Comodo Firewall wishlist v4

Because all inbound connections are blocked by default, I would like to see an option that would alert the user that an inbound connection is being made. Are there reasons why the Network Monitor does not prompt (unlike Application Monitor) for inbound connections?

:slight_smile:

My request would be to make it more informative. By that I mean, the most frustrating experience when it comes to firewalls has been ā€œnot knowingā€ what applications/services connecting and most of all I don’t know if I should allow or deny all these alerts about all the ā€œapplication behavior analysisā€ protections. I just don’t have enough expertise to know which dll or parent programs for example is safe to allow and which ones is bad. I am more then willing to read and learn, so maybe provide link within the alert menu to comodo site where it gives description of that file/service/dll/process and etc. So instead of just pressing allow or deny like right now when we’re not 100% sure what we’re doing, we will be educated about what we’re doing.

if i let the firewall allert me for port IP application (i think the maximum alert level)
it display a IP in the alert… this should be as a link to a good WhoIs site wich can give more information about the specific IP something like here http://www.ip-plus.net/tools/whois_set.en.html
also maybe the same with ports like here http://www.auditmypc.com/freescan/portsearch.asp

  1. I would like to do more specific zones i.e.
    #Zone A
    #…192.168.0.1-192.168.0.10, 192.168.0.20, 192.168.0.30, 192.168.0.40-192.168.0.50

  2. Maybe Applicationmonitor can de done with a treeView for each Application

  3. there should be a usermode and a passwordsaved adminmode, and it should be possible to block users fom setting static rules

  4. sometimes if i block something nonStatic i have to restart the PC to get it unblocked again, this should be refreshable without rebooting, something licke clear-cache

  5. maybe its possible to definie optional some settings in alert-popup, things licke zone or anyPort or allowAllForApp or maybe like in some other firewals ā€œact as a serverā€ whatever it means" :SMLR

greatings to all

I would like to see all of the Network Monitor default rules have the ā€œCreate an alert if this rule is firedā€ checked when the firewall is installed. This would give log entries for troubleshooting. purposes.

jasper

Hi…
First time using this firewall… Seems fine to me… (:CLP)
Some on the most important things to me are the features:

  1. Ads / popblocker / spyware filter. So it blocks any ad on the webpages… I will recommend this feature very much…
  2. Using as low memory and processor as possibly
  3. ā€œTranslated to danishā€ :stuck_out_tongue:
  4. Showing transfer rate of downloading with etc. possiblilly bandwith control…

Then ask LeStrata to hurry up with the translation :wink:

https://forums.comodo.com/index.php/topic,3271.0.html

Here I am with another suggestion, selfcreated groups for Application Control Rules, so under one ony app Path item all the sub parent apps could appear.

Hope it helps.

I am not sure if this is worded differently on your list or not, but I put it on here: I like the ā€œinternet lockā€ like ZA has. It would be a timer that blocks all after a designated period of inactivity. I suppose it would be nice if rules could be added to allow certain programs inbound/outbound connections for updates that run overnight. An internet lock feature would be a nice security addition, especially for those who have computers that are always connected to the internet.

Thanks!

hi

i would like to generate groups of definied applications and control theyr default rules with templates
i.e.

Title: ApplicationSet_001
Description: Normal browsing of internet.
Selected aplications:
----*Firefox.exe
----C:\AppDir\InternetExplorer.exe
----C\AppDir*-Browser.exe
----…
----…
Selected rules:
----Browsing rule 001
----Browsing rule 002
----…
----…

Title:Browsing rule 001
any TCP Out Port 80

Title:Browsing rule 002
any TCP Out Port 443

Something like windows-group-policie-editor for comodo firewall. :smiley:

##########
EDIT:
Pass though lines in a list with arrow up and down keys on keyboard

+1

also i would like to add to the wishlist:

SPI for ICMP packets.

Hi, team!

I have not seen this feature in wishlist, but it would be very nice - allow to edit rule for new application before apply it.

For example, if I see popuped question, that application ā€œABCā€ initialize outside connection to 10.1.1.1/UDP:53, I want to edit it right there, to allow any IP address/UDP:53. In current version I have to go to config window, find rule and edit it…

Welcome to the forum.

This have been suggested before (if I don’t missunderstand your suggestion completly :slight_smile: )

GUI improvements
4. Ability to create advanced rules straight from: pop-up notifications, activity lists, maybe even logs.

1. A change in way the rules are stored:

  • Currently in Registry, this leads to increased Reg Size and slows down entire computer.
  • Propose to store in a file, preferable text like CyberArmor, in a table format (e.g., comma delimited).

2. A change in way the log file is stored:

  • Currently in either binary or unicode(?) format. (Displays a lot of square boxes with the text.)
  • Propose to store in a file, preferable text, in a table format (e.g., comma delimited).

3. Log file should include DNS Name of IP Addresses.
IP assignments may change, so Name time of connection is nice.

WHY?

  1. These two suggestions will allow easy manipulation of the rules in a text editor/spreadsheet/database, etc.
  2. Also, #2 allows easily mining the logs to identify new rules, etc.
  3. My default install is to block everything and only allow as needed. This leads to a huge number of Parent/Application/IP/Port rules. An easy way to analyze the logs is essential.
  4. Easy backup - simple XCOPY in a batch file.

Other alternative ways to achieve the same results are also fine.

ICMP should be a protocol option for application rules

Although the latest betas have registry protection for the Comodo specific registry keys, you can still readily delete the registry key that starts the user interface. This key should be added to the protection list.

Please see

https://forums.comodo.com/index.php/topic,4728.msg35916.html#msg35916

Cheers,
Ewen :slight_smile:

This has probably been suggested b4 but i’m gonna reitorate - CPF needs some way to inform the user of what apps are whitelisted so that they don’t think CPF isn’t working when e.g. Ad-Aware gains access to the internet and CPF doesn’t display any warnings.

Is there a webpage with a list of all the trusted apps?

I would like to know this too!

My top 5: [and another more unlikely 1]

  1. Combined rules:
  • sets of rules for each application instead of numerous rules for the same application
  • freestyle combination of ports, protocols, directions for IP / range based rules
  1. User-definable zones / groups (lists of hosts, as opposed to ranges).

  2. User-defined rules should ALWAYS take precedence.

  3. All lists (log, monitors) should be sortable by each column. All elements should be selectable for copy/paste

  4. Enabled/disabled checkbox next to each rule.

  5. Traffic rate limiter (per application and/or connection definable in rules or instantly in activity monitor)

No

I thought that might be case. Let me guess, conflict of interest eh? lol - i could go on >_>

The politics of business is only surpassed in comedy by actual politicians >.<