Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
January 04, 2010, 03:31:57 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
347469
Posts
38443
Topics
87373
Members
Latest Member:
norris08
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Help - CIS
Firewall Help
What rules should I have for...
« previous
next »
Pages:
[
1
]
2
Author
Topic: What rules should I have for... (Read 1492 times)
metalforlife
Comodo's Hero
Offline
Posts: 298
What rules should I have for...
«
on:
November 12, 2009, 11:30:17 AM »
"svchost.exe" and "system"? And, how to setup svchost.exe so that the undesired services are blocked, and the required ones are allowed?
Logged
clockwork
Comodo Loves me
Offline
Posts: 178
Re: What rules should I have for...
«
Reply #1 on:
November 14, 2009, 06:50:07 AM »
i block everything internet related to system and svchost. you should make a test running of windows update, to see if there appear questions.
and the defense rules you should make for those, you will notice when you need it.
just run your operating system. and when YOU do something, and a question is asked about something that fits to your action, you can be relative sure, that its needed.
when YOU dont do something or the question doesnt fit, be careful why theres a question.
if you want to get rid of un-needed services, theres a program from the german chaos computer club, which disables those services. "...and in the most cases a firewall could be not more necessary".
for all the other cases you have the comodo firewall running
http://www.dingens.org/index.html.en
its name is NOT shutdown windows SERVERS.... thats a strange error on that page. its about SERVICES.
when you see any problems, just use the program again to undo. i never had a problem with it. i used some other programs, because its better to have a secure base than to trust a running process too much.
in the start my xp has under "system" 9 windows processes running. the whole process amount is 22 (including 2 comodo, 2 avira, 2 punkbuster, 2 grafic card processes), when i ask the task explorer. but THE services are mostly located under "system".
«
Last Edit: November 14, 2009, 07:00:15 AM by clockwork
»
Logged
adioz86
Comodo Loves me
Offline
Posts: 182
Re: What rules should I have for...
«
Reply #2 on:
November 14, 2009, 11:23:20 AM »
I would recommend:
"System": everything for it except LAN (192.168.0.1 - 192.168.255.255) Incoming /Outgoing
The same for "Windows Operating System".
LAN is needed if you want to play on LAN Party.
For svchost.exe: Allow Outgoing TCP HTTP(80) and HTTPS(443). If you need the exactly IP of Microsoft server for Windows Update you have to look it up your self (something like 65.xxx.xxx.xxx).
Allow Outgoing UDP NTP(123) for time synchronisation.
Allow LAN like above.
Allow DNS Resolve: Outgoing UDP Port 53.
I would recommend to remove the default ruleset for "Windows Update Application" or something like that.
«
Last Edit: November 14, 2009, 11:31:19 AM by adioz86
»
Logged
Intel Core 2 Quad Q9550 2.83GHz C1-Stepping [at]3.4GHz, Scythe Mugen 2 Cooler, Gigabyte EP45-DS3LR, Kingston HyperX 2*2GB 1066Mhz [at]800Mhz, ATI HD 4890, Antec Three Hundred, Dual Boot Win7 x64 and WinXP Pro x86 for 16bit programs
metalforlife
Comodo's Hero
Offline
Posts: 298
Re: What rules should I have for...
«
Reply #3 on:
November 19, 2009, 04:26:18 AM »
adioz86, I presume you mean that I should remove svchost.exe from the "windows updater applications" file group, and instead add it to "network security policy" separately.
For the LAN rules for all the three, what do you mean by "play on LAN Party"? And, how do I add Windows Operating System as a separate application?
Logged
adioz86
Comodo Loves me
Offline
Posts: 182
Re: What rules should I have for...
«
Reply #4 on:
November 19, 2009, 05:17:24 AM »
"play on LAn PArty" just mean, that you have in a LAN just to allow the apps(game.exe), which want to connect the LAN. That was the problem at my LAN party, and with this settings for the three it works then. Just had to allow the game.exe.
You can add Windows Operation System: Network Security Policies->add->choose acive Process->and on top there shoudl be Windows Operation System.
