Welcome, Guest. Please login or register.
November 22, 2009, 05:11:54 AM

Login with username, password and session length

336759 Posts
37262 Topics
84470 Members

Latest Member: bwennero

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  Firewall Help
| | | | |-+  What rules should I have for...
« previous next »
Pages: [1] Go Down Print
Author Topic: What rules should I have for...  (Read 438 times)
metalforlife
Comodo's Hero
*****
Online Online

Posts: 276


« on: November 12, 2009, 11:30:17 AM »

"svchost.exe" and "system"? And, how to setup svchost.exe so that the undesired services are blocked, and  the required ones are allowed?
Logged
clockwork
Comodo Loves me
****
Offline Offline

Posts: 107


« Reply #1 on: November 14, 2009, 06:50:07 AM »

i block everything internet related to system and svchost. you should make a test running of windows update, to see if there appear questions.
and the defense rules you should make for those, you will notice when you need it.
just run your operating system. and when YOU do something, and a question is asked about something that fits to your action, you can be relative sure, that its needed.
when YOU dont do something or the question doesnt fit, be careful why theres a question.

if you want to get rid of un-needed services, theres a program from the german chaos computer club, which disables those services. "...and in the most cases a firewall could be not more necessary".
for all the other cases you have the comodo firewall running Wink

http://www.dingens.org/index.html.en

its name is NOT shutdown windows SERVERS.... thats a strange error on that page. its about SERVICES.
when you see any problems, just use the program again to undo. i never had a problem with it. i used some other programs, because its better to have a secure base than to trust a running process too much.

in the start my xp has under "system" 9 windows processes running. the whole process amount is 22 (including 2 comodo, 2 avira, 2 punkbuster, 2 grafic card processes), when i ask the task explorer. but THE services are mostly located under "system".
« Last Edit: November 14, 2009, 07:00:15 AM by clockwork » Logged
adioz86
Comodo Loves me
****
Offline Offline

Posts: 142


« Reply #2 on: November 14, 2009, 11:23:20 AM »

I would recommend:

"System": everything for it except LAN (192.168.0.1 - 192.168.255.255) Incoming /Outgoing
The same for "Windows Operating System".
LAN is needed if you want to play on LAN Party.

For svchost.exe: Allow Outgoing TCP HTTP(80) and HTTPS(443). If you need the exactly IP of Microsoft server for Windows Update you have to look it up your self (something like 65.xxx.xxx.xxx).
Allow Outgoing UDP NTP(123) for time synchronisation.
Allow LAN like above.
Allow DNS Resolve: Outgoing UDP Port 53.

I would recommend to remove the default ruleset for "Windows Update Application" or something like that.
« Last Edit: November 14, 2009, 11:31:19 AM by adioz86 » Logged

Intel Core 2 Quad Q9550 [at]3,4Ghz, Scythe Mugen 2 Cooler, Gigabyte EP45-DS3LR, Kingston HyperX 2*2GB 1066Mhz, ATI HD 4890
metalforlife
Comodo's Hero
*****
Online Online

Posts: 276


« Reply #3 on: November 19, 2009, 04:26:18 AM »

adioz86, I presume you mean that I should remove svchost.exe from the  "windows updater applications" file group, and instead add it to "network security policy" separately.

For the LAN rules for all the three, what do you mean by "play on LAN Party"? And, how do I add Windows Operating System as a separate application?
Logged
adioz86
Comodo Loves me
****
Offline Offline

Posts: 142


« Reply #4 on: November 19, 2009, 05:17:24 AM »

"play on LAn PArty" just mean, that you have in a LAN just to allow the apps(game.exe), which want to connect the LAN. That was the problem at my LAN party, and with this settings for the three it works then. Just had to allow the game.exe.

You can add Windows Operation System: Network Security Policies->add->choose acive Process->and on top there shoudl be Windows Operation System.

You should let svchost.exe in Windows Updater application group of Defense+. But with default settings there has been an entry with "Windows Updater" or something like that in Network security policies. This rule should be removed.
Logged

Intel Core 2 Quad Q9550 [at]3,4Ghz, Scythe Mugen 2 Cooler, Gigabyte EP45-DS3LR, Kingston HyperX 2*2GB 1066Mhz, ATI HD 4890
metalforlife
Comodo's Hero
*****
Online Online

Posts: 276


« Reply #5 on: November 19, 2009, 01:43:37 PM »

Nope, I do not play LAN games. Would the rule for the LAN be necessary now?
Logged
adioz86
Comodo Loves me
****
Offline Offline

Posts: 142


« Reply #6 on: November 19, 2009, 04:05:03 PM »

No, then you don't need them.

I would recommend:
"System": everything for it except LAN (192.168.0.1 - 192.168.255.255) Incoming /Outgoing
The same for "Windows Operating System".
LAN is needed if you want to play on LAN Party.
I meant block everything except of LAN. So you can block everything for System and Windows Operation System. I would not recommend to log blocked actions, cause your Firewall log would increase really fast.
Logged

Intel Core 2 Quad Q9550 [at]3,4Ghz, Scythe Mugen 2 Cooler, Gigabyte EP45-DS3LR, Kingston HyperX 2*2GB 1066Mhz, ATI HD 4890
clockwork
Comodo Loves me
****
Offline Offline

Posts: 107


« Reply #7 on: November 19, 2009, 05:41:13 PM »

i definitely would suggest to log blocked things!
how should you know otherwise why something doesnt work?
the best chance you have when you start something, but it doesnt work, and then you see in the log, "hey, it was blocked".

who cares, if a log becomes big? after 2mb it will be erased in default.

for me its always "block and log".
Logged
metalforlife
Comodo's Hero
*****
Online Online

Posts: 276


« Reply #8 on: November 19, 2009, 06:01:27 PM »

No, then you don't need them.
I meant block everything except of LAN. So you can block everything for System and Windows Operation System. I would not recommend to log blocked actions, cause your Firewall log would increase really fast.

So that is "allow" incoming and outgoing for LAN, and block everything else?

i definitely would suggest to log blocked things!
how should you know otherwise why something doesnt work?
the best chance you have when you start something, but it doesnt work, and then you see in the log, "hey, it was blocked".

who cares, if a log becomes big? after 2mb it will be erased in default.

for me its always "block and log".

I get 20-30 alters every minute on an average. I don't want to stop logging just to see a neat events window, but I want the logging to decrease as I configure the firewall better. I haven't gotten around it as of yet, and as I keep learning more and more, I'll configure it as I want and for lesser alerts.
Logged
adioz86
Comodo Loves me
****
Offline Offline

Posts: 142


« Reply #9 on: November 20, 2009, 07:12:33 AM »

So that is "allow" incoming and outgoing for LAN, and block everything else?
That's right.

I get 20-30 alters every minute on an average. I don't want to stop logging just to see a neat events window, but I want the logging to decrease as I configure the firewall better. I haven't gotten around it as of yet, and as I keep learning more and more, I'll configure it as I want and for lesser alerts.

Then I recommend you, if you are not in a LAN, to block 137-139and 445, and just block and log everything else.
Logged

Intel Core 2 Quad Q9550 [at]3,4Ghz, Scythe Mugen 2 Cooler, Gigabyte EP45-DS3LR, Kingston HyperX 2*2GB 1066Mhz, ATI HD 4890
metalforlife
Comodo's Hero
*****
Online Online

Posts: 276


« Reply #10 on: November 20, 2009, 04:10:39 PM »

I'll do that, thanks.
Logged
shadowRider
Newbie
*
Offline Offline

Posts: 7


« Reply #11 on: November 20, 2009, 07:37:21 PM »

Are you guys able to see the Network Map under windows Network & Sharing tab?   I have allowed all communication for my LAN addresses 192.168.1.1. through 192.168.1.110 via the general rules, and Windows is not able to see or access the other computers or printers, even though I can access the printer and router via internet explorer.
Logged
adioz86
Comodo Loves me
****
Offline Offline

Posts: 142


« Reply #12 on: Yesterday at 07:19:01 AM »

Which Operating System do you have?

It looks like there is something blocked by a firewall or OS? Look up your Firewall Logs.
If you can access them via IE, then it should be possible to access them via windows.
Logged

Intel Core 2 Quad Q9550 [at]3,4Ghz, Scythe Mugen 2 Cooler, Gigabyte EP45-DS3LR, Kingston HyperX 2*2GB 1066Mhz, ATI HD 4890
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.041 seconds with 18 queries.
Powered by SMF 1.1.10 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com