Welcome, Guest. Please login or register.
August 21, 2008, 09:42:30 AM

Login with username, password and session length

184898 Posts
21467 Topics
52061 Members

Latest Member: gafanhoto-san

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Help for v3
| | | |-+  Global Rules not being applied?
« previous next »
Pages: [1] Go Down Print
Author Topic: Global Rules not being applied?  (Read 213 times)
heffalump
Newbie
*
Offline Offline

Posts: 6


« on: December 15, 2007, 10:07:16 AM »

I'm very new to Comodo and having some trouble with Global Rules. I added a Global Rule for DNS lookup, essentially allowing out UDP port 53 to my DNS server. But I still get application popup from Comodo for every application wanting to do a DNS lookup!

I have Firewall set to Custom Policy, D+ to Clean PC

I'm also using Firewall Alert Settings to High so I can control ports apps use.

For some reason the Global Rule for DNS lookup is being ignored. How can I fix it so it is not ignored but I can still control the other ports an app uses? Thanks!
Logged
sded
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 1825



« Reply #1 on: December 15, 2007, 10:15:27 AM »

You still need to add the "allow DNS out" rule for each of your applications-you should be able to do it in the predefined firewall policies for web browser, email client, ftp client if you are using them, but will need to add it separately for other applications.   The Firewall looks at the application policy before the global policy for outbound connections.
Logged

CFP 3.0.24/368, Vista Ultimate 32x + SP1, Avast! 4.8, Windows Defender.  SAS offline.  Acronis True Image just in case.  Wink
heffalump
Newbie
*
Offline Offline

Posts: 6


« Reply #2 on: December 15, 2007, 10:51:46 AM »

Ah that's an interesting design. I'd have thought Global would come first to avoid just such a thing. Not really much point in having the global DNS rule like I have then if apps still get the popup about it...
Logged
sded
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 1825



« Reply #3 on: December 15, 2007, 11:02:49 AM »

Global is looked at first for incoming connections, last for outgoing connections.  For another view of global rules see http://forums.comodo.com/help_for_v3/an_alternative_to_global_rules-t17138.0.html;msg117356#msg117356 .  I don't use them, for similar reasons. Smiley
Logged

CFP 3.0.24/368, Vista Ultimate 32x + SP1, Avast! 4.8, Windows Defender.  SAS offline.  Acronis True Image just in case.  Wink
MaratR
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 245



« Reply #4 on: December 15, 2007, 01:45:46 PM »

Global rules don't make much sense when you allow something, since you have to do it twice, allowing it again on the application level. But they do make sense when you block something, since it applies to all applications at once.
« Last Edit: December 15, 2007, 01:48:45 PM by MaratR » Logged

XP Pro SP2 / CFP 3.0.18.309 / AntiVir PersonalEdition Classic  ~  Vista SP1 / CFP 3.0.18.309 / AntiVir PersonalEdition Classic
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.147 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com