Author Topic: Firewall blocking system files  (Read 590 times)

Offline shmu26

  • Comodo's Hero
  • *****
  • Posts: 234
Firewall blocking system files
« on: November 03, 2018, 11:34:38 AM »
System info:
Windows 10 pro x64 1809
CFW 11.0.0.6728 proactive config
Windows Defender default settings

I am getting firewall blocks from:
Dashost
Cortana
System
sometimes other processes

Windows firewall is disabled.
Nothing special or unusual was running on the system at the time of the blocks.
« Last Edit: November 03, 2018, 11:37:25 AM by shmu26 »

Offline futuretech

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 3943
Re: Firewall blocking system files
« Reply #1 on: November 05, 2018, 10:40:51 AM »
Because you have application rules for those applications which is set to block certain connections.

Offline shmu26

  • Comodo's Hero
  • *****
  • Posts: 234
Re: Firewall blocking system files
« Reply #2 on: November 05, 2018, 10:51:35 AM »
But I have only the default application rules.

Offline futuretech

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 3943
Re: Firewall blocking system files
« Reply #3 on: November 05, 2018, 12:03:04 PM »
Then global rules or you have do not show alerts block requests and it was automatically blocked when an inbound connection was made. Without seeing the other blocked events for the other applications and how you have your global rules set up, it is hard to figure out why the firewall is blocking connections. But it most likely is a configuration that is causing these blocks.

Offline shmu26

  • Comodo's Hero
  • *****
  • Posts: 234
Re: Firewall blocking system files
« Reply #4 on: November 05, 2018, 12:30:10 PM »
There are no custom rules for applications, except for a few applications that I added to the trusted list, but they don't have application rules.
The global rules are all default, and I don't get any blocks other than these occasional, quirky network blocks.
The only thing I did to tweak the config was to turn on embedded code detection for all processes on the default list. I also disabled website filtering.
I saw this behavior only on win10 1809.
I tried CFW 10 and CFW 11, same result.

Offline shmu26

  • Comodo's Hero
  • *****
  • Posts: 234
Re: Firewall blocking system files
« Reply #5 on: November 05, 2018, 12:32:51 PM »
In autocontainment, I set unknown processes to run limited, instead of the default setting of partially limited. But I don't think that should affect processes running outside of containment.
What else did I tweak? Let me think... I set firewall to not show alerts, and to block. Maybe that's the problem?

Offline futuretech

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 3943
Re: Firewall blocking system files
« Reply #6 on: November 05, 2018, 03:43:38 PM »
In autocontainment, I set unknown processes to run limited, instead of the default setting of partially limited. But I don't think that should affect processes running outside of containment.
What else did I tweak? Let me think... I set firewall to not show alerts, and to block. Maybe that's the problem?
Fully virtualized is the default, PL hasn't been the default since version 7. Default proactive global firewall rules is set to ask incoming connections, and as I said before if you have do not show popup alerts: block requests enabled, any incoming connection request will automatically be blocked.

Offline shmu26

  • Comodo's Hero
  • *****
  • Posts: 234
Re: Firewall blocking system files
« Reply #7 on: November 06, 2018, 11:50:31 PM »
FYI it seems the win10 1809 bug that I am reporting in this thread only affects Proactive config, not Firewall config.
I can't say conclusively because I didn't run Firewall config long enough, but that's the way it looks :)

Offline futuretech

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 3943
Re: Firewall blocking system files
« Reply #8 on: November 07, 2018, 03:03:11 PM »
It is not a bug if it is blocking inbound connections due to a config change of automatically blocking requests without showing an alert. The default global rules for the proactive and firewall configuration is set to ask for incoming connections. If you change the global rules by running the stealth ports task and select block incoming connections, you won't see blocked events because it will silently block the connections and not log the block.

 

Free Endpoint Protection
Seo4Smf 2.0 © SmfMod.Com Smf Destek