Welcome, Guest. Please login or register.
March 17, 2010, 05:22:23 PM

Login with username, password and session length

372261 Posts
41235 Topics
93884 Members

Latest Member: Iza

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Archived Boards
| |-+  Discontinued Products
| | |-+  Comodo Firewall
| | | |-+  Frequently Asked Questions (FAQ) for Comodo firewall
| | | | |-+  Name resolution & file sharing on local network
« previous next »
Pages: [1] Go Down Print
Author Topic: Name resolution & file sharing on local network  (Read 10046 times)
robin
Newbie
*
Offline Offline

Posts: 2


« on: January 02, 2007, 08:30:26 AM »

Forums have been very helpful, but i had to figure one thing out for myself - just wanted to mention it incase anyone else comes across a similar problem.

On a small local network, it is generally advised on this forum to create a zone using 'tasks' and then create a network rule to:
allow IP, from IP: local zone, to IP: any

Taking the approach of opening as little as possible, I allowed IP to the local zone only (eg. to 192.168.1.1 to 192.168.1.5).

Whilst it was possible to connect to local machines/printers by IP address, connection by name (ie \\computername\sharename ) was not possible. Assuming your machine name is not given out by a DNS server, but the one you entered into windows (as mine is), you also need to allow UDP traffic (only) from the local zone to 192.168.1.255

I've attached a picture of the resulting network rule  Smiley

Ofcourse this could be done more elegently by just making the local zone 192.168.1.1 - 192.168.1.255, or even more so by allowing the local zone to contact ANY IP, but I just mentioned it incase it helps anyone else who likes to open up as little as possible :s

Thanks for great firewall btw - zonealarm pro licence pretty useless now!
« Last Edit: January 06, 2007, 07:39:05 AM by robin » Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5361


I'm not a complete idiot, some bits are missing.


« Reply #1 on: January 02, 2007, 09:05:46 AM »

Hi robin, welcome to the forums & thank you for sharing this with us.

If it's OK with you, I'll move this to the FAQ section.
Logged

Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
robin
Newbie
*
Offline Offline

Posts: 2


« Reply #2 on: January 06, 2007, 07:40:09 AM »

Kail, yes sure - I've corrected a couple of typos and attached a picture of the resulting rule.

regards, robin
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5361


I'm not a complete idiot, some bits are missing.


« Reply #3 on: January 06, 2007, 08:06:04 AM »

OK, thanks robin.. moved to FAQ.
Logged

Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
jobeard
Comodo Member
**
Offline Offline

Posts: 36


« Reply #4 on: February 11, 2007, 01:25:40 PM »

Whilst it was possible to connect to local machines/printers by IP address, connection by name (ie \\computername\sharename ) was not possible. Assuming your machine name is not given out by a DNS server, but the one you entered into windows (as mine is), you also need to allow UDP traffic (only) from the local zone to 192.168.1.255
btw:  Map Network Drive will still work w/o this rule
Logged
pepoluan™
Comodo Loves me
****
Offline Offline

Posts: 140


Da Genius in SpEX.


WWW
« Reply #5 on: March 14, 2007, 02:29:42 AM »

If I want to batten down the computer but still allow file/printer sharing, what ports should I enable?

I enabled 137, 138, 139, 445. The result: mapping using ip e.g. \\192.168.0.5\share$ works. But I am concerned that I opened too many ports.
Logged


All my TinyURL links are safe!
pepoluan™
Comodo Loves me
****
Offline Offline

Posts: 140


Da Genius in SpEX.


WWW
« Reply #6 on: March 15, 2007, 11:14:53 AM »

Any input on my concerns?
Logged


All my TinyURL links are safe!
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6258



« Reply #7 on: March 15, 2007, 11:31:39 AM »

Sorry, pepoluan, I don't have any significant input for you... I'm not the wizkid of file/print-sharing, I'm afraid.  I try to stay thoroughly away from implementing that.  Grin

However, I know some wizkids are here, so someone should help you out shortly...

LM
Logged

You read my sig block.  That's enough personal interaction for one day. Kewl
gibran
Average User
Comodo's Hero
*****
Offline Offline

Posts: 5063


A bad workman always blames his tools


« Reply #8 on: April 03, 2007, 05:36:17 PM »

Regarding the ports needed, look at the section Client/Server port usage in this page describing SMB (Server Message Block)

Quote
If the server has NetBT enabled, it listens on UDP ports 137, 138, and on TCP ports 139, 445. If it has NetBT disabled, it listens on TCP port 445 only.

Still testing it...

But these network rules could be put on top of the others.
modify your network range accordingly...

BLOCK and LOG TCP or UDP IN FROM IP NOT IN RANGE 192.168.0.0 -192.168.255.255
TO IP RANGE 192.168.0.0 -192.168.255.255 WHERE SOURCE PORT IS [ANY] AND DESTINATION PORT IS IN [135,137,138,445]


BLOCK and LOG TCP or UDP OUT FROM IP RANGE 192.168.0.0 -192.168.255.255 TO IP NOT IN RANGE 192.168.0.0 -192.168.255.255 WHERE SOURCE PORT IS IN [135,137,138,445] AND DESTINATION PORT IS [ANY]
« Last Edit: April 04, 2007, 01:42:00 AM by gibran » Logged

"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in -0 seconds with 19 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com