Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
August 21, 2008, 11:24:36 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
184929
Posts
21471
Topics
52066
Members
Latest Member:
egzepher
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Frequently Asked Questions (FAQ) for Comodo firewall
Summary of Network rules
« previous
next »
Pages:
[
1
]
2
Author
Topic: Summary of Network rules (Read 14603 times)
pandlouk
I love Comodo
Global Moderator
Comodo's Hero
Offline
Posts: 2240
Panagiotis
Summary of Network rules
«
on:
January 15, 2007, 04:03:16 PM »
Since a lot members get confused with the Network rules I decided to create this topic to gather the various rules in one place.
«
Last Edit: January 15, 2007, 04:10:40 PM by pandlouk
»
Logged
pandlouk
I love Comodo
Global Moderator
Comodo's Hero
Offline
Posts: 2240
Panagiotis
Default Rules
«
Reply #1 on:
January 15, 2007, 04:04:19 PM »
Here are the rules that are automatically created by CFP during the installation.
Rule #0
Action = Allow
Protocol = TCP or UDP
Direction = Out
Source IP = Any
Destination IP = Any
Source Port = Any
Destination Port = Any
Rule #1
Action = Allow
Protocol = ICMP
Direction = Out
Source IP = Any
Destination IP = Any
ICMP Details = ICMP Echo Request
Rule #2
Action = Allow
Protocol = ICMP
Direction = In
Source IP = Any
Destination IP = Any
ICMP Details = ICMP Fragmentation Needed
Rule #3
Action = Allow
Protocol = ICMP
Direction = In
Source IP = Any
Destination IP = Any
ICMP Details = ICMP Time Exceeded
Rule #4
Action = Allow
Protocol = IP
Direction = Out
Source IP = Any
Destination IP = Any
IP Details = GRE
Rule #5
Action = Block (create an alert if this rule is fired)
Protocol = IP
Direction = In/Out
Source IP = Any
Destination IP = Any
IP Details = Any
Logged
pandlouk
I love Comodo
Global Moderator
Comodo's Hero
Offline
Posts: 2240
Panagiotis
Restricted Secure Zone Rules
«
Reply #2 on:
January 15, 2007, 04:05:54 PM »
Instead of using the secure zone you can create copies of rules for individual IPs. This is highly recommended for users with wifi networks
For example:
If you have a network with 1 router(IP= x.x.x.1) and 3 pc (IP pc1 = x.x.x.12, IP pc2 = x.x.x.120, pc3 = y.y.y.15) you should create the following rules (at the example we configure CFP on pc1):
Rule #0
Action = Allow
Protocol = IP
Direction = Out
Source IP = pc1
Destination IP = router
IP details = Any
Rule #1
Action = Allow
Protocol = IP
Direction = In
Source IP = router
Destination IP = pc1
IP details = Any
Rule #3
Action = Allow
Protocol = IP
Direction = Out
Source IP = pc1
Destination IP = pc2
IP details = Any
Rule #4
Action = Allow
Protocol = IP
Direction = In
Source IP = pc2
Destination IP = pc1
IP details = Any
Rule #5
Action = Allow
Protocol = IP
Direction = Out
Source IP = pc1
Destination IP = pc3
IP details = Any
Rule #6
Action = Allow
Protocol = IP
Direction = In
Source IP = pc3
Destination IP = pc1
IP details = Any
Rule #7 (serves for finding the other 2 pcs by searching their name)
Action = Allow
Protocol = UDP
Direction = In
Source IP = broadcast adress of the router
Destination IP = pc1
Source Port = Any
Destination Port = Any
ps. For finding the brodcast adress of the router you can use:
1. A simple subnet calculator like this one
http://net.apollo.lv/subnet.php
2. or with Advanced Subnet Calculator a free program a little more difficult to understand.
http://www.softpedia.com/get/Network-Tools/Misc-Networking-Tools/Advanced-Subnet-Calculator.shtml
Logged
pandlouk
I love Comodo
Global Moderator
Comodo's Hero
Offline
Posts: 2240
Panagiotis
Rules for programs like p2p, etc.
«
Reply #3 on:
January 15, 2007, 04:07:15 PM »
There are programs that need to accept incoming connections for fuction properly. A classic example are the filesharing applications like emule, azureus, utorrent, etc.
