Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 21, 2010, 01:59:25 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373364
Posts
41414
Topics
94137
Members
Latest Member:
Mandy
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Discontinued Products
Comodo Firewall
Help for v3
HELP me configure my CFP3
« previous
next »
Pages:
1
...
9
10
[
11
]
12
Author
Topic: HELP me configure my CFP3 (Read 20492 times)
AnotherOne
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 712
Re: HELP me configure my CFP3
«
Reply #150 on:
November 25, 2007, 07:48:08 PM »
I was afraid that program rules would not work - just too ignorant of the details for CFP. Let's hope that Comodo adds port triggering as I requested:
http://www.portforward.com/help/porttriggering.htm
That would allow the listen ports to be open when the software is running without the ports having to be open all the time.
Logged
What do you mean, my shoes are on the wrong feet??? These are the only feet I've got!
gandazilla
♀ beast
Global Moderator
Comodo's Hero
Offline
Posts: 5731
beware! will use ad hominem
Re: HELP me configure my CFP3
«
Reply #151 on:
November 25, 2007, 11:30:35 PM »
Quote from: Soyabeaner on November 25, 2007, 12:03:38 PM
Instead of manually copying me, you want me to upload my config for you so that I you can import them? Trouble with that is that they also include all the other settings in CFP3 including Defense+ that might not be applicable to your pc setup. What do you mean by "what's my TCP port?"?
no no no, i won't copy them all.(can it be done anyway
).
Gibran taught me these : (creating port set)
incoming TCP port ==>
add yours
, what's mine
Logged
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 8240
Re: HELP me configure my CFP3
«
Reply #152 on:
November 25, 2007, 11:44:13 PM »
If you don't know what your TCP port set is, how do you expect I would know
If you mean the Firewall > Common Tasks > My Port Sets, then I didn't touch it. It left them all at the defaults. It doesn't matter to me anyway since I don't use them.
===
Ah....I see now you mean the port to open / create an an allow rule? Firstly, mine is TCP and UDP for it, and secondly, it's for uTorrent. If you don't p2p then don't create such a rule.
«
Last Edit: November 25, 2007, 11:48:47 PM by Soyabeaner
»
Logged
Do u know how I sleep? With 1 eye open. I have 9 kids. U know what they say? "Papa if u don't have candy we are going to kill u in your sleep!" When I finally get to sleep & they find the candy do u think they thank me? No. They say "Papa u stupid. Papa u ugly. Papa u look like a pornstar from 1977"
gandazilla
♀ beast
Global Moderator
Comodo's Hero
Offline
Posts: 5731
beware! will use ad hominem
Re: HELP me configure my CFP3
«
Reply #153 on:
November 26, 2007, 12:17:44 AM »
Quote from: Soyabeaner on November 25, 2007, 11:44:13 PM
If you don't know what your TCP port set is, how do you expect I would know
, i've look for it in wiki, there are lots of port for TCP.how do i know which one of it
Quote from: Soyabeaner on November 25, 2007, 11:44:13 PM
If you don't p2p then don't create such a rule.
never mind then
i've done playing with CFP3 then, i think this global rules : block IP in any/any/any covers them all.
now what should i play
Logged
AnotherOne
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 712
Re: HELP me configure my CFP3
«
Reply #154 on:
November 26, 2007, 12:45:33 AM »
Which TCP port you use depends on the application that you are using TCP for. For HTTP (browser) download managers, you would use port 80 for incoming data and outgoing requests, while for FTP you would use port 20 for incoming data and port 21 for outgoing connection requests. You would also have to include an outgoing DNS lookup (UDP out to/from Any;source port any;target port 53). This would be written as a set of rules for a particular program with the usual Block rule at the end. Other ports apply for email and other applications.
Logged
What do you mean, my shoes are on the wrong feet??? These are the only feet I've got!
Munemasa Katagiri
Comodo Loves me
Offline
Posts: 103
Re: HELP me configure my CFP3
«
Reply #155 on:
November 26, 2007, 11:03:35 AM »
I use Emule and Bittorrent, I didn't create any special rule and they're working well so far.
Logged
girltech
Newbie
Offline
Posts: 6
Re: HELP me configure my CFP3
«
Reply #156 on:
November 26, 2007, 12:12:17 PM »
Quote from: AnotherOne on November 23, 2007, 08:58:39 PM
Hi Girltech - You only need the multicasting rules if you are using internet based media streaming services. See
http://en.wikipedia.org/wiki/IP_Multicast
for a bit of background. You may need it for a home-based multimedia center computer if you are using it in conjunction with your TV or stereo components (not those built into your computer). I don't quite know if this is so - I don't think it applies unless you have multiple computers involved. I installed it because I was getting a blocked request for a connection to 224.0.0.24, which should be harmless and I don't like crippling features that are not a security threat.
The LAN and the LAN and Outgoing rules are rules you would have to write yourself. Basically, you can write the rules for LAN without the multicasting option like this:
Firewall>Advanced>Predefined Firewall Policies>Add>(Use a Custom Policy)>Add
Allow IP in/out from (192.168.0.0-192.168.0.255) to (192.168.0.0-192.168.0.255) where the protocol is Any
Block and Log (Check "Log" box) IP in/out from Any to Any protocol Any
The address range might be different for your network (the router counts as a LAN address, so you have a network). To see the IP address of your computer, click Start>Run>(type Cmd to open a DOS window)>(type ipconfig and press Enter)
The LAN and Outgoing "Predefined Firewall Policy" is the same with the addition of:
Allow TCP or UDP out from IP Any to IP Any; Source Port Any; Destination Port Any
This rule must appear above the Block and Log rule.
