Welcome, Guest. Please login or register.
October 16, 2008, 04:40:07 PM

Login with username, password and session length

200857 Posts
23049 Topics
55226 Members

Latest Member: whiteguy

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Frequently Asked Questions (FAQ) for Comodo firewall
| | | |-+  Application Monitor Rules Hierarchy
« previous next »
Pages: 1 2 [3] 4 Go Down Print
Author Topic: Application Monitor Rules Hierarchy  (Read 8722 times)
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6017



« Reply #30 on: May 17, 2007, 09:54:36 PM »

How about, "Please see this thread, and respond..." ?
Logged

date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #31 on: May 17, 2007, 09:58:53 PM »

That might work Smiley
Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #32 on: May 17, 2007, 09:59:46 PM »

Hey Opus, sorry we hijacked your thread Smiley
Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
OD
Forum Volunteer
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 507


"To live is to dance, to dance is to live."


« Reply #33 on: May 17, 2007, 11:08:19 PM »

No problem
I,ve found it interesting
and almost impossible to get AM to do exactly What I wanted

What I would like is an expert mode in AM that would dissable auto sorting within Rule sets.
Rule sets being defind as a group of rules where the "Path" Application and the "Parent" application are all the same.

Also I would like An option to log all traffic allowed or blocked or better yet an option to Select loging for specific rules Like Net Mon

Programs that auto arange things are always great for beginer users but it always seams tyo be a pain for the advanced uses if you cant turn off the auto arrange features


Hey Opus, sorry we hijacked your thread Smiley
Logged

"Sometimes when I get up in the morning, I feel very peculiar. I feel like I've just got to bite a cat! I feel like if I don't bite a cat before sundown, I'll go crazy! But then I just take a deep breath and forget about it", then again sometimes you just have to bite a cat
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #34 on: May 17, 2007, 11:18:18 PM »

I seem to remember requesting something similar myself, can't remember which wishlist...Oh well V3 comes soon...
Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #35 on: May 18, 2007, 12:46:33 AM »

One I forgot Smiley

If one has a application with several parents, and one of the parents gets wiped (yes it does happen) AM leaves all the other parents alone...

As an example (this has happened to me several times with both fx and tb) Take firefox

It has several parents and each parent has several rules. For one reason or another, yet to be established, I find that one set of rules, related to a single parent has been set to 'skip the parent' all other rules for each or the other parents are fine, that is, they retain their respective parents.
Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6017



« Reply #36 on: May 18, 2007, 12:49:52 PM »

My ticket to support reads as follows:

Quote
Will you please review this thread and comment on Application rules and why they don't function as it seems they should?

http://forums.comodo.com/index.php/topic,8863.0/topicseen.html

Thanks, we'd really like a concise answer on this confusing issue.

LM
Logged

date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
OD
Forum Volunteer
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 507


"To live is to dance, to dance is to live."


« Reply #37 on: May 18, 2007, 02:40:38 PM »

I think it is a good plan to file the ticket.
I doubt they will do anything about it in version 2 but with this and if it is not improved in V3, We should keep afte them in the beta program.
Enough Voices will probably eventualy be heard. Smiler 

If this was fixed I believe Comodo would have a world class Firewall Comprable with most of the ones out on the Commercial Market

I have not worked with Checkpoint in years but I'd like to hear of Some opinions of people who have worked with some of the commecial enterprise firewall and get their opinions of Comodo

If this applies to anyone out there if it does Please post your opinion of the two in comparison.  maybe I will post a poll.






My ticket to support reads as follows:

LM
Logged

"Sometimes when I get up in the morning, I feel very peculiar. I feel like I've just got to bite a cat! I feel like if I don't bite a cat before sundown, I'll go crazy! But then I just take a deep breath and forget about it", then again sometimes you just have to bite a cat
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #38 on: May 18, 2007, 03:04:01 PM »

Hey Opus, it might be worth pursuing that conversation in the Computer Firewalls forum. It's likely you'll get a better response Smiley

LM, do you want me to file a ticket too?
Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6017



« Reply #39 on: May 18, 2007, 03:20:13 PM »

LM, do you want me to file a ticket too?
I think that'd be good.  Not to overwhelm, but to make sure they realize it's not a random issue or question.

LM
Logged

date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #40 on: May 18, 2007, 03:46:40 PM »

Done
Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
gibran
Forum Member
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3882


Sometimes words are meaningless indeed...


« Reply #41 on: May 18, 2007, 05:17:27 PM »

Ok I think Ive got it figured out for CPF version 2.4.18.184 this may change completely for  CPF V3
Note Application rules Are very complicated and some of the auto configuration features in COMODO may cause problems in manually configured Application rule Sets


I really had problem understanding this thread... Huh
Why don't you use Not in range (or zone)?
It would be interesting to export cpf setting before and after rules sorting (maybe the rules are saved the same way but displayed differently)
Logged

Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #42 on: May 18, 2007, 05:30:14 PM »

You've lost me gibran Huh
Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
gibran
Forum Member
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3882


Sometimes words are meaningless indeed...


« Reply #43 on: May 18, 2007, 06:18:13 PM »

Yeah gibran.  What do you mean "zone"?  The define a network one or the twilight version?  I thought this was about Application Monitor Huh

Well... you can use block not in zone in app monitor too...
Hmmm... I assumed that Appmon rules were not hierarchical so I would have used allow zone and deny not in zone instead of

      Path- C:\windows\ Explorer.exe
      Parent- C:\windows\System32\Userinit.exe 
      Destination- [LAN]
      Port- [ANY]
      Protocol- TCP/UDP In
      Permission- Allow

      Path- C:\windows\ Explorer.exe
      Parent- C:\windows\System32\Userinit.exe 
      Destination- [LAN]
      Port- [ANY]
      Protocol- TCP/UDP Out
      Permission- Allow

      Path- C:\windows\ Explorer.exe
      Parent- C:\windows\System32\Userinit.exe 
      Destination- [ANY]
      Port- [ANY]
      Protocol- TCP/UDP In
      Permission- Block

      Path- C:\windows\ Explorer.exe
      Parent- C:\windows\System32\Userinit.exe 
      Destination- [ANY]
      Port- [ANY]
      Protocol- TCP/UDP Out
      Permission- Block
« Last Edit: May 18, 2007, 06:21:47 PM by gibran » Logged

pacificwing
Newbie
*
Offline Offline

Posts: 17


« Reply #44 on: May 21, 2007, 10:14:41 AM »

I can also confirm the speculation on this thread that the AM works in an entirely non-sensible way.

Ideally, I would love to have absolute control over application access rights. If I want my webbrower to access only outbound port 80, and block everything else, then I should be able to do this.

Currently, this is only intermittently possible. AM is not supposed to have a hierarchy, according to what I've read. The problem is, is that it DOES have a hierarchy. The rule order DOES effect how the AM behaves. The problem is, the user has no reliable way to control what this hierarchy is.

The AM should have a fully functional hierarchy. This is the way most other firewalls behave. I say, in V3, hierarchy control should be added to AM (similar to what is in NM). Furthermore, it would simplify things immensely if it were possible to "group" applications, to prevent a tediously long AM list from forming.

If those two features were added in V3, all of the major AM problems would go away.

My two cents,
-PW
Logged
Tags:
Pages: 1 2 [3] 4 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 1.248 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com