
next »
Pages:
[
1
]
2
Author
Topic: My only global firewall rule (Read 555 times)
LeoniAquila
Still non-retired moderator but on vacation for a while
Global Moderator
Comodo's Hero
Offline
Posts: 6604
My only global firewall rule
«
on:
July 06, 2009, 03:10:24 PM »
First of all, I'm a complete novice when it comes to networks and firewalls. I'm more into local system activity.
Now, my PC is not in a home network, it's just connected to the Internet. No hardware firewall, no router. Simple as that. Long ago (in CFP 3.0 I guess) it seemed like someone/something tried to connect to my machine. Despite the default Comodo rules I got some alerts of incoming connection attempts once in a while. Thus I got help at this forum to create a global firewall rule. It's simply "
Block IP In From IP Any to IP Any Where Protocol Is Any
" and I'm still using it, after every reinstallation of CIS (for whatever reason) I delete the default global rules and add my own rule.
Although I'm a firewall novice this rule appears to me as it would block just about every kind of connection coming in to my PC. So, can anyone explain - very simply please
- how is it possible that I can actually surf, use DC++, and use Spotify without any connection problems whatsoever?
Thank you.
«
Last Edit: July 06, 2009, 03:14:33 PM by LeoniAquila
»
Logged
Moderator LeoniAquila:
Aims to keep the forum a friendly place. Any concerns? Please send me a PM and/or review the
Forum Policy
.
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 5323
I'm not a complete idiot, some bits are missing.
Re: My only global firewall rule
«
Reply #1 on:
July 06, 2009, 03:31:48 PM »
Unsolicited - Traffic you didn't ask for.
Solicited - Traffic you asked for.
There is nothing wrong with that rule, it will basically any block any inbound unsolicited connection attempts that an application hasn't grabbed. This is something that router users don't often need to worry about, because most routers do that by default. Now, this works because applications often open up ports to listen on for inbound connections attempts and this circumvents the global block rule because the port is already open (which is what you want). Sometimes, application dependent, you need to create special application rules to handle the inbound traffic & force a port open, but it is rarer these days I think. Another way, I suspect, for traffic to circumvent the global block rule is to use something like UPnP or port mapping, where all the inbound connections are, in effect, solicited (already established).
Logged
Vista Business x32+SP2 with CIS 3.12 & Firefox 3.5 & Becky! 2.52
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
bluesjunior
Comodo's Hero
Offline
Posts: 353
Re: My only global firewall rule
«
Reply #2 on:
July 06, 2009, 03:57:57 PM »
I don't know any more than you LeoniAquila but your rule is the same as the bottom Global rule in the Default Comodo CIS settings with the exception being that you are not logging the blocks. Here is a screenshot of my Global Rules all default except for the top one which allows my DHCP to get an address renewal from my IP. I have the same sort of layout as you a single desktop PC connected direct to the internet by broadband cable through a Fast Ethernet modem.
Logged
LeoniAquila
Still non-retired moderator but on vacation for a while
Global Moderator
Comodo's Hero
Offline
Posts: 6604
Re: My only global firewall rule
«
Reply #3 on:
July 07, 2009, 01:31:31 AM »
Thanks kail, slightly clearer now.
Thanks bluesjunior, I forgot that the default block rule actually is exactly the same as mine (except that I have no logging).
Why are there some other global default rules, the ones that allow certain traffic (as shown in bluesjunior's screenshot)? Obviously I don't need them?
Logged
Moderator LeoniAquila:
Aims to keep the forum a friendly place. Any concerns? Please send me a PM and/or review the
Forum Policy
.
bluesjunior
Comodo's Hero
Offline
Posts: 353
Re: My only global firewall rule
«
Reply #4 on:
July 07, 2009, 03:17:20 AM »
When my PC updated to 3.10 529 the default Global Rules were as below but after I applied Kyles set up guides and went to create the Port 67 & 68 DHCP rule I noticed that the had changed to the way they are now and have been in previous versions.
I can't tell you why yours are different it must be something to do with your own personal settings.
