A few (and hopefully simple) questions regarding CIS

Some background info: DSL behind a router running DCHP. Two other computers connected wirelessly. Using file and printer sharing. Installed the latest version of CIS to date. Ran spyware and anti-virus before installing. Firewall set to safe mode, Defense+ set to clean PC mode. Now my questions.

  1. If I answer an alert and select remember my answer, how do I get it to re-prompt me if I want to change my mind, or if I have answered incorrectly by mistake?

  2. After reading a number of posts, I changed system and svchost to outgoing only. I am getting firewall events as shown in the attached image. 192.168.0.1 is my router, 192.168.0.4 is me, and 192.168.0.6 is another computer in the network. If I stealth my ports using the first option and selecting my home network, it changes system back to custom, adds two new rules, Is that okay?

  3. Why is it blocking those requests if they are in my home network?

Thanks in advance,

Dave

[attachment deleted by admin]

Hello Dave;

  1. You Can Edit The Policy By Going To “Firewall > Advance > Network Security Policy” or If It’s Defense+ You may go to “Defense > Advance > Computer Security Policy” And Find The Program (Either Remove It by selecting it then click delete/remove or edit it) then once you are done Remember to click “Apply”
    *If you remove the application from the list and click apply; You’ll Receive Alerts For That Application

  2. Yes, That is ok; It’s adding rules to allow connections from and to your Network

  3. Was this screen shot while the two rules are in place?

Did this help?

Jacob

Jacob,

Thanks for getting back to me. I can’t honestly remember if the rules were in place. I just checked the log again, and am getting one of the same blocks check out the attached image. I’m not sure why though, because 192.168.0.1 is my router, and the other is my machine. Should it allow it since it’s in the trusted zone?

Thanks again,

Dave

[attachment deleted by admin]

Hello Dave;

For Information About svchost.exe
https://forums.comodo.com/empty-t14464.0.html

the Log you are seeing is normal;
If you set your home network as trusted through “Stealth Ports Wizard”; It should disapear

svchost.exe should be also set as out going only. (If you are going to set your home network as trusted i would do this first).

Did this help?

Jacob