Here is another BASIC outbound protection filtering test for testing firewalling functionality. It tests data transfer over ICMP and a firewall’s reaction to it. Any average firewall should pass these basic ones though there are still many which cant.
Just want to add one thing. Disabling all ICMP-traffic with IPSec will make you pass the test.
With CFP you get Error: icmpEcho Status=11010, but with IPSec, you get Error: icmpEcho Status=11003.
What’s the difference between 11010 and 11003?
same good results here: first alert from Def+, I allow it, and then an alert from the firewall itself. Also in my case when I disable CFP, the router firewall doesn’t pass the test.
By the way it’s not the first time I notice that: when I allow or block something from Def+ or the firewall without checking the remember box, things are being remembered for the Windows Session. Like for that test, I didn’t check remember and the ICMP traffic from it keeps being blocked with no alert, starting with the second test.
hey, if I can pass this test with v3 installed in Basic (ie, no D+) by blocking the executable trying to connect to the internet, how is there no outbound protection?
same here, as i said in my post above, I allowed the process with Def+, and still got an alert from the firewall. Good news for those guys down there at Scott’s newsletter! :Beer
That “so called recommended firewall” was failing this basic test in its most advanced mode. You can test yourself if they havent fixed yet. And people still compare it with CFP 3…
The reason many firewall have poor outbound protection for ICMP is that is rarely used to leak data.
Comodo should make a leaktest that sends data (a short string written by the user) using pings (e.g. using 16 different sizes of ping, each one representing 4 bits) to a comodo server with software able to decode the pings and show the strings in a website.
Never mind leaking data, there are various DDoS Attacks Tools that use ICMP protocol. It is not just leaking the data. A User’s computer can be a zomby and his firewall may not be detecting this at all… Another example: http://ca.com/us/securityadvisor/pest/pest.aspx?id=2776
I dont think most firewalls would fail this test. At least the decent ones… It is as basic as grc.com leaktest…