You should let svchost.exe in Windows Updater application group of Defense+. But with default settings there has been an entry with "Windows Updater" or something like that in Network security policies. This rule should be removed.
Logged
Intel Core 2 Quad Q9550 2.83GHz C1-Stepping [at]3.4GHz, Scythe Mugen 2 Cooler, Gigabyte EP45-DS3LR, Kingston HyperX 2*2GB 1066Mhz [at]800Mhz, ATI HD 4890, Antec Three Hundred, Dual Boot Win7 x64 and WinXP Pro x86 for 16bit programs
metalforlife
Comodo's Hero
Offline
Posts: 298
Re: What rules should I have for...
«
Reply #5 on:
November 19, 2009, 01:43:37 PM »
Nope, I do not play LAN games. Would the rule for the LAN be necessary now?
Logged
adioz86
Comodo Loves me
Offline
Posts: 182
Re: What rules should I have for...
«
Reply #6 on:
November 19, 2009, 04:05:03 PM »
No, then you don't need them.
Quote from: adioz86 on November 14, 2009, 11:23:20 AM
I would recommend:
"System": everything for it except LAN (192.168.0.1 - 192.168.255.255) Incoming /Outgoing
The same for "Windows Operating System".
LAN is needed if you want to play on LAN Party.
I meant block everything except of LAN. So you can block everything for System and Windows Operation System. I would not recommend to log blocked actions, cause your Firewall log would increase really fast.
Logged
Intel Core 2 Quad Q9550 2.83GHz C1-Stepping [at]3.4GHz, Scythe Mugen 2 Cooler, Gigabyte EP45-DS3LR, Kingston HyperX 2*2GB 1066Mhz [at]800Mhz, ATI HD 4890, Antec Three Hundred, Dual Boot Win7 x64 and WinXP Pro x86 for 16bit programs
clockwork
Comodo Loves me
Offline
Posts: 178
Re: What rules should I have for...
«
Reply #7 on:
November 19, 2009, 05:41:13 PM »
i definitely would suggest to log blocked things!
how should you know otherwise why something doesnt work?
the best chance you have when you start something, but it doesnt work, and then you see in the log, "hey, it was blocked".
who cares, if a log becomes big? after 2mb it will be erased in default.
for me its always "block and log".
Logged
metalforlife
Comodo's Hero
Offline
Posts: 298
Re: What rules should I have for...
«
Reply #8 on:
November 19, 2009, 06:01:27 PM »
Quote from: adioz86 on November 19, 2009, 04:05:03 PM
No, then you don't need them.
I meant block everything except of LAN. So you can block everything for System and Windows Operation System. I would not recommend to log blocked actions, cause your Firewall log would increase really fast.
So that is "allow" incoming and outgoing for LAN, and block everything else?
Quote from: clockwork on November 19, 2009, 05:41:13 PM
i definitely would suggest to log blocked things!
how should you know otherwise why something doesnt work?
the best chance you have when you start something, but it doesnt work, and then you see in the log, "hey, it was blocked".
who cares, if a log becomes big? after 2mb it will be erased in default.
for me its always "block and log".
I get 20-30 alters every minute on an average. I don't want to stop logging just to see a neat events window, but I want the logging to decrease as I configure the firewall better. I haven't gotten around it as of yet, and as I keep learning more and more, I'll configure it as I want and for lesser alerts.
Logged
adioz86
Comodo Loves me
Offline
Posts: 182
Re: What rules should I have for...
«
Reply #9 on:
November 20, 2009, 07:12:33 AM »
Quote from: metalforlife on November 19, 2009, 06:01:27 PM
So that is "allow" incoming and outgoing for LAN, and block everything else?
That's right.
Quote from: metalforlife on November 19, 2009, 06:01:27 PM
I get 20-30 alters every minute on an average. I don't want to stop logging just to see a neat events window, but I want the logging to decrease as I configure the firewall better. I haven't gotten around it as of yet, and as I keep learning more and more, I'll configure it as I want and for lesser alerts.