Sorry, I don't really know if the rules will transfer to the v.3 final update. I have gotten into the habit of uninstalling Beta releases before updating. I believe that there is an option to export your settings (under the miscellaneous section) but I have not tried it, so I don't know if you can import the rules sucessfully.
Ok I think I understand a little of this. In the LAN settings, the IP address you gave go on the Source tab and the Destination tab? Is the Block and Log a seperate rule to be made? And the 3rd is the LAN and Outgoing rule. Sorry I know I am really new at this. Back when I got V.2 one of the guys posted a picture of their rules and I just copied those but v.3 is so different that I don't know if those rules will work. Thanks for the help.
Logged
AnotherOne
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 712
Re: HELP me configure my CFP3
«
Reply #157 on:
November 26, 2007, 01:18:11 PM »
Hi Girltech - I've made a screenshot of a couple of parts of the process ( I see that I have left the "Log" box checked for the first screen shot - uncheck that except for the Block rule):
«
Last Edit: November 26, 2007, 01:24:58 PM by AnotherOne
»
Logged
What do you mean, my shoes are on the wrong feet??? These are the only feet I've got!
girltech
Newbie
Offline
Posts: 6
Re: HELP me configure my CFP3
«
Reply #158 on:
November 26, 2007, 01:40:51 PM »
I understand the first picture but not the second. How did you get three different things on the LAN & Outgoing page? Under my LAN policy which is like the first pic all it says is Allow and log IP IN/OUT " ". Could you attach a pic of your policy name page, too? Thanks.
«
Last Edit: November 26, 2007, 01:44:37 PM by girltech
»
Logged
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: HELP me configure my CFP3
«
Reply #159 on:
November 26, 2007, 01:56:09 PM »
Quote from: girltech on November 26, 2007, 01:40:51 PM
I understand the first picture but not the second. How did you get three different things on the LAN & Outgoing page? Under my LAN policy which is like the first pic all it says is Allow and log IP IN/OUT " ". Could you attach a pic of your policy name page, too? Thanks.
You need to create a new group in Firewall\advanced\predefined firewall policies (click add)
then you'll see a blank dialog where you can fill in a name for the policy (eg Lan and Outgoing) and add your rules in order to make it like
Then you can associate this new policy to all application you want (in Firewall\advanced\network security policy applications.
«
Last Edit: November 26, 2007, 02:01:11 PM by gibran
»
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: HELP me configure my CFP3
«
Reply #160 on:
November 26, 2007, 02:03:06 PM »
BTW I've not tested this but Allow IP in/out from (192.168.0.0-192.168.0.255) to (192.168.0.0-192.168.0.255) where the protocol is Any
could cut out some legit lan traffic.
I guess it is better to create a Lan Zone with multicast and broadcast IP too
«
Last Edit: November 26, 2007, 02:04:43 PM by gibran
»
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
AnotherOne
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 712
Re: HELP me configure my CFP3
«
Reply #161 on:
November 26, 2007, 02:08:10 PM »
The first screenshot is the first "Add" to the second screenshot. To create the second rule, click "Add" again and write the second part. Do that again to add the Block rule and your policy is done. To create the LAN policy, "Add" a new policy, and then Add the same rule for the LAN zone and just omit the "Allow TCP/UDP out" rule and finish with the Block rule.
Logged
What do you mean, my shoes are on the wrong feet??? These are the only feet I've got!
AnotherOne
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 712
Re: HELP me configure my CFP3
«
Reply #162 on:
November 26, 2007, 02:19:39 PM »
If you need multicasting rules, see the following screenshot for the LAN policy. It uses port sets defined on the "Common Tasks" page of Firewall. Gibran has pointed out that there are LAN braodcasts to 0.0.0.0 and 255.255.255.255 as well as the port ranges listed above. This seems to happen on my system already, possibly because of a Global rule for TCP/UDP out via privileged ports:
Allow and log TCP/UDP out where source IP is any, destination IP any; source port is in Privileged ports (Already provided in the setup); destination port is any
It may be wise to include the two IP extremes above in your LAN rules.
«
Last Edit: November 26, 2007, 03:12:51 PM by AnotherOne
»
Logged
What do you mean, my shoes are on the wrong feet??? These are the only feet I've got!
bamaman66
Comodo Member
Offline
Posts: 42
Re: HELP me configure my CFP3
«
Reply #163 on:
November 26, 2007, 03:23:46 PM »
I have just downloaded the newest version of comodo firewall with the basic firewall. Could someone point me to some instructions for setting it up or is it good to use in the default position? It is very different than V2.
Logged
gandazilla
♀ beast
Global Moderator
Comodo's Hero
Offline
Posts: 5731
beware! will use ad hominem
Re: HELP me configure my CFP3
«
Reply #164 on:
November 26, 2007, 09:15:49 PM »
Quote from: bamaman66 on November 26, 2007, 03:23:46 PM
I have just downloaded the newest version of comodo firewall with the basic firewall. Could someone point me to some instructions for setting it up or is it good to use in the default position? It is very different than V2.
i've passed the "confusion phase" of configuring CFP3
.
if you don't need any specific rule (in other word: you just want to monitor what goes in and what goes out) : create this rule on firewall/advanced/network security policy/GLOBAL RULES :
block & log IP in from IP any from IP any where protocol is any
Logged
Tags:
Pages:
1
...
9
10
[
11
]
12
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.086 seconds with 18 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com