Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
August 29, 2008, 08:41:24 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
187195
Posts
21658
Topics
52479
Members
Latest Member:
wellofsouls
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Frequently Asked Questions (FAQ) for Comodo firewall
Problems with acquiring or renewing the IP address
« previous
next »
Pages:
[
1
]
2
3
...
13
Author
Topic: Problems with acquiring or renewing the IP address (Read 45452 times)
pandlouk
I love Comodo
Global Moderator
Comodo's Hero
Offline
Posts: 2240
Panagiotis
Problems with acquiring or renewing the IP address
«
on:
February 26, 2007, 12:43:53 PM »
If you have a problem like:
1. Connecting in internet with a modem
2. Difficulties in acquiring the IP address (through the DCHP server)
3. Renewing the IP address (through the DCHP server)
4. Loosing connectivity
Try to disable the feature
Do Protocol Analysis
in CFP.
You will find it under
Security
->
Advanced
->
Advanced Attack Detection and Prevention
->
Configure
->
Miscelanous
ps. In some cases a reboot is needed for this to work.
«
Last Edit: March 04, 2007, 09:56:38 AM by pandlouk
»
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6011
Re: Problems with acquiring or renewing the IP address
«
Reply #1 on:
February 26, 2007, 01:38:31 PM »
Pandlouk,
For the sake of education, why would disabling protocol analysis aid in obtaining the DHCP lease?
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
pandlouk
I love Comodo
Global Moderator
Comodo's Hero
Offline
Posts: 2240
Panagiotis
Re: Problems with acquiring or renewing the IP address
«
Reply #2 on:
February 26, 2007, 01:49:20 PM »
Quote from: Little Mac on February 26, 2007, 01:38:31 PM
Pandlouk,
For the sake of education, why would disabling protocol analysis aid in obtaining the DHCP lease?
LM
Hi Little Mac,
It seems that with some network cards, modems, etc., the protocol analysis block some data from the dchp server. I do not know why though
. Maybe Egemen could give us some information.
I suspected about this, since it gave problems with gprs,bluetooth, and wifi cards but thanks to willas00 I had the confermation about it.
http://forums.comodo.com/index.php/topic,6335.msg49501.html#msg49501
«
Last Edit: February 26, 2007, 01:51:20 PM by pandlouk
»
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6011
Re: Problems with acquiring or renewing the IP address
«
Reply #3 on:
February 26, 2007, 02:06:20 PM »
Hmm, I notice in the Help Files release notes that an issue with DHCP Lease Renewal/Stateful Packet Inspection was resolved for version 2.3.6.81.
Perhaps it has been "un-resolved" or there is a new issue... Probably someone who is/was experiencing it needs to file a ticket with Support.
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
MitchA
Newbie
Offline
Posts: 9
Re: Problems with acquiring or renewing the IP address
«
Reply #4 on:
March 04, 2007, 09:43:26 AM »
I just recently tried this and it really does help, lately my interent connection had been dropping arounf every 6 hours or so and evertyime it did there was a block entry in the log with an ip address & the dhcp port attached to it, now my connection is no longer dropping and I no longer see any dhcp blocked ips in the log
Logged
gustav
Newbie
Offline
Posts: 8
Re: Problems with acquiring or renewing the IP address
«
Reply #5 on:
March 08, 2007, 03:26:10 PM »
I have a similar problem, which does not seem to be resolved by disabling the protocol analysis, however as soon as I turn off the network monitor on my host computer the problem goes away. That said, I haven't found any clues as to what is blocked, looking at several log entries, except perhaps this one
Date/Time :2007-03-07 16:54:53
Severity :Medium
Reporter :Network Monitor
Description: Inbound Policy Violation (Access Denied, IP = 192.168.0.77, Port = bootp(67))
Protocol: UDP Incoming
Source: 192.168.0.77:dhcp(68)
Destination: 255.255.255.255:bootp(67)
and at the same time
Date/Time :2007-03-07 16:54:53
Severity :Low
Reporter :Network Monitor
Description: Information (Access Granted, IP = 192.168.0.77, Port = bootp(67))
Protocol: UDP Incoming
Source: 192.168.0.77:dhcp(68)
Destination: 255.255.255.255:bootp(67)
Reason: Network Control Rule ID = 1
this seems to imply that the same rule allows and denies access
On my client computer I see the following entries
Date/Time :2007-03-08 14:40:33
Severity :Low
Reporter :Network Monitor
Description: Information (Access Granted, IP = 192.168.0.1, Port = bootp(67))
Protocol: UDP Outgoing
Source: 192.168.0.251:dhcp(68)
Destination: 192.168.0.1:bootp(67)
Reason: Network Control Rule ID = 1
even though it is not getting any Ip address.
I am totally mystified
P.S. this problem only started after the latest update of Comodo
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6011
Re: Problems with acquiring or renewing the IP address
«
Reply #6 on:
March 08, 2007, 04:03:29 PM »
gustav,
I must say, "
" That makes no sense to me... How can one rule both allow & deny the exact same communication at the exact same time?
What's odd to is that IP of the Outgoing message from the client is not the same IP listed in the Incoming message on the host.
Will you please open your Network Monitor to full screen, capture a screenshot, save it, and attach to your post under Additional Options. If you personal IP address shows in it, you can mask it out for privacy.