«
Last Edit: July 07, 2009, 03:19:07 AM by bluesjunior
»
Logged
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 4173
Re: My only global firewall rule
«
Reply #5 on:
July 07, 2009, 05:05:10 PM »
I am not initmately familiar with the workings of DC++ but as far as I know this is a p2p program. For p2p programs you must have an open port for incoming, unsolicited, traffic. To make that work you need to open a port under Global Rules.
Without an open port for the incoming traffic you will have less download capabilities. As a consequence the situation is as follows. Either you are happy with having less download capabilities (that may also translates to lower download speed ) or your firewall is not functioning properly. With regards to the latter run Diagnostics and see if there are Active connections just to be on the safe side of things.
Logged
Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
LeoniAquila
Still non-retired moderator but on vacation for a while
Global Moderator
Comodo's Hero
Offline
Posts: 6604
Re: My only global firewall rule
«
Reply #6 on:
July 08, 2009, 07:32:30 AM »
It's not p2p, it's direct file sharing.
Logged
Moderator LeoniAquila:
Aims to keep the forum a friendly place. Any concerns? Please send me a PM and/or review the
Forum Policy
.
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2727
Follow the White Rabbit...
Re: My only global firewall rule
«
Reply #7 on:
July 08, 2009, 07:48:28 AM »
Quote
It's not p2p, it's direct file sharing.
to be fair, it's still p2p. (person to person)
Anyway, for DC++ to work correctly you need to allow a Global IN rule. I can't remember the port, but without it, it's not going to work very well. Sure, you might be able to download from others, but they won't be able to get from you.
To be honest, I don't know how you have managed with just a block IN rule...
I know from experience, we can do without Global rules completely, but if you place a single global block IN, to my mind, that's exactly what it does.
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
LeoniAquila
Still non-retired moderator but on vacation for a while
Global Moderator
Comodo's Hero
Offline
Posts: 6604
Re: My only global firewall rule
«
Reply #8 on:
July 08, 2009, 04:00:34 PM »
Quote from: Toggie on July 08, 2009, 07:48:28 AM
to be fair, it's still p2p. (person to person)
Fair enough.
Quote from: Toggie on July 08, 2009, 07:48:28 AM
Anyway, for DC++ to work correctly you need to allow a Global IN rule. I can't remember the port, but without it, it's not going to work very well. Sure, you might be able to download from others, but they won't be able to get from you.
Might be true... I'm actually hardly using DC++, and I don't share anything, so I can't really tell whether that part works or not.
Quote from: Toggie on July 08, 2009, 07:48:28 AM
I know from experience, we can do without Global rules completely, but if you place a single global block IN, to my mind, that's exactly what it does.
I read long ago that some users use CFP/CIS without global rules, but I wouldn't feel safe doing so. What if you launch a program with possibility to send and receive data, and you have no application rule for it (nor any global rule) - thus it's open for incoming attacks? Would CFP warn about such an incoming connection attempt as the application lacks a rule?
Thanks.
Logged
Moderator LeoniAquila:
Aims to keep the forum a friendly place. Any concerns? Please send me a PM and/or review the
Forum Policy
.
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2727
Follow the White Rabbit...
Re: My only global firewall rule
«
Reply #9 on:
July 08, 2009, 08:24:50 PM »
I remember there being a long thread on here somewhere, it's probably buried in the archive board somewhere. As far as I can remember, we came to the conclusion that Global Rules, whilst useful for a number of reasons, aren't essential.
For communication to take place there must be an appropriate rule, that's true for both inbound and outbound traffic. If you think about an application like uTorrent, for example, you can see that it needs to have a rule that allows TCP and UDP IN and OUT. If that rule doesn't exist, uTorrent won't work. Now think about how that rule is catered for under CIS.
Application Rule - (this is only part of the whole rule)
Action = Allow
Protocol = TCP or UDP
Direction = In
Source Address = Any
Destination Address = Any
Source Port = Any
Destination Port = [Your uTorrent Port]
Action = Allow
Protocol = UDP
Direction = Out
Source Address = Any
Destination Address = Any
Source Port = [Your uTorrent Port]
Destination Port = Any
So, what about a Global rule for this, is it necessary? Well the answer to that is, it depends. First we need to look at the current rules, if there is a block rule that disallows all inbound traffic, then we will need a rule:
Action = Allow
Protocol = TCP or UDP
Direction = In
Source Address = Any
Destination Address = [Your uTorrent Port]
Source Port = ANY
If, on the other hand, there are no Global Rules, then there is nothing to prevent communication in either direction.
