Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
November 15, 2009, 06:59:20 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
334793
Posts
37021
Topics
83938
Members
Latest Member:
bob62
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archive Boards
Comodo Firewall
Help for v3
Logging sucks
« previous
next »
Pages:
[
1
]
2
Author
Topic: Logging sucks (Read 3372 times)
VanguardLH
Comodo Family Member
Offline
Posts: 81
Logging sucks
«
on:
May 16, 2008, 05:49:03 PM »
I cannot find a global option to enable/disable firewall logging for ALL policies (predefined and applications). Instead I have to go to every rule for each predefined policy and enable logging. Then I have to go to every application policy and each rule within it to enable logging on that rule. When I decide to turn off logging, I have to repeat this highly laborious process. I have hundreds of application rules. Oh joy, how I love going through each one to enable logging and then again to disable logging, and having to remember to do the same when a new application policy is defined ... NOT! Not having a global on/off option for logging just sucks.
Then after spending a long time enabling logging on every rule in every predefined and application policy, I test the logging and find that many events never get logged or they are not logged reliably. I connect from another host using NetBIOS for file sharing (ports 135, 137-139) and maybe once out of 3 times is there a logged event of the connection. I have Outlook connect to SpamPal, a local anti-spam proxy, which then connects to the POP3 mail host. When Outlook polls for new mail, I see the event for the connection from Outlook to SpamPal (at 127.0.0.1 for localhost) but there is no event recorded for the connection from SpamPal to the POP3 mail host. And, yes, logging is enabled on both the Outlook and SpamPal application policies.
The inability of flipping logging on and off (and for ALL connects) and then missing some connects that were supposed to be logged pretty much obviates the use of logging in Comodo's v3 firewall to know what is going on in my system.
Logged
sded
Guest
Re: Logging sucks
«
Reply #1 on:
May 16, 2008, 05:57:21 PM »
Look at miscellaneous/settings/logging, where you can turn all firewall and d+ logging on and off (separately). The logging is selective in any case (by the program, unfortunately) so there is no way to directly get a really complete log.
Logged
VanguardLH
Comodo Family Member
Offline
Posts: 81
Re: Logging sucks
«
Reply #2 on:
May 17, 2008, 04:42:13 AM »
The misc settings only let me set the size of the logging, and to disable logging (and enable if I deselect the disable). Those were already setup to increase the logfile from 2MB to 10MB and the logging disables were NOT selected (so logging was enabled). Yet I got nothing in the logs. Only a couple of policies had rules within them where they blocked and logged. I wanted logging enabled for ALL policies and ALL rules within them so I could monitor ALL traffic that was going through the firewall. It took something like an hour, or more, of finding out where I had to enable logging on every rule in every policy along with going through all the policies and rules for each to enable logging. Yes, this allows me very fine granularity in what I log but then that level of granularity isn't wanted nor is it easy to configure. That's like wanting to put a couple of teaspons of sugar in your couple but doing so by using a microscope and tweezers to add the sugar one grain at a time. Ease-of-use was obviously not considered by the developers who think workarounds are sufficient.
Logged
Vettetech
Guest
Re: Logging sucks
«
Reply #3 on:
May 17, 2008, 06:14:49 AM »
Why in the world do you want to log everything. That can actually slow your pc down. You can make a global rule to log everything if thats what you want.
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 7454
... and I say to myself, "What a wonderful world"
Re: Logging sucks
«
Reply #4 on:
May 17, 2008, 08:38:45 AM »
Quote from: VanguardLH on May 17, 2008, 04:42:13 AM
Ease-of-use was obviously not considered by the developers who think workarounds are sufficient.
Of course, the devlopment team are concerned with usability. Can you please add this (toggle to allow log all and log none) to the Firewall Wishlist topic? The developers can, and do, monitor that thread and it has been responsible for more than a few refinements to the firewall.
Thanks in advance,
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
VanguardLH
Comodo Family Member
Offline
Posts: 81
Re: Logging sucks
«
Reply #5 on:
May 17, 2008, 02:20:14 PM »
Quote from: Vettetech on May 17, 2008, 06:14:49 AM
Why in the world do you want to log everything. That can actually slow your pc down. You can make a global rule to log everything if thats what you want.
Yes, logging can slow the firewall and the traffic through it. That's why I'd like a global option to immediately and easily enable all logging, and then immediately and easily disable it when I was through trying to see what was happening during the logging period.
Please explain the global rule that I would define that would log all traffic through the firewall. There is already the Outgoing pre-defined policy for Comodo's processes but that doesn't log anything for the applications, just for Comodo itself.
I'm still trying to figure out why Comodo will log the traffic between Outlook and SpamPal, both of which are local, but not from SpamPal to the mail host out on the Internet. When a mail poll occurs, all I see is an event logged for Outlook and nothing recorded for SpamPal.
Logged
VanguardLH
Comodo Family Member
Offline
Posts: 81
Re: Logging sucks
«
Reply #6 on:
May 17, 2008, 02:22:09 PM »
Quote from: panic on May 17, 2008, 08:38:45 AM
Of course, the devlopment team are concerned with usability. Can you please add this (toggle to allow log all and log none) to the Firewall Wishlist topic? The developers can, and do, monitor that thread and it has been responsible for more than a few refinements to the firewall.
I can't find an option that lets me flip a thread from one forum to another. Maybe only a moderator or admin can do that. If so, could you move this thread over to the wishlist forum? Thanks.
