Welcome, Guest. Please login or register.
October 10, 2008, 07:41:13 PM

Login with username, password and session length

199084 Posts
22882 Topics
54908 Members

Latest Member: teyminglie

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Help for v2
| | | |-+  Block single IP address
« previous next »
Pages: 1 2 [3] Go Down Print
Author Topic: Block single IP address  (Read 12513 times)
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 1737



« Reply #30 on: July 04, 2006, 07:35:01 AM »

For Blocking someone (even if I don't get it, why you want shuch feature; unless the other party is a leecher), you should use:
Security -> Network Monitor - > add rule ( I'm writing this so others can understand where to find this options)
Action = Block
Protocol = IP
Direction = Out
Source IP = Your IP (pay attention if you are behind a router to use your computer internal IP and not the Internet IP of the router); I'm not sure but maybe you can also leave it blank [ -> I mean Any (coment added on May 20 2006)]
Remote IP = The IP of the nasty user Tongue
IP Protocol = Any

Then move the rule up (over the default rule "Allow /IP Out/ Any/ Any")

Hope it Helped Cheesy

Direction field must be "IN" and SOURCE IP and REMOTE IP must be exchanged. Please have a look at the following message

http://forums.comodo.com/index.php/topic,193.msg1458.html#msg1458 to solve this problem.

Egemen
Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5469


... and I say to myself, "What a wonderful world"


« Reply #31 on: July 04, 2006, 11:22:15 AM »

Okay, to play a devil's lawyer (just for my own understanding):

A: some server (e.g. local) that sends message to me regulary informing me on updates

B: my computer

(1) A ---SYN--> B  ("hi there, I want to connect")

At this stage packet (1) is unsolicitated, I did not ask for it. But, I accept it (e.g. having some network monitor rules that does this).

(2) B ---SYN/ACK ---> A ("okay, you've got my ear")

(3) A---ACK--->B ("good let's talk")

now connection is established

(4) A---(data)-->B ("I have some updates for you, here they are")

Okay, now at this stage, I haven't really asked for (data) but it gets in. Is(4) solicitated or unsolicitated package?

Zoran

(4) is solicited because (2) said "OK, come on in". That and the fact that you had an explicit rule that allowed the initial SYN in.

Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
Wisanggeni
Comodo's Hero
*****
Offline Offline

Posts: 592



« Reply #32 on: July 04, 2006, 02:12:38 PM »

A question, Egemen.
How do I implemented this with my non-direct connection (Sock 5) ?

*. I use Putty to tunnel my way "in/out" the Net
*. I've tried using IP instead of TCP/UDP... still no luck

...am I "special" case here, or do CPF Dev's forgot about this type of connection?
Logged
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 1737



« Reply #33 on: July 05, 2006, 06:29:13 AM »

A question, Egemen.
How do I implemented this with my non-direct connection (Sock 5) ?

*. I use Putty to tunnel my way "in/out" the Net
*. I've tried using IP instead of TCP/UDP... still no luck

...am I "special" case here, or do CPF Dev's forgot about this type of connection?

If attackers' IP addresses remain the same, i.e. if your proxy does not change the remote IP addresses no difference.
Logged
Wisanggeni
Comodo's Hero
*****
Offline Offline

Posts: 592



« Reply #34 on: July 05, 2006, 05:29:10 PM »

Ah, I see...
Thanks, Egemen.
Logged
zorank
Comodo Member
**
Offline Offline

Posts: 39



« Reply #35 on: July 06, 2006, 10:47:54 PM »

(4) is solicited because (2) said "OK, come on in". That and the fact that you had an explicit rule that allowed the initial SYN in.

Ewen :-)


Hmmm... I see now. Happily jumping around filled with joy of life and a little extra understanding.

Many thanks!!!

Zoran
Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5469


... and I say to myself, "What a wonderful world"


« Reply #36 on: July 07, 2006, 12:42:58 AM »

Hmmm... I see now. Happily jumping around filled with joy of life and a little extra understanding.

Many thanks!!!

Zoran

LOL. Doesn't take much to float your boat, Zoran.  Wink
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
Tags:
Pages: 1 2 [3] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.097 seconds with 20 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com