Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 26, 2009, 02:00:23 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
345309
Posts
38133
Topics
86600
Members
Latest Member:
agona
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archive Boards
Comodo Firewall
Help for v3
v3 not allowing a tracert
« previous
next »
Pages:
1
2
[
3
]
Author
Topic: v3 not allowing a tracert (Read 6546 times)
pudelein
Comodo Loves me
Offline
Posts: 128
Re: v3 not allowing a tracert
«
Reply #30 on:
November 26, 2007, 01:39:10 PM »
Just a quick FWIW on this tracert issue. I am using Windows XPSP2 with CFP 3.0.13.268. I added one small rule at the top of the Global set, namely, "Allow ICMP IN From IP ANY to IP ANY Where ICMP Message is TIME EXCEEDED"; the default rule is used with the Application (tracert). This works. The Application rule allows all outbound items, whatever the protocol or addresses. The Global rule allows the incoming TIME EXCEEDED. More complicated rule sets add nothing additional for this application.
Logged
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: v3 not allowing a tracert
«
Reply #31 on:
November 26, 2007, 06:41:17 PM »
Quote from: pudelein on November 26, 2007, 01:39:10 PM
Just a quick FWIW on this tracert issue. I am using Windows XPSP2 with CFP 3.0.13.268. I added one small rule at the top of the Global set, namely, "Allow ICMP IN From IP ANY to IP ANY Where ICMP Message is TIME EXCEEDED"; the default rule is used with the Application (tracert). This works. The Application rule allows all outbound items, whatever the protocol or addresses. The Global rule allows the incoming TIME EXCEEDED. More complicated rule sets add nothing additional for this application.
Please post a screenshot of you global ruleset. Tracert needs also outbound icmp echo requests.
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: v3 not allowing a tracert
«
Reply #32 on:
November 26, 2007, 06:52:09 PM »
Quote from: tech dunce on November 26, 2007, 12:29:20 PM
well, im back to ver 2.4 set to custom and all is fine. id be the first to admit, i really do need to start investigating the innerworkings of firewalls, and their many functions.but this upgrade left me behind. techdunce
Firewall wise V3 is pretty much like V2. Maybe the only thing that is different is that you have few processes that were hidden by that
Allow traffic for applications certified by comodo
.
So you can configure V3 firewall like you did with V2 (this time you get port sets and predefined policies to make your life easier, plus you can log application traffic too)
I guess the most noisy alerts came from file protection and registry protection. But something can be done.
Anyway if you would like and you are willing to install V3 on another pc I can reply your questions about the differences and how to mimic old V2 functionality (if possible).
So you can later write a FAQ about this topic
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
tech dunce
Comodo Member
Offline
Posts: 40
Re: v3 not allowing a tracert
«
Reply #33 on:
November 26, 2007, 07:29:42 PM »
thanks for that gibran, but if nothing else, this has shown me just how little i know about firewalls. i dont have another pc, but will stick with ver 2.4 for now and brush up my very limited knowledge on the subject.but, genuine thanks, techdunce
Logged
sded
Guest
Re: v3 not allowing a tracert
«
Reply #34 on:
November 26, 2007, 07:41:13 PM »
Microsoft actually has a pretty good overview of firewalls at
http://www.microsoft.com/technet/security/guidance/networksecurity/firewall.mspx
that you might find interesting. Their website, especially technet, seems to have a lot of good reference material on a lot of different topics.
Logged
pudelein
Comodo Loves me
Offline
Posts: 128
Re: v3 not allowing a tracert
«
Reply #35 on:
November 26, 2007, 07:48:40 PM »
[at]Gibran:
For tracert, the application rule provides the outbound requirements. It allows tracert to use any protocol to any external address; that covers the need for ICMP echo requests. The Global rule allows only ICMP 11 (Time exceeded) to enter for tracert or any other application. Posting screenshots just doesn't seem necessary.
Logged
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: v3 not allowing a tracert
«
Reply #36 on:
November 26, 2007, 09:19:20 PM »
Quote from: pudelein on November 26, 2007, 07:48:40 PM
[ at ] Gibran:
For tracert, the application rule provides the outbound requirements. It allows tracert to use any protocol to any external address; that covers the need for ICMP echo requests. The Global rule allows only ICMP 11 (Time exceeded) to enter for tracert or any other application. Posting screenshots just doesn't seem necessary.