Logged
Someone
Guest
Re: Logging sucks
«
Reply #7 on:
May 17, 2008, 02:28:56 PM »
Wishlist is a thread on " Feedback/Comments/Announcements/News"
https://forums.comodo.com/feedbackcommentsannouncementsnews/comodo_firewall_wishlist_v6-t15557.0.html;msg160910#new
Logged
sded
Guest
Re: Logging sucks
«
Reply #8 on:
May 17, 2008, 02:38:45 PM »
You may find this thread
http://forums.comodo.com/empty-t16888.0.html
on logging interesting, since we did a few experiments. Logging allows are a particular problem. Simple things like putting a global rule to log all incoming/outgoing don't work. Most things only log the first time you execute them. Chains of local connections only log the first one, and only once. SPI won't log at all. I agree that logging sucks. There are bug reports on things that are broken, and you might check for other requests in the wishlist-there have been several. The search tool is working again, so you can probably find some other interesting logging threads. If you want to see the effects of your rules you can use Wireshark. If you actually want to see a log of the rules activity, as in several other firewalls, you will need to wait until the wishlist gets around to you. Firewall logging as a debugging aid is not something that Comodo supports.
«
Last Edit: May 17, 2008, 03:03:55 PM by sded
»
Logged
VanguardLH
Comodo Family Member
Offline
Posts: 81
Re: Logging sucks
«
Reply #9 on:
May 17, 2008, 02:58:37 PM »
Quote from: sded on May 17, 2008, 02:38:45 PM
Simple things like putting a global rule to log all incoming/outgoing don't work.
I'm finding that out. I just defined a global rule where I could enable logging. I can't simply disable the rule to eliminate the logging, and leaving a global "allow all" rule doesn't quite seem kosher, to me. Having to delete the rule and recreate it when I want to do logging is a nuisance, but not as much a nuisance as having to visit every policy and rule within each policy to enable logging, and do it all again to disable logging. There is a global option to disable all firewall logging but, after I disable most logging, I still want logging on the blocked applications.
Quote
Most things only log the first time you execute them. Chains of local connections only log the first one, and only once.
Noticed that, too. Can see Outlook connection to SpamPal get logged but not the connection from SpamPal to the mail host.
Quote
If you want to see the effects of your rules you can use Wireshark.
Yeah, that was under consideration, too. While that lets me monitor all network activity, it really doesn't show me how the firewall itself is working as regards to its particular policies.
Quote
If you actually want to see a log of the rules activity, as in several other firewalls, you will need to wait until the wishlist gets around to you. Firewall logging as a debugging aid is not something that Comodo supports.
Alas, logging is how I guage the effectiveness of a firewall. If I cannot monitor that it is working as configured then I have no assurance it is indeed working as configured. The lack of adequate logging is why I've abandoned other firewalls.
Logged
Vettetech
Guest
Re: Logging sucks
«
Reply #10 on:
May 18, 2008, 12:16:13 AM »
Logging to me doesn't prove how a firewall works. Download a leak test and watch Comodo kick in. Download a know trojan or something and you will see Comodo kick in again. Comodo is the bets firewall out there. Logging doesn't prove it. Sorry I guess I don't agree with you cause frankly I never look at my logs. I actually never get any logging cause my hardware firewall blocks all I need.
Logged
Someone
Guest
Re: Logging sucks
«
Reply #11 on:
May 18, 2008, 01:11:12 AM »
Firewall logs are more important (for a firewall) than the latest POC keylogger..
There can be no f doubt about that.
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 7454
... and I say to myself, "What a wonderful world"
Re: Logging sucks
«
Reply #12 on:
May 18, 2008, 05:38:23 AM »
G'day,
And therein lies, I believe, the difference between knowledge and faith.
Logging is important, if only to verify that your current configuration is doing what it is supposed to do.
Confucius said
Quote
I read and I believe.
I see and I understand.
I do and I know.
Admittedly, logs that show nothing can mean either A) nothings happening or B) logging isn't working properly.
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
VanguardLH
Comodo Family Member
Offline
Posts: 81
Re: Logging sucks
«
Reply #13 on:
May 18, 2008, 05:58:59 AM »
Quote from: Vettetech on May 18, 2008, 12:16:13 AM
Logging to me doesn't prove how a firewall works. Download a leak test and watch Comodo kick in. Download a know trojan or something and you will see Comodo kick in again. Comodo is the bets firewall out there. Logging doesn't prove it. Sorry I guess I don't agree with you cause frankly I never look at my logs. I actually never get any logging cause my hardware firewall blocks all I need.
All you need is not what all anyone else chooses to *need*. Look at it the opposite way. You have an application that won't connect. You know that if you disable the firewall then the application can connect. So WHAT in the firewall is causing the problem? You don't know because there is no [decent and reliable] logging. Yeah, you could go hunt around in the global policies and then wander through the hundreds of application policies looking at the multiple rules within each one - but do you really think that is an effective means of troubleshooting the firewall?
You propose that logging is unnecessary when something gets blocked that you want to have blocked. How about when something is blocked that you do NOT want blocked? Are you going to forego troubleshooting the problem and simply disable the firewall during the entire time that the problematic application is loaded and leave yourself exposed that entire time just because you couldn't determine WHAT within the firewall was causing the problem?
Logged
Vettetech
Guest
Re: Logging sucks
«
Reply #14 on:
May 18, 2008, 07:36:02 AM »
Honestly I have never had that problem on any of my of pc's. I know every program on my pc. I never download or install anything I do not know. My hardware firewall stops all inbounds. I use Comodo for the HIPS and program control,
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - Program Lineup
===> Comodo.TV - News and Announcements
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.044 seconds with 18 queries.
Powered by SMF 1.1.10
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com