BIG BUG: Firewall doens't filter ANY connection to internet!

Hi all,

Comodo has released COMODO Internet Security 4.0.132838.716 RC, please install and test it, if you encounter same problem, please tell me, we will fix these bug based on this version.

The latest released version, please refer to https://forums.comodo.com/beta-corner-cisv4/comodo-internet-security-40132838716-rc-released-t51706.0.html

I did install this version. Same problem.

I will try to reproduce and analyse it in our lab

Hi jarmomak,

Please set firewall security level to Block All Mode, and test if your connection not detected can work ok?

Thanks & Regards,
Rick ■■■■

If I “block all”, comodo correctly blocks all outgoing connections. It is very difficult to test whatever comodo blocks incoming connections too. But if I create a rule that blocks all incoming connections but allows outgoing connections, Comodo is not able to block any incoming connection. pcflank.com firewall test still sees my open and visible ports.

Active Connections -dialog shows no outbound connections through my mobile broadband. Just localhost listening ports.

See My Network Zones capture in attached file. Comodo does not detect my IP correctly. For some reason DHCP is slow to return IP, so one second or so ip address is 169.xx.xxx.xx. That is detected, but not right IP when it finally arrives. There is one problem as far as I can see.

[attachment deleted by admin]

Hi Jarmomak,

Please be careful with this conclusion, do you have a Modem/Router in between your PC and the Internet?
It could very well be that you are scanning your Modem/Router instead of your PC in this situation…

Try to create a rule that logs traffic and cause outgoing traffic with it so see if CIS is able to log this traffic.

There is no router or anything. Just connection to my mobile broadband connection right from my T500 laptop (ericsson mobile broadband modem). Pcflank.com shows the same IP as my computer has.

i did create rule that logs any outgoing connection. I removed all application rules.
No connections were logged. Firewall Events shows only localhost events.

Okay cool, good that have that verified, I had the same issue with my 3G adapter…

i did create rule that logs any outgoing connection. I removed all application rules. No connections were logged. Firewall Events shows only localhost events.
Did you do that on the Global rules, or did you also try an application rule say for example Firefox?

Maybe it’s asked before but do you have ANY other security software installed that could possibly interfere and is windows firewall disabled?

Can you start msinfo32.exe and post the Network, Adapter part that it shows here in a text file?

I do not have any other security software except Avast 5.0 antivirus (which I recently installed). Problem was found before I installed Avast 5.

I did logging rule on the Global Rules.

When I run your tests I have Windows Firewall disabled. Mean while I have to enable it to have some inbound protection.
I did attach output of msinfo32. It is in finnish language, sorry! But I think you can interpret information you want. And learn a new language ;D

Ah well between the lines i can guess, but Finnish is a bit more difficult then Danish which can be read a bit more easy by this Dutch guy :wink:

But then there’s always some Online Translator


Name [00000017] F3507g Mobile Broadband Driver Wireless Adapter Type Product Type F3507g Mobile Broadband Driver Yes, installed PNP-ID USB \ VID_0BDB & PID_1900 & MI_07 \ 3541430249607340_07 Last reset on 25.2.2010 15:36 Index 17 Service name WwanUsbServ The IP address 85.77.x.x IP-subnet 255.255.255.0 IP default gateway 85.77.y.y DHCP Enabled Yes DHCP server 255.255.255.255 DHCP license expires Not available DHCP license from Not Available MAC address 02:80:37: EC: 02:00 Driver c: \ windows \ system32 \ drivers \ wwanusbmp.sys (1.0.0.52, 208.04 KB (213 032 bytes) 9.10.2009 5:15)

I removed your attachment as it contained your external ip… thought it would be better to mask that…

Related bug:

Topic: Firewall doesnt monitor traffic (Win7 64)?

hello,

here I am with the same bug, my posting was moved here by Ronny in the prevous answer.

just for the records…
I made the same test downloading a bif traffic in Firefox but this time not using WLAN but LAN connection through cable. The result was the same: no indication of this in the summary page :-\

Well the summary page isn’t real-time, the “view active connections” screen is though, if it doesn’t show up there then it’s not “seen” by the firewall filter…

yes, this is what I mean, just wanted to give the result that with LAN connection the ussue still exists, not only with W-LAN

the new version 4.0.xxxx.742 doesnt fix the bug with traffic monitor.
Where is the sense for the official release the new version ???

I think they will fix this in an upcoming release of v4.0.x

ok, lets wait

hey guys count me in

search my posts… I am having the very same problems. >:(