I guess so as I can test that myself. That is just to provide enough information to member reading this topic.
Using no global rules you don't even need to allow ICMP Time exceeded so I guess you have at least an inbound IP deny after that rule.
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: v3 not allowing a tracert
«
Reply #37 on:
November 26, 2007, 09:23:15 PM »
Quote from: tech dunce on November 26, 2007, 07:29:42 PM
thanks for that gibran, but if nothing else, this has shown me just how little i know about firewalls. i dont have another pc, but will stick with ver 2.4 for now and brush up my very limited knowledge on the subject.but, genuine thanks, techdunce
Who will write that faq then?
Anyway some members are planning a V3 userguide to cover all the topics any user should know. So you'll update to v3 soon
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
adric
"Start every day with a smile and get it over with."
Global Moderator
Comodo's Hero
Online
Posts: 642
"I am not young enough to know everything. "
Re: v3 not allowing a tracert
«
Reply #38 on:
November 27, 2007, 06:26:31 AM »
Quote from: pudelein on November 26, 2007, 07:48:40 PM
[ at ] Gibran:
For tracert, the application rule provides the outbound requirements. It allows tracert to use any protocol to any external address; that covers the need for ICMP echo requests. The Global rule allows only ICMP 11 (Time exceeded) to enter for tracert or any other application. Posting screenshots just doesn't seem necessary.
I agree and I have verified that adding this single rule gives me a tracert that functions normally. IMHO this rule should be part of the default rules.
Beats me why tracert works out of the box for Vista as reported by some.
Al
«
Last Edit: November 27, 2007, 06:30:30 AM by adric
»
Logged
Luxor
Comodo Loves me
Offline
Posts: 128
In The Doghouse
Re: v3 not allowing a tracert
«
Reply #39 on:
November 27, 2007, 07:53:20 AM »
Quote from: gibran on November 26, 2007, 11:35:13 AM
That's only a revamped old 2.4 type ruleset
Actually ping and tracert are handled by
Allow ICMP Out From From IP Any to IP Any Where ICMP Message Is ECHO REQUEST
Allow ICMP In From From IP Any to IP Any Where ICMP Message Is ECHO REPLY
Allow ICMP In From From IP Any to IP Any Where ICMP Message Is TIME EXCEEDED
But I can only partly agree with you. The fact is we don't have any specifics about different installation-created ruleset.
During installation V3 settings change depending on the answers users chose.
I really cannot tell if another ruleset support ping or tracert but you have to admit that these are Support related tools.
A revamped old 2.4 ruleset it may be but it's not something that had to be created or edited by the user who was using Comodo v2.4. It worked staright out of the box without the need to start playing around with any settings.
IMHO that is the way it should be. I may of course be in the minority to have that view, but have that view I do. No problem with your view on this though as I'm sure you have none with mine.
However can I give you a story of my brother who visited me last night.
I asked him if he had installed the new version of Comodo. He had not done so yet (naturally that earned him a thick ear). I showed him this thread and explained to him that to get tracert to work he
may
have to go through all this just to run this simple task. I won't repeat his answer here as it's a family friendly forum. But needless to say Comodo 3 is not going on his PC.
So that's one potential user lost already. Which is a shame really.
Forgot to add that I got it working by making a rule in Global Rules to allow ICMP in/out as suggested by jasper2408 earlier in the thread.
«
Last Edit: November 27, 2007, 08:44:52 AM by Luxor
»
Logged
We say just what we want because we might be right.
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: v3 not allowing a tracert
«
Reply #40 on:
November 27, 2007, 09:38:57 AM »
Quote from: Luxor on November 27, 2007, 07:53:20 AM
A revamped old 2.4 ruleset it may be but it's not something that had to be created or edited by the user who was using Comodo v2.4. It worked staright out of the box without the need to start playing around with any settings.
IMHO that is the way it should be. I may of course be in the minority to have that view, but have that view I do. No problem with your view on this though as I'm sure you have none with mine.
However can I give you a story of my brother who visited me last night.
