I have always had a little trouble undertanding the utility of global rules, and found it confusing to do things like end with a block all or block in, then put all of the exceptions in front of it as well as some in the application rules. Probably prejudices left over from using Kerio, Sygate, Jetico, Netveda, … in the past (I never got around to using any of the $ ones), but having a dual tier rule system was counter intuitive.
So I eliminated all of the global rules, put the ICMP rules under Windows Operating System, verified I could use ping/tracert, and ended the application rules with a block all and log. For applications requiring inbound connections, I only put them in the application ruleset now. The effect of the blockall placement is to require a little more maintenance. When I add a new program that requires the network, I need to remember to move the blockall and log so CFP3 will generate popups and an initial ruleset. I then edit the ruleset as required, and put the Block All and Log back. If I forget, the program gets blocked. Then I check the log to see what it wanted, remove the block all and repeat. I actually find it more secure, since otherwise I get a popup, and answer OK without really understanding what the program will do.
This does not, however, have any impact on some other strange things I have noticed. DU meter, for example, has no application rules, since it’s not a network program. It will therefore block when I try to do an automatic update, unless I build a ruleset for it. But it happily lets me go to the DU meter website anyway-presumably because it can go to the ashwebsv http loopback proxy without Comodo noticing it?
So Comodo has provided what appears to be another viable alternative for rulemaking. But I have not checked out all cases, so wondered if others had investigated this, or would have problems doing it this way, or would just find it more confusing and difficult? Or are there reasons it is just less secure to do it this way? Thanks; Ed. :THNK
[attachment deleted by admin]