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
pandlouk
I love Comodo
Global Moderator
Comodo's Hero
Offline
Posts: 2240
Panagiotis
Re: Problems with acquiring or renewing the IP address
«
Reply #7 on:
March 08, 2007, 05:23:48 PM »
Quote from: gustav on March 08, 2007, 03:26:10 PM
Date/Time :2007-03-07 16:54:53
Severity :Medium
Reporter :Network Monitor
Description: Inbound Policy Violation (Access Denied, IP = 192.168.0.77, Port = bootp(67))
Protocol: UDP Incoming
Source: 192.168.0.77:dhcp(68)
Destination: 255.255.255.255:bootp(67)
and at the same time
Date/Time :2007-03-07 16:54:53
Severity :Low
Reporter :Network Monitor
Description: Information (Access Granted, IP = 192.168.0.77, Port = bootp(67))
Protocol: UDP Incoming
Source: 192.168.0.77:dhcp(68)
Destination: 255.255.255.255:bootp(67)
Reason: Network Control Rule ID = 1
this seems to imply that the same rule allows and denies access
First time for me too.
I think that you just found a bug in CFP.
Quote from: soyabeaner on March 08, 2007, 04:47:18 PM
Also, I don't believe I've ever seen a Severity warning at Low level. The first is medium, the second is low.
Low security are the allow rules when they are logged.
Logged
gustav
Newbie
Offline
Posts: 8
Re: Problems with acquiring or renewing the IP address
«
Reply #8 on:
March 08, 2007, 11:28:09 PM »
Here are the rules for my host ICS computer, although the rule number has changed, it is now number 3, allowing traffic in from my local network. It is definitely here the problem lies, because as soon as I turn off the network monitor, I can get a new IP address from the dhcp.
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 5342
... and I say to myself, "What a wonderful world"
Re: Problems with acquiring or renewing the IP address
«
Reply #9 on:
March 09, 2007, 12:16:24 AM »
G'day all,
Question out of left field - if Gustav's first alert was as a result of a broadcast message sent to 255.255.255.255:67 by 192.168.0.77:68, as an address of 255.255.255.255 is well outside the named range for his zone, would we need to make an explicit rule to allow traffic IN for the broadcast address?
I know previous versions handled the broadcast address as allowable, regardless of whether it had a NM rule or not, maybe this is what has changed in the latest version.
To test the theory, we need to make a NM rule with the following values :
Action : ALLOW
Direction : IN
Protocol : UDP
Source IP : ANY
Destination IP : 255.255.255.255
Source Port : 68
Destination Port : 67
Logging should be enabled for the duration of the test and this new rule should be rule 0 - at the very top of the list.
Do you think this would help? Or have I just made the waters muddier?
Cheers,
Ewen :-)
«
Last Edit: March 09, 2007, 05:41:14 AM by panic
»
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
willas00
Comodo Loves me
Offline
Posts: 154
Re: Problems with acquiring or renewing the IP address
«
Reply #10 on:
March 09, 2007, 09:00:02 AM »
ive added that to the NM rules now mine is due to renew at 1700 UK Time so we shall see if that helps me. The TOP post worked for me fine but stoped working all of a sudden. Maybe this will work if not ill post logs 2night
Logged
irc.ukchatters-planet.co.uk
http://www.ukchatters-planet.co.uk
http://www.doubletroubleradio.co.uk
pepoluan
Comodo Loves me
Offline
Posts: 138
Re: Problems with acquiring or renewing the IP address
«
Reply #11 on:
March 09, 2007, 09:29:18 AM »
Hi!
Our school server, which is connected to Cable ISP, requires DHCP to get its IP address. DHCP always failed when Comodo is active. So I added some rules:
Allow UDP In/Out from [Any] to [Any] where source port is 67-68 and destination port is 67-68.
No problems with DHCP anymore.
( I know that is overkill, but our server is used as the DHCP server for the school's internal network )
Logged
All my TinyURL links are safe!
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6011
Re: Problems with acquiring or renewing the IP address
«
Reply #12 on:
March 09, 2007, 11:30:30 AM »
Quote from: panic on March 09, 2007, 12:16:24 AM
Logging should be enabled for the duration of the test and this new rule should be rule 0 - at the very top of the list.
Do you think this would help? Or have I just made the waters muddier?
I think that's worth a shot, Ewen. You may be right about the current version; I had not followed that train of thought back, although I know they made changes to the way it monitors and logs traffic.
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
gustav
Newbie
Offline
Posts: 8
Re: Problems with acquiring or renewing the IP address
«
Reply #13 on:
March 09, 2007, 12:40:44 PM »
I have tried most of these solutions, without success. If I turn off the network monitor I see the request for an IP address from 0.0.0.0 to 255.255.255.255, as you can see from the connections shot attached, but I have not managed to get these rules to open up my firewall.
Paradoxically, even if I cannot renew my IP address, I can still connect to the internet if I am using one previously acquired, whose lease has not yet expired.
I can also share files and printers if I use a static Ip address (alternative configuration)
Logged
willas00
Comodo Loves me
Offline
Posts: 154
Re: Problems with acquiring or renewing the IP address
«
Reply #14 on:
March 09, 2007, 12:57:12 PM »
Quote from: panic on March 09, 2007, 12:16:24 AM
To test the theory, we need to make a NM rule with the following values :
Action : ALLOW
Direction : IN
Protocol : UDP
Source IP : ANY
Destination IP : 255.255.255.255
Source Port : 68
Destination Port : 67
Did that it will went dead. in my other post ive posted logs!
Logged
irc.ukchatters-planet.co.uk
http://www.ukchatters-planet.co.uk
http://www.doubletroubleradio.co.uk
Tags:
Pages:
[
1
]
2
3
...
13
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.171 seconds with 20 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com