Welcome, Guest. Please login or register.
November 28, 2009, 08:54:21 AM

Login with username, password and session length

338269 Posts
37450 Topics
84949 Members

Latest Member: Fenrir Ragner

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Archive Boards
| |-+  Comodo Firewall
| | |-+  Help for v2
| | | |-+  Comodo & Hamachi
« previous next »
Pages: [1] Go Down Print
Author Topic: Comodo & Hamachi  (Read 2962 times)
somethingnew
Newbie
*
Offline Offline

Posts: 1


« on: June 27, 2007, 07:53:25 PM »

Hi there,

can anybody please add a tutorial for setting up Hamachi on Comodo Firewall (RULES ETC.)

I am new to Comodo, but it is simple. I tried yesterday, with my friend also using Hamachi. All we were trying to do was ping each other.

All routers were forwarding ports of Hamachi i.e. 12975.
Last thing left was Comodo to set it up.

I tried it in simple way. I turned off Hamachi & turned back on, and got alert from Comodo, & then I allowed it  "Allow" to communicate. This action added "Hamachi.exe" into application monitor list. sorry I cannot provide screenshots now, as I am away from my pc. I edited the setting of hamachi.exe in application monitor to be a trusted application, and allow any traffic by this application. and even invible connections also.
my friend did same thing.
but still after that we were not able to ping each other.
only way we could ping each other was, if we tun of firewall, like going to summary page and selecting "allow all" from lefft bottom corner.
then we dicovered network rules.
the last rule i.e. "block" seemed to us unfair, and i got rid of it, & now the ping was working. but it made a sense that anybody can enter my network.
so, i applied again by asking settings of this rule from my friend. it added as last rule as it was before, but after adding this time, Comodo behaved differently. It wasnot letting me even logon to hamachi, pinging was also lost.

fidling around, didn't solved my problem. so i uninstalled comodo, and did reinstalled to get all default rules.
and now Hamachi can log into the server., but haven't tried yet to ping my friend's pc.

so you can see i am pretty new to these rules, it would be good if you can put a tutorial.

please consider the following:
system os :winxp sp2 pro
user: administrators
net: at my end adsl & my friend's cable
requirement: Comodo to provide all access on Hamachi virtual connection between me & my friend's ip only, and on all ports, both tcp & udp.

& most important : after everything is done, I need to communicate my friend via Hamachi (i.e. VPN) on port 7788, so this port should be forwarded in both directions to my friend only.

version: Comodo latest & Hamachi also latest (infact downloaded them yesterday)

thanks heaps.
« Last Edit: June 27, 2007, 09:20:10 PM by somethingnew » Logged
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6254



« Reply #1 on: June 28, 2007, 08:53:50 AM »

welcome to the forums, somethingnew!

I responded to your PM, and will post here as well.

Try this post:

http://forums.comodo.com/help/hamachi_fails_after_installing_cpf-t788.0.html;msg5711#msg5711

These will go in Network Monitor; they need to be at the top of the list (positions Rule ID 0 & 1).  As Trench notes, Hamachi is sort of its own "virtual" network; and it needs to be defined as such within CFP's network rules.  These two rules will allow all traffic to & from Hamachi's interface.

Once that's working, you can try changing the "Any" IP to your friend's IP (and your friend changing it to yours) on the "In" rule to limit the access.

Your Application Rules should be fine for that part of it.  Once you have the Network rules in place, you might not even need to have Hamachi defined as a "trusted" application; you could always try it and see, but I'd get the Network Rules working first.

And yes, you need that Block & Log All rule in place; that is your safety net.  However, it MUST be the last rule (the bottom position), as the rules filter from the top downward.  If it's not at the bottom, it will be blocking anything that comes below it; you can click on that rule and then use the Move button to get to the bottom.

LM
Logged

You read my sig block.  That's enough personal interaction for one day. Kewl
gordon
Comodo's Hero
*****
Offline Offline

Posts: 249



« Reply #2 on: June 28, 2007, 09:02:11 AM »

note that the default Comodo Network Monitor rules do not allow ECHO_REPLY
therefore you will never return  a ping with a pong EVEN if the nodes
are in fact connectible (over other protocol(s)) ...
« Last Edit: June 28, 2007, 09:08:47 AM by gordon » Logged

Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6254



« Reply #3 on: June 28, 2007, 09:20:07 AM »

note that the default Comodo Network Monitor rules do not allow ECHO_REPLY
therefore you will never send a reply to a ping EVEN if the nodes
are in fact connectible (over other protocol(s)) ...
It will with those two network rules (as in the linked post) which make the Hamachi interface a Zone & then define that as a Trusted Network.  Since the rules Allow IP (rather than limiting to TCP/UDP/etc), they allow the various subsets to occur as well.  Pinging should not be an issue with that type of setup.

LM
Logged

You read my sig block.  That's enough personal interaction for one day. Kewl
bokkibear
Newbie
*
Offline Offline

Posts: 2


« Reply #4 on: June 30, 2007, 10:50:26 AM »

I'm having some odd problems with Hamachi too - I've set it up as a trusted zone, so the network monitor is happy, but the application monitor is blocking DHCP requests from svchost.exe when Hamachi tries to start up. The weird thing is that I have the following rule in the application monitor:

Allow all activities for svchost.exe, including invisible connections.

Yet still the logs show the following block:

Date Created: 16:44:41 30-06-2007
Date/Time :2007-06-30 16:44:32
Severity :Medium
Reporter :Application Monitor
Description: Application Access Denied (svchost.exe:5.0.0.1:  :dhcp(68))
Application: C:\WINDOWS\system32\svchost.exe
Parent: C:\WINDOWS\system32\services.exe
Protocol: UDP In
Destination: 5.0.0.1::dhcp(68)


When I turn off the application monitor, everything works fine. Can anyone explain why this might be happening?
Logged
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6254



« Reply #5 on: July 02, 2007, 09:50:37 AM »

bokkibear,

Is the application monitor rule for svchost.exe set as In/Out, or just Out?  It will need to be both.

Also, you might try a reboot, if you haven't already done so. 

If you've done these and it's still blocked, remove that rule from appmon, and reboot.  Any alerts you get for svchost.exe, Allow with Remember, to reset the rule.

LM
Logged

You read my sig block.  That's enough personal interaction for one day. Kewl
bokkibear
Newbie
*
Offline Offline

Posts: 2


« Reply #6 on: July 02, 2007, 06:29:55 PM »

Thanks for replying. I think I've got it to work OK now, probably thanks to the reboot.
Logged
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6254



« Reply #7 on: July 03, 2007, 08:56:29 AM »

Thanks for replying. I think I've got it to work OK now, probably thanks to the reboot.
No problem; hopefully the reboot did the trick.  If not, just let us know...

LM
Logged

You read my sig block.  That's enough personal interaction for one day. Kewl
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.039 seconds with 17 queries.
Powered by SMF 1.1.10 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com