Lets use Emule and azureus as examples:
For Emule
1. Rule for TCP protocol
Action = Allow
Protocol = TCP
Direction = In
Source IP = Any
Destination IP = Any
Source port = Any
Destination port = TCP port of emule
2. Rule for UDP protocol
Action = Allow
Protocol = UDP
Direction = In
Source IP = Any
Destination IP = Any
Source port = Any
Destination port = UDP port of emule
For Azureus
Rule for TCP/UDP protocol
Action = Allow
Protocol = TCP or UDP
Direction = In
Source IP = Any
Destination IP = Any
Source port = Any
Destination port = TCP/UDP port of azureus
You should move these rules over the default Block IP IN/OUT
Logged
pandlouk
I love Comodo
Global Moderator
Comodo's Hero
Offline
Posts: 2240
Panagiotis
Block IPs
«
Reply #4 on:
January 15, 2007, 04:08:59 PM »
Since CFP has statefull inspection of the packets there are two rules for blocking IPs; 1 for blocking outgoing connections and 1 for blocking incoming connections.
1.Blocking outgoing connections
(this rule will prevent your computer to initiate a connection with a banned IP)
Action = Block
Protocol = TCP or UDP
Direction = Out
Source IP = Any
Destination IP = The IP you want to block
Source port = Any
Destination port = Any
2.Blocking incoming connections
(this rule will prevent a banned IP to initiate a connection with your computer)
Action = Block
Protocol = TCP or UDP
Direction = In
Source IP = The IP you want to block
Destination IP = Any
Source port = Any
Destination port = Any
You should move these rules above all the other rules for working properly
ps.If you want to ban someone in p2p you will need the second rule.
If you want to prevent any comunication with a banned IP both rules are needed
Logged
pandlouk
I love Comodo
Global Moderator
Comodo's Hero
Offline
Posts: 2240
Panagiotis
Summary of all the rules
«
Reply #5 on:
January 15, 2007, 04:09:58 PM »
Here is an image of all the above rules together.
Logged
AOwL
Comodo SuperHero
Global Moderator
Comodo's Hero
Offline
Posts: 2349
Comodo Firewall Pro - Be safe, use protection...
Re: Summary of Network rules
«
Reply #6 on:
January 15, 2007, 04:17:05 PM »
Great work Pandlouk!
(just delete my post if it's in the way of your rules...)
Sweet pandlouk, very nice. I wouldn't ruin your FAQ.
Edit: Don't mess with my posts Kail!
«
Last Edit: January 24, 2007, 07:04:19 AM by AOwL
»
Logged
WinXP SP2 HE - IE7 - FF 2 - TB - CFP 2.4 - NOD32 - BoClean -ST - AMD64x2 - 3Gb Ram - 1.5Tb HD
pandlouk
I love Comodo
Global Moderator
Comodo's Hero
Offline
Posts: 2240
Panagiotis
Re: Summary of Network rules
«
Reply #7 on:
January 16, 2007, 04:48:40 AM »
Quote from: AOwL™ on January 15, 2007, 04:17:05 PM
Great work Pandlouk!
(just delete my post if it's in the way of your rules...)
Sweet pandlouk, very nice. I wouldn't ruin your FAQ.
Hehe.
Thanks AOwL but it cannot compare with your noob guide.
ps. anyone can post here. I had locked it temporary for being able to put those rules one after another without interaptions
Logged
Simplicity
Comodo Family Member
Offline
Posts: 83
Re: Default Rules
«
Reply #8 on:
January 31, 2007, 05:38:49 PM »
Newbie here
I installed Comodo on 2 of my computers last night and promptly lost my home network (Internet still worked on both computers tho)
I stumbled my way through the menus and found this last option you put in the message...
As soon as I deleted that rule from both computers I found my computers would talk to each other again...
Please tell me I haven't done something very wrong..
Quote from: pandlouk on January 15, 2007, 04:04:19 PM
Rule #5
Action = Block (create an alert if this rule is fired)
Protocol = IP
Direction = In/Out
Source IP = Any
Destination IP = Any
IP Details = Any
Logged
AOwL
Comodo SuperHero
Global Moderator
Comodo's Hero
Offline
Posts: 2349
Comodo Firewall Pro - Be safe, use protection...