Then I recommend you, if you are not in a LAN, to block 137-139and 445, and just block and log everything else.
Logged
Intel Core 2 Quad Q9550 2.83GHz C1-Stepping [at]3.4GHz, Scythe Mugen 2 Cooler, Gigabyte EP45-DS3LR, Kingston HyperX 2*2GB 1066Mhz [at]800Mhz, ATI HD 4890, Antec Three Hundred, Dual Boot Win7 x64 and WinXP Pro x86 for 16bit programs
metalforlife
Comodo's Hero
Offline
Posts: 298
Re: What rules should I have for...
«
Reply #10 on:
November 20, 2009, 04:10:39 PM »
I'll do that, thanks.
Logged
shadowRider
Newbie
Offline
Posts: 8
Re: What rules should I have for...
«
Reply #11 on:
November 20, 2009, 07:37:21 PM »
Are you guys able to see the Network Map under windows Network & Sharing tab? I have allowed all communication for my LAN addresses 192.168.1.1. through 192.168.1.110 via the general rules, and Windows is not able to see or access the other computers or printers, even though I can access the printer and router via internet explorer.
Logged
adioz86
Comodo Loves me
Offline
Posts: 182
Re: What rules should I have for...
«
Reply #12 on:
November 21, 2009, 07:19:01 AM »
Which Operating System do you have?
It looks like there is something blocked by a firewall or OS? Look up your Firewall Logs.
If you can access them via IE, then it should be possible to access them via windows.
Logged
Intel Core 2 Quad Q9550 2.83GHz C1-Stepping [at]3.4GHz, Scythe Mugen 2 Cooler, Gigabyte EP45-DS3LR, Kingston HyperX 2*2GB 1066Mhz [at]800Mhz, ATI HD 4890, Antec Three Hundred, Dual Boot Win7 x64 and WinXP Pro x86 for 16bit programs
metalforlife
Comodo's Hero
Offline
Posts: 298
Re: What rules should I have for...
«
Reply #13 on:
November 24, 2009, 08:54:47 AM »
Hello adioz86, for the outgoing rules for svchost.exe to work, do I have to add anything ("incoming") to Global Rules?
For ports 67 and 68 (DHCP), in the beginning, I used to see lots of log entries that showed blocked-incoming for svchost.exe. Afterward svchost.exe stopped receiving anything for ports 67 and 68, and I started seeing connections through the ports 67 and 68 for System and Windows Operating System being blocked. Now it is only Windows Operating System that receives anything through those two ports, all of which are blocked by the firewall.
How should I configure these three applications for ports 67 and 68?
For all the rules for svchost.exe, System and Windows Operating System do I have to add corresponding rules to Global Rules?
Edit: My Stealth Ports Wizard setting is "Block all incoming connections - (the "dash" is missing from the interface; probably a bug.) stealth my ports to everyone".
«
Last Edit: November 24, 2009, 10:00:17 AM by metalforlife
»
Logged
adioz86
Comodo Loves me
Offline
Posts: 182
Re: What rules should I have for...
«
Reply #14 on:
November 24, 2009, 11:25:46 AM »
I have never used Ports Stealth Wizard, and never got a problem with it(logs to much). I configure that for each app.
I have just allowed Outgoing UDP remote Port 67 for svchost.exe and the other connections already mentioned in a post..
For System and windows operation system i have just a block rule on my laptop, without logging, cause i dont use it for LAN.
everything work fine with it.
For default i would always deny incoming traffic.
If your computer access internet, it always do it with an outgoing connection.
Just for filesharing and torrent client, incoming traffic is needed.
Logged
Intel Core 2 Quad Q9550 2.83GHz C1-Stepping [at]3.4GHz, Scythe Mugen 2 Cooler, Gigabyte EP45-DS3LR, Kingston HyperX 2*2GB 1066Mhz [at]800Mhz, ATI HD 4890, Antec Three Hundred, Dual Boot Win7 x64 and WinXP Pro x86 for 16bit programs
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in -0 seconds with 20 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com