advanced learning rules, help pls..

Hi,

Normally i don’t post a question that fast but there are so many threads/posts which makes it almost impossible to find what i am looking for, so i hope, if this has been asked before you won’t get annoyed.
I am using Windows XP Home Edition and before i had Sygate Personal Firewall Pro installed. Because I never really liked it I decided to change to Tiny Personal Firewall 2 because i got that same firewall running on other computers here and it really works excellent. After uinstalling Sygate, rebooting, installing Tiny2 and rebooting again my computer gave me a blue screen. Whatever I did I couldn’t get it installed, which is still weird to me because there are no problems at all with Tiny2 on the other computers.
After looking around on the net I stumbled upon Comodo and as far as I’ve used it till now I can say I like it. There is a learning option in Comodo but that one just let’s you select accept/deny with or without remembering alerts when there are outgoing connects. In Tiny2 when there comes an alert it is possible to set more advanced rules with learning, like you can set to which port/ip it was possible to connect to or get a connection from in and to which ip with programs, services, etc, etc. I’ve been digging into Comodo but I can’t find that option, so now is my question is there an option like this in Comodo to be able to select the way Tiny2 does in ‘advanced learning mode’?
I hope you guys can give me some feedback, thanks in advance…

kind regards,

Walter

(:WAV)

hi,

go in app monitor, highlight and right click options

you might want also read FAQ about comodo layered transaction.

Mike

Welcome to the forums, Walter ~

What version of CFP do you have?

LM

Thank you very much for the welcome LM. I’m happy to be on this forum because it really is filled with many infos about CFP. I’m using version 2.4.18.184 with Windows XP Home Edition.
I’ll check out what meier12 said ( thanks for the reply meier12 ), nevertheless i kinda miss that option with the learning mode in CFP like Tiny Personal Firewall 2 has with it’s learning mode/alert popup.

kind regards,

Walter

Walter,

v2.4 has no learning mode (except for Component Monitor, which is a bit of a different issue). There is a “set & forget” tutorial in this thread: https://forums.comodo.com/index.php/topic,6167.0.html as well as other info like how to tighten your configuration. You may be interested in the explanation of layered security as well.

Unfortunately as well (it’s been requested, I know) you can’t create specialized/custom rules from popups; a lot of users would like that feature.

I don’t think v3 has that functionality either (at least not yet, but it’s not code-complete), but it does have a couple different options for Learning Modes. It’s currently in Beta-testing, and seems to be coming along nicely.

In v2, I am confident you will find you can do everything you do in Tiny (and then some!), just in a different way. You may have to learn how drive the car all over again, but once you get the hang of it, I think you’ll like driving this car… :wink:

LM

Thank you for your (quick) reply and I have to agree with you saying “You may have to learn how drive the car all over again”. It’s still completely new for me and i just have to adjust myself to doing things another way now and figure things out. I will check out the url you gave to me so I can find out more about how things work. I can’t resist to say that it’s a pity that the v3 won’t have the feature I was talking about ( well like you said the code is not done yet, so I still have my hopes up, (:WIN) ). I’d love to install v3 but i still am hesitating to do that because I don’t know how stable it is.

kind regards,

Walter

No problem; just let us know if you have questions.

v3 has been (for me) relatively stable on the current release. However, some folks are still getting bsods, application crashes and have other relatively major issues. My advice is if you’re not sure about beta-testing, then don’t. It will keep things much simpler for you…

LM

The closest thing you got is the alert level. Set a level that you want, and use it always.

Very high will create rules from pop-ups specific to ports, protocol and IPs. High will do the same except for any IP, and so on.

Then you revise the rules created and merge/generalize where necessary.
But you can’t do it like kerio 2.1.5 or Tiny where you can edit the rule straight from pop-up.

hi,

comodo blocks anything INbound of tcp and udp.

if you did understand that, and that apps rule just tell ya might need allow …

and then make new rule in network.

and that a browser eg work with default rulesets is only of its a “certified app list of comodo” …

Mike

PS: anyone knows disable this "certified app list (certified by comodo) feature which seems hidden work or how to edit or or?

Yes it works.