Re: Summary of Network rules
«
Reply #9 on:
January 31, 2007, 05:56:56 PM »
Welcome to the forum
You have done something very wrong... shame on you...
Put that back immediately!
Have you made a trusted zone/network? (security/tasks)
Logged
WinXP SP2 HE - IE7 - FF 2 - TB - CFP 2.4 - NOD32 - BoClean -ST - AMD64x2 - 3Gb Ram - 1.5Tb HD
Simplicity
Comodo Family Member
Offline
Posts: 83
Re: Summary of Network rules
«
Reply #10 on:
January 31, 2007, 06:00:54 PM »
Ooopppsss
Will copy the line from this thread in an attempt to put it back again..
Trusted Zone??? - Ummm all I done is install the program, I chose the automatic thing on install, so thought that would set things up..
I think I might uninstall the firewall from both computers and then reinstall it again, that way anything I touched will be gone, then I can look for the trusted zone thing
Thank you very much for your reply
Quote from: AOwL on January 31, 2007, 05:56:56 PM
Welcome to the forum
You have done something very wrong... shame on you...
Put that back immediately!
Have you made a trusted zone/network? (security/tasks)
«
Last Edit: January 31, 2007, 06:03:25 PM by Simplicity
»
Logged
pandlouk
I love Comodo
Global Moderator
Comodo's Hero
Offline
Posts: 2240
Panagiotis
Re: Summary of Network rules
«
Reply #11 on:
January 31, 2007, 06:04:17 PM »
You can use the wizard for the trusted zone, or you can built a more Restricted Secure Zone
http://forums.comodo.com/index.php/topic,5340.msg39466.html#msg39466
,which is more secure for wifi connections
Logged
Simplicity
Comodo Family Member
Offline
Posts: 83
Re: Summary of Network rules
«
Reply #12 on:
January 31, 2007, 06:15:00 PM »
Thanks for the reply, much appreciated..
As I said above I going to uninstall and then reinstall, that way things will be back to the way they are, then I will try that wizard to see if I can get my computers talking again..
I presume there is a way to have it setup to allow a port range (eg: 192.168.*.*) in it, as I have noticed in the past that sometimes the IP addresses of my computers change.
Anyway, will give it a go and see what happens (I not too technical, cause at 52yrs old my brain takes a while to figure things out)
Quote from: pandlouk on January 31, 2007, 06:04:17 PM
You can use the wizard for the trusted zone, or you can built a more Restricted Secure Zone
http://forums.comodo.com/index.php/topic,5340.msg39466.html#msg39466
,which is more secure for wifi connections
Logged
Simplicity
Comodo Family Member
Offline
Posts: 83
Re: Summary of Network rules
«
Reply #13 on:
January 31, 2007, 06:40:07 PM »
Well thank you both for your help, I reinstalled the firewall on both computers, ran that Wizard and now have my computers talking to each other again..
Wizard was really easy to do, wasn't as bad as I though it would be.. Very straight forward..
Since you people around here so friendly and helpful, methinks I will uninstall avg and install your antivirus as well
Logged
Geekboy
Newbie
Offline
Posts: 6
Re: Summary of Network rules
«
Reply #14 on:
May 17, 2007, 06:22:45 AM »
Hi Panlouk
Thanks for the rules. I have also read M0ng0d article on network rules with no joy in solving my problem.
I have just installed CPF on my desktop and have been attempting a setup to enable ad-hoc wireless connection from my laptop using the trusted zone wizard. With CPF set to 'allow all' the wireless network adapters communicate and the laptop is assigned a 192.168.0.x IP address and am able to surf the net. Putting CPF back to 'custom' still enables internet connection. Great.
My problem is getting the wireless adapters to communicate while CPF is in the normal custom mode. The desktop wireless adaptor is manually configured to 192.168.0.1 etc but the laptop gets no communication and defaults to the 169.254.x.x IP address.
I have put the desktop wireless adapter in the trusted zone with the 192.168.0.0/255 range and left the ethernet adapter in the internet zone. I assume that is correct.
My rules seem to agree with what has been written so I assume I am missing something obvious.
Any help appreciated
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 1 seconds with 20 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com