I asked him if he had installed the new version of Comodo. He had not done so yet (naturally that earned him a thick ear). I showed him this thread and explained to him that to get tracert to work he
may
have to go through all this just to run this simple task. I won't repeat his answer here as it's a family friendly forum. But needless to say Comodo 3 is not going on his PC.
So that's one potential user lost already. Which is a shame really.
Forgot to add that I got it working by making a rule in Global Rules to allow ICMP in/out as suggested by jasper2408 earlier in the thread.
I cannot really comment on this because I chose the
configure it by yourself
option in the installer.
I'm not against this argument but we need someone to test the installer option in order to profile default rules for each option
I guess one time I tried I got only an ICMP IN echo block but I don remember what option I used.
With that single global rule there would be no issue to get tracert working.
As there is not only one default global ruleset I guess things will get a bit more complicated.
«
Last Edit: November 27, 2007, 12:17:48 PM by gibran
»
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
pudelein
Comodo Loves me
Offline
Posts: 128
Re: v3 not allowing a tracert
«
Reply #41 on:
November 27, 2007, 11:27:16 AM »
[at]Gibran,
You are correct! When I installed V3, I chose to block all unsolicited incoming IP, so that rule had to be preceded by the ICMP 11 rule above it. An alternative, of course, is simply to remove all Global rules altogether! I suppose I could do this well enough, since I am behind a DSL modem/NAT router that also blocks inbound packets. Maybe I don't trust that???
Logged
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: v3 not allowing a tracert
«
Reply #42 on:
November 27, 2007, 12:30:39 PM »
Quote from: pudelein on November 27, 2007, 11:27:16 AM
[ at ] Gibran,
You are correct! When I installed V3, I chose to block all unsolicited incoming IP, so that rule had to be preceded by the ICMP 11 rule above it. An alternative, of course, is simply to remove all Global rules altogether! I suppose I could do this well enough, since I am behind a DSL modem/NAT router that also blocks inbound packets. Maybe I don't trust that???
Actually global rules can handle some traffic that network rules cannot. I usually stick with the old way to configure CFP and I use global rules to define certain criteria all apps must follow. This way for example there would be no way for a trusted app to open an inboud connections on undefined ports without my explicit consent.
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
john q private
Newbie
Offline
Posts: 5
Re: v3 not allowing a tracert
«
Reply #43 on:
November 27, 2007, 09:01:24 PM »
Quote from: john q private on November 23, 2007, 10:12:52 PM
I apologize for the waste of bandwidth but it seems I literally just fixed the problem.
Quote from: jasper2408 on November 23, 2007, 10:17:37 PM
Your post isn't a waste of bandwidth as you posted a solution that someone else might need to get their tracert working.
three pages later.........
Anyways, without going through all the motions yet, do the rules gibran posted allow tracert to function properly while blocking unsolicited pings?
«
Last Edit: November 27, 2007, 09:04:59 PM by john q private
»
Logged
VanguardLH
Comodo Family Member
Offline
Posts: 84
Re: v3 not allowing a tracert
«
Reply #44 on:
November 27, 2007, 11:26:31 PM »
In a virtual machine under VMWare Server (free) where I have (or can revert to) a clean install of Windows XP Pro SP-2 (with all current updates) - and which is about as clean an OS as Comodo should expect any user to have - the tracert did not work. It would still timeout. I added the following global rule:
Allow ICMP In from IP Any to IP Any where ICMP message is TIME EXCEEDED
The app rule that was auto-generated by CFP3 for tracert.exe allowed the outbound connection while the global rule allowed in the inbound UDP packets. This global rule does not allow ICMP for ECHO REQUEST or ECHO Reply (either direction) so the host should be stealthed against pings.
So with about as simple as I could get in defining just one global rule that only allowed unsolicited inbound UDP packets of type 11 (see
http://www.iana.org/assignments/icmp-parameters
) and letting CFP3 handle auto-defining the app rule for the outbound packets, I got tracert working.
This rule should already be included in the set of global rules as an install-time default
-
or the auto-generation of rules for certified programs should include both the app and global rules needed for a program to work.
Yes, I'll stick a link to this post in the wishlist thread but this really isn't a request for enchancement. It is a bug so maybe I should put the link to this thread over there.
Logged
Tags:
Pages:
1
2
[
3
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in -0 seconds with 17 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com