Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 08, 2008, 05:48:28 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
198073
Posts
22794
Topics
54762
Members
Latest Member:
idra
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Frequently Asked Questions (FAQ) for Comodo firewall
Application Monitor Rules Hierarchy
« previous
next »
Pages:
1
[
2
]
3
4
Author
Topic: Application Monitor Rules Hierarchy (Read 8211 times)
OD
Forum Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 505
"To live is to dance, to dance is to live."
Re: Application Monitor Rules Hierarchy
«
Reply #15 on:
May 17, 2007, 02:48:19 PM »
You are Right just checked it out and I´ve got I backwards By double clicking on the top Set of Rules and clicking OK it will move that set of rules to the bottom it also seems to group the allow and block rules together Note I have not experimented with More than 4 rules 2 to allow and 2 to block
I will correct my rules above though.
Thanks for catchin that
Opus
Quote from: Little Mac on May 17, 2007, 02:35:03 PM
Maybe it was Toggie and I that discussed it, I don't remember. But I do remember going over app rules with someone, and reading an entry in the Help files that stated there was a hierarchy. It seems kinda buggy the way it works. There was some rule, we found, that when edited did not move up in its section, but the rest would move to the top of that application when edited. Thus, it would come first, and the user could find themselves being blocked for an allowed application...
LM
PS: SearchMaestro Soya, do your thing...
Logged
"Sometimes when I get up in the morning, I feel very peculiar. I feel like I've just got to bite a cat! I feel like if I don't bite a cat before sundown, I'll go crazy! But then I just take a deep breath and forget about it", then again sometimes you just have to bite a cat
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: Application Monitor Rules Hierarchy
«
Reply #16 on:
May 17, 2007, 02:58:13 PM »
You'll find it also groups rules by parent too...
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6017
Re: Application Monitor Rules Hierarchy
«
Reply #17 on:
May 17, 2007, 03:38:27 PM »
Quote from: Soya on May 17, 2007, 02:47:15 PM
I did. Was there enough links in that one above?
Nope, or at least not what I'm remembering. I guess it doesn't really matter. I just thought you could pull it up...
But then again, if it
was
Toggie and I, it might've been thru PM, and I purge those periodically...
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 7366
Re: Application Monitor Rules Hierarchy
«
Reply #18 on:
May 17, 2007, 03:41:42 PM »
Sigh. Here it is:
http://forums.comodo.com/index.php/topic,8804.0.html
Actually, this is the one you're really looking for as it has you in it. I didn't want you to start believing you had amnesia or something:
http://forums.comodo.com/index.php/topic,7235.0.html
Did you realize you typed "In order to" 73 times in this forum? You can just cross out "in order" part because it'll shorten your sentence. No need to present things in a sophisticated manner.
«
Last Edit: May 17, 2007, 03:45:21 PM by Soya
»
Logged
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: Application Monitor Rules Hierarchy
«
Reply #19 on:
May 17, 2007, 04:14:13 PM »
The logic used to rearrange rules in AM, is, sometimes, beyond me
1. Overall, rules are arranged alphabetically
2. Within application groups, arrangement is by parent
3. within parent groups, arrangement seems to be IN rules first, followed by OUT rules.
4. After that, it appears to place BLOCK rules Before ALLOW rules. (sometimes)
The rearrangement of the rules isn't completely automatic. In fact it's possible to force a rearrangement of the rules so that the BLOCK rule is placed last, simply by opening an ALLOW rule, clicking OK and closing the rule.
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6017
Re: Application Monitor Rules Hierarchy
«
Reply #20 on:
May 17, 2007, 04:16:59 PM »
Well golly gee, Soya! That there's the exact one about which I thought.
Thanks for providing that
in order to
keep my sanity.
My apologies for using proper grammar. The current generation of American public school grads won't present you with that issue, that's for certain.
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 7366
Re: Application Monitor Rules Hierarchy
«
Reply #21 on:
May 17, 2007, 04:20:57 PM »
Quote from: Toggie on May 17, 2007, 04:14:13 PM
The rearrangement of the rules isn't completely automatic. In fact it's possible to force a rearrangement of the rules so that the BLOCK rule is placed last, simply by opening an ALLOW rule, clicking OK and closing the rule.
I just tried it and it's as you posted. It if it's to be uniformly sorted in alphabetical order, then this is a bug because
A
llow should be before
B
lock.
If I already have a blocked rule on an app and create another rule to allow that same app, there won't be 2 app rules; it'll just replace the current one. Another inconsistency.
«
Last Edit: May 17, 2007, 04:22:46 PM by Soya
»
Logged
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: Application Monitor Rules Hierarchy
«
Reply #22 on:
May 17, 2007, 04:33:42 PM »
AM is a joy
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6017
Re: Application Monitor Rules Hierarchy
«
Reply #23 on:
May 17, 2007, 04:46:47 PM »
Another twitchy glitchy with it that I have noticed is that when (for instance) AF is at High (which would require Port/Protocol/Direction in the details), that if you have a rule that stipulates a port, and another rule that is "Any" port, it will create a prompt. In order for it to work, each port has to have its own rule (or be included in a "range" on one rule).
I first really noticed this because of BOC using an FTP server for updates. I created a rule to allow the port 21 connect, and let it popup for the other two, which I allowed without remember. That kept failing if I wasn't at the machine, so I finally made a second rule (below the port 21 rule) to allow Any port for the FTP site. Doesn't work. It still alerts on each additional port. Maybe that's because I included too much detail (the IP address) for the AF level; I really dont' want to go to Very High to include the IP though, as I don't want 5000 popups a day (number used for effect only; not an indication of reality).
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: Application Monitor Rules Hierarchy
«
Reply #24 on:
May 17, 2007, 05:03:34 PM »
My BOC rules currently are:
port 21 TCP OUT
Port 51000 - 55000 TCP OUT
Port 80 TCP OUT
Plus DNS entries. This seems to work ok, I've not received any additional prompts for quite a while. However, I don't know for sure what the port range is exactly.
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6017
Re: Application Monitor Rules Hierarchy
«
Reply #25 on:
May 17, 2007, 05:07:56 PM »
I've never seen it do port 80 out. Although it does do a DNS connect on 53. But that's enough about BOC; that's not the topic of this thread. How's that, Soya? Proud of me for steering the topic back?
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 7366
Re: Application Monitor Rules Hierarchy
«
Reply #26 on:
May 17, 2007, 05:14:22 PM »
Quote from: Little Mac on May 17, 2007, 05:07:56 PM
How's that, Soya? Proud of me for steering the topic back?
That was such a shocking development that I almost had a heart attack there.
So what's there more to type? Who's going to file a
http://support.comodo.com
ticket on this?
Logged
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: Application Monitor Rules Hierarchy
«
Reply #27 on:
May 17, 2007, 06:44:50 PM »
Which bit ;P
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 7366
Re: Application Monitor Rules Hierarchy
«
Reply #28 on:
May 17, 2007, 06:59:16 PM »
Why there are so many
bugs
mysteries on AM rules?
Logged
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: Application Monitor Rules Hierarchy
«
Reply #29 on:
May 17, 2007, 07:13:48 PM »
In all seriousness, I agree a ticket should be raised, but I think a definitive list of issues should be included as part of the request. We could just ask something like, why does AM rearrange rules, but it's a bit woolly.
What I'd like, is a solid explanation from one of the devs, about how AM is supposed to work...
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Tags:
Pages:
1
[
2
]
3
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.257 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com