Extra networks (VM, VPN & ?wireless) not detected & silently allowed [V6][M189]

A. THE BUG/ISSUE:

  1. What you did: Installed CIS on production computer
  2. What actually happened or you actually saw: One network was correctly detected, and I said it was a home network, so a zone was created. No further networks were detected or Zones created
  3. What you expected to happen or see: In CIS 5.x VM (2) and VPN (2) networks were detected, possibly wireless adapter as well, and network zone entries were created for each. This is important as for example you may wish to allow a VPN service for comms purposes without giving all VPN members full file sharing access to your computer. (Obviously there are other ways of restricting this, bur CIS does not alert you to the need).
  4. How you tried to fix it & what happened: Have not yet tried
  5. If a software compatibility problem have you tried the compatibility fixes (link in format)? : N/A
  6. Details & exact version of any software (except CIS) involved (with download link unless malware): Comodo Unite 3.0.2.0, Comodo TrustConnect 1.7.3, VMware Workstation downgraded to Player 5.01
  7. Whether you can make the problem happen again, and if so precise steps to make it happen: Yes has happened on each of 3 installs. No special measures are required, I ran the installer uneslected Yahoo and C.DNS, otherwise followed all recommendations, then received network detection notