Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 14, 2010, 06:14:24 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
370838
Posts
41083
Topics
93540
Members
Latest Member:
liwei
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Discontinued Products
Comodo Firewall
Frequently Asked Questions (FAQ) for Comodo firewall
Internet Connection Sharing problem
« previous
next »
Pages:
1
[
2
]
3
4
Author
Topic: Internet Connection Sharing problem (Read 15215 times)
vabantha
Newbie
Offline
Posts: 17
Re: Internet Connection Sharing problem
«
Reply #15 on:
February 27, 2007, 05:54:08 PM »
Yes, it's been connected.
IP 192.168.0.252
subnet 255.255.255.0
gateway 192.168.0.1
Quote from: pandlouk on February 27, 2007, 05:49:19 PM
Did you connect the laptop? I mean did it acquired the IP adress and the connection through ICS?
It seems strange because CFP reports the same range again.
Please check at your laptops connection status.
Start
->
Control Panel
->
Network and internet connections
->
Network connections
Select the active network connection, right click with he mouse and select
status
->
support
IP adress=?
Subnet Mask=?
Default gateway=?
Logged
pandlouk
I love Comodo
Comodo's Hero
Offline
Posts: 2240
Retired Mod
Re: Internet Connection Sharing problem
«
Reply #16 on:
February 27, 2007, 06:24:10 PM »
ok the default gateway of your portable is the ics host.
add this rule at the network monitor of the host pc.
Action = Allow
Protocol = UDP
Direction = In
Source IP = Any
Destination IP = 192.168.0.1
Source port = 68
Destination port = 67
then move this rule up over the
default BLOCK Rule
and try to do some tests connecting and disconnecting your portable.
if this resolve the problem please report back the results.
«
Last Edit: February 27, 2007, 06:27:41 PM by pandlouk
»
Logged
vabantha
Newbie
Offline
Posts: 17
Re: Internet Connection Sharing problem
«
Reply #17 on:
February 28, 2007, 11:20:25 AM »
Didn't work...
Quote from: pandlouk on February 27, 2007, 06:24:10 PM
ok the default gateway of your portable is the ics host.
add this rule at the network monitor of the host pc.
Action = Allow
Protocol = UDP
Direction = In
Source IP = Any
Destination IP = 192.168.0.1
Source port = 68
Destination port = 67
then move this rule up over the
default BLOCK Rule
and try to do some tests connecting and disconnecting your portable.
if this resolve the problem please report back the results.
Logged
pandlouk
I love Comodo
Comodo's Hero
Offline
Posts: 2240
Retired Mod
Re: Internet Connection Sharing problem
«
Reply #18 on:
February 28, 2007, 04:01:39 PM »
Quote from: vabantha on February 28, 2007, 11:20:25 AM
Didn't work...
Hi Vabantha,
I did some research and from
http://www.microsoft.com/technet/security/smallbusiness/topics/ServerSecurity/ref_net_ports_ms_prod.mspx
I found that you must allow udp incoming for the ports 53,67 and maybe 2535. And maybe is also necessary to alow tcp incoming at the port 53.
These should be the rules:
Rule 1 (necessary)
Action = Allow
Protocol = UDP
Direction = In
Source IP = Any
Destination IP = 192.168.0.1
Source port = ?
Destination port = 53
Rule 2 (necessary)
Action = Allow
Protocol = UDP
Direction = In
Source IP = Any
Destination IP = 192.168.0.1
Source port = 68
Destination port = 67
Rule 3 (?)
Action = Allow
Protocol = UDP
Direction = In
Source IP = Any
Destination IP = 192.168.0.1
Source port = ?
Destination port = 2535
Rule 4(?)
Action = Allow
Protocol = TCP
Direction = In
Source IP = Any
Destination IP = 192.168.0.1
Source port = ?
Destination port = 53
ps. I'll ask the other mods and maybe someone from the firewall team to help me restrict a little these rules. Hopefully tomorrow we will finally resolve the ICS problem
Logged
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 8172
Re: Internet Connection Sharing problem
«
Reply #19 on:
February 28, 2007, 04:07:21 PM »
I hope this isn't irrelevant, but your first log pic indicates outgoing ICMP (needed fragmentation) is blocked. Is a Net Mon rule required to allow these connections?
Logged
Do u know how I sleep? With 1 eye open. I have 9 kids. U know what they say? "Papa if u don't have candy we are going to kill u in your sleep!" When I finally get to sleep & they find the candy do u think they thank me? No. They say "Papa u stupid. Papa u ugly. Papa u look like a pornstar from 1977"
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6258
Re: Internet Connection Sharing problem
«
Reply #20 on:
February 28, 2007, 04:13:45 PM »
soyabeaner, I think you're thinking of default Rule ID 2, which is Allow
In
ICMP where message is Fragmentation Needed.
LM
Logged
You read my sig block. That's enough personal interaction for one day.
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 8172
Re: Internet Connection Sharing problem
«
Reply #21 on:
February 28, 2007, 04:18:07 PM »
I know, but vabantha's log shows Outbound Policy Violation, so it must be outgoing connections.
Logged
Do u know how I sleep? With 1 eye open. I have 9 kids. U know what they say? "Papa if u don't have candy we are going to kill u in your sleep!" When I finally get to sleep & they find the candy do u think they thank me? No. They say "Papa u stupid. Papa u ugly. Papa u look like a pornstar from 1977"
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6258
Re: Internet Connection Sharing problem
«
Reply #22 on:
February 28, 2007, 04:33:27 PM »
Okay, then that may be a possibility.
But here's two questions, and some suggestions:
1. Is CFP installed on both computers (just to make certain); if so, you will need to define the Zone & set it as a Trusted Network, on both computers.
2. When you defined the Zone, did you modify the IP addresses at all, or are they as CFP defined them?
Now the suggestions, to "force" the issue, since we know there's something in CFP's rules that are stopping you (since it works if set to Allow All).
Turn both computers off. Then turn the Host back on, get it connected to the internet successfully. Then connect the Client (laptop), turn it on, and try to connect. Does it work? If so it may be due to a response delay.
Next step, if that doesn't work. Turn Network Monitor on each computer off, one at a time, starting with Host. Check each time to see if you can connect. If so, we can narrow it down to that machine's Network Monitor.
Next step, if that doesn't work. Go to Security/Advanced/Miscellaneous. Move Alert Frequency to High or Very High. OK. Reboot. After reboot, you will get a lot more alerts; be sure to Allow & Remember on svchost.exe, or you may lose all connectivity. If you recognize an application, and know you want to allow it, select Allow & Remember. Now see if your computers can both connect.
Last step, if you still have no joy: Edit: Next step. Turn to Allow All. Connect Client, establish connection. Check Activity/Connections as it's connecting, to see application, IP Protocol, IP addresses, and Ports used. Then we'll create rules specifically for that.
Hope something here helps,
LM
«
Last Edit: February 28, 2007, 04:37:42 PM by Little Mac
»
Logged
You read my sig block. That's enough personal interaction for one day.
vabantha
Newbie
Offline
Posts: 17
Re: Internet Connection Sharing problem
«
Reply #23 on:
February 28, 2007, 05:11:18 PM »
I have only have comodo running on the host computer. I wanted to get the ICS working through the host before screwing around with the laptop. When I turn the network control rules off on the host, everything works fine. I'm assuming the ICS problem is there.
Quote from: Little Mac on February 28, 2007, 04:33:27 PM
Okay, then that may be a possibility.
But here's two questions, and some suggestions:
1. Is CFP installed on both computers (just to make certain); if so, you will need to define the Zone & set it as a Trusted Network, on both computers.
2. When you defined the Zone, did you modify the IP addresses at all, or are they as CFP defined them?
Now the suggestions, to "force" the issue, since we know there's something in CFP's rules that are stopping you (since it works if set to Allow All).
Turn both computers off. Then turn the Host back on, get it connected to the internet successfully. Then connect the Client (laptop), turn it on, and try to connect. Does it work? If so it may be due to a response delay.
Next step, if that doesn't work. Turn Network Monitor on each computer off, one at a time, starting with Host. Check each time to see if you can connect. If so, we can narrow it down to that machine's Network Monitor.
Next step, if that doesn't work. Go to Security/Advanced/Miscellaneous. Move Alert Frequency to High or Very High. OK. Reboot. After reboot, you will get a lot more alerts; be sure to Allow & Remember on svchost.exe, or you may lose all connectivity. If you recognize an application, and know you want to allow it, select Allow & Remember. Now see if your computers can both connect.
Last step, if you still have no joy: Edit: Next step. Turn to Allow All. Connect Client, establish connection. Check Activity/Connections as it's connecting, to see application, IP Protocol, IP addresses, and Ports used. Then we'll create rules specifically for that.
Hope something here helps,
LM
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6258
Re: Internet Connection Sharing problem
«
Reply #24 on:
February 28, 2007, 05:24:36 PM »
Okay, so the next step then would be,
Turn the Network Monitor back on.
Set Security to Allow All.
Open Activity/Connections.
Connect Client, create connection. Watch CFP Connections screen, write down (or do a screenshot) of the connection(s) created when the laptop is able to connect.
We will use this info to create Network rules to (hopefully) resolve this little (big) problem.
LM
Logged
You read my sig block. That's enough personal interaction for one day.
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 8172
Re: Internet Connection Sharing problem
«
Reply #25 on:
February 28, 2007, 05:30:14 PM »
It may be easier to create a Network Monitor to allow all IP In/Out, put it at the top, and then edit that rule to log (
Create an alert if this rule is fired
).
Logged
Do u know how I sleep? With 1 eye open. I have 9 kids. U know what they say? "Papa if u don't have candy we are going to kill u in your sleep!" When I finally get to sleep & they find the candy do u think they thank me? No. They say "Papa u stupid. Papa u ugly. Papa u look like a pornstar from 1977"
pandlouk
I love Comodo
Comodo's Hero
Offline
Posts: 2240
Retired Mod
Re: Internet Connection Sharing problem
«
Reply #26 on:
February 28, 2007, 05:49:58 PM »
Quote from: soyabeaner on February 28, 2007, 05:30:14 PM
It may be easier to create a Network Monitor to allow all IP In/Out, put it at the top, and then edit that rule to log (
Create an alert if this rule is fired
).
I agree.
1. vabantha please add the above rule of soyabeaner at position #3 and enable all the three top rules (the first two are your trusted zone) to log.
2. Then clear the logs from CFP and after that start an ICS connection with the laptop.
3. Export the logs in html and attach them here in a zip archive.
Thanks,
Panagiotis
Logged
vabantha
Newbie
Offline
Posts: 17
Re: Internet Connection Sharing problem
«
Reply #27 on:
February 28, 2007, 06:24:11 PM »
Ok, I've added the rule. I am still unable to access the internet on the laptop with the new rule.
Quote from: pandlouk on February 28, 2007, 05:49:58 PM
I agree.
1. vabantha please add the above rule of soyabeaner at position #3 and enable all the three top rules (the first two are your trusted zone) to log.
2. Then clear the logs from CFP and after that start an ICS connection with the laptop.
3. Export the logs in html and attach them here in a zip archive.
Thanks,
Panagiotis
«
Last Edit: March 01, 2007, 03:08:54 PM by vabantha
»
Logged
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 8172
Re: Internet Connection Sharing problem
«
Reply #28 on:
February 28, 2007, 06:28:44 PM »
Thanks for the uploads, vabantha. You should edit out any private IPs, though. Strange how your internet was still inaccessible because the allow all IP rule is essentially the same as the Allow All security level setting.
«
Last Edit: February 28, 2007, 06:30:31 PM by soyabeaner
»
Logged
Do u know how I sleep? With 1 eye open. I have 9 kids. U know what they say? "Papa if u don't have candy we are going to kill u in your sleep!" When I finally get to sleep & they find the candy do u think they thank me? No. They say "Papa u stupid. Papa u ugly. Papa u look like a pornstar from 1977"
pandlouk
I love Comodo
Comodo's Hero
Offline
Posts: 2240
Retired Mod
Re: Internet Connection Sharing problem
«
Reply #29 on:
February 28, 2007, 06:37:12 PM »
Thanks Vabantha.
It is strange indeed.
Can you please reboot your host and try this again?
IMPORTANT:
1. Disable
do protocol analysis
2. Make sure to have unplugged your portable pc before you clear the logs. I could not find the initial traffic which assign the IP at the portable pc.
After that attach again the new logs
«
Last Edit: February 28, 2007, 06:40:11 PM by pandlouk
»
Logged
Tags:
Pages:
1
[
2
]
3
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> False Positive/Negative reporting - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.066 seconds with 20 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com