Again, think about a common configuration for Global rules:
The first rule is always invariably:
Allow IP OUT ANY ANY ANY
And the final rule is almost always invariably:
Block IP IN ANY ANY ANY
In the middle, rules, such the one above for uTorrent, will exist.
So, Yes, we can exist with out Global Rules, they simply make some things easier to achieve.
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
LeoniAquila
Still non-retired moderator but on vacation for a while
Global Moderator
Comodo's Hero
Offline
Posts: 6604
Re: My only global firewall rule
«
Reply #10 on:
July 09, 2009, 02:54:54 AM »
Thanks a lot for explaining, although I don't really follow all details.
Quote from: Toggie on July 08, 2009, 08:24:50 PM
If, on the other hand, there are no Global Rules, then there is nothing to prevent communication in either direction.
What mainly concerns me is the possibility of a hacker to somehow access my PC, provided that I have no global rules. Can they enter my system somehow, when it's just idle, and no application (like uTorrent - although I don't have uTorrent) is running?
If my concern is insubstantial, what about having uTorrent (or any application that uses the network) running - would those "allow" rules you wrote compromise the system as there are no application "block" rules, nor any global rule?
Logged
Moderator LeoniAquila:
Aims to keep the forum a friendly place. Any concerns? Please send me a PM and/or review the
Forum Policy
.
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2727
Follow the White Rabbit...
Re: My only global firewall rule
«
Reply #11 on:
July 09, 2009, 03:24:07 AM »
The example I posted for uTorrent is only a small portion of the whole. At the bottom of each application rule, I have an ASK or a BLOCK depending on what I'm trying to do. if I happy a rule works, I place a block and log, it it's a work in progress I use Ask and log.
The last rule I have in Application Rules Is Block IP IN/OUT ANY ANY ANY.
If I decided not to use Global Rules, then this last rule is fundamentally the same as your Global Rule.
As I said earlier, There has to be an Allow rule somewhere in the pathway for a connection to be made, this applies to both in and outbound communications.
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
LeoniAquila
Still non-retired moderator but on vacation for a while
Global Moderator
Comodo's Hero
Offline
Posts: 6604
Re: My only global firewall rule
«
Reply #12 on:
July 09, 2009, 04:06:33 AM »
OK
Quote from: Toggie on July 09, 2009, 03:24:07 AM
The example I posted for uTorrent is only a small portion of the whole. At the bottom of each application rule, I have an ASK or a BLOCK depending on what I'm trying to do. if I happy a rule works, I place a block and log, it it's a work in progress I use Ask and log.
The last rule I have in Application Rules Is Block IP IN/OUT ANY ANY ANY.
If I decided not to use Global Rules, then this last rule is fundamentally the same as your Global Rule.
As I said earlier, There has to be an Allow rule somewhere in the pathway for a connection to be made, this applies to both in and outbound communications.
Being the last rule I guess hierarchy applies? Basically the rule is active, but those above it (in the rule tree of the application) override it?
Logged
Moderator LeoniAquila:
Aims to keep the forum a friendly place. Any concerns? Please send me a PM and/or review the
Forum Policy
.
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2727
Follow the White Rabbit...
Re: My only global firewall rule
«
Reply #13 on:
July 09, 2009, 04:22:46 AM »
Exactly. Just the same as Global rules.
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
LeoniAquila
Still non-retired moderator but on vacation for a while
Global Moderator
Comodo's Hero
Offline
Posts: 6604
Re: My only global firewall rule
«
Reply #14 on:
July 09, 2009, 08:56:38 AM »
Thanks, it's a bit clearer now.
Logged
Moderator LeoniAquila:
Aims to keep the forum a friendly place. Any concerns? Please send me a PM and/or review the
Forum Policy
.
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.046 seconds with 19 queries.
Powered by SMF 1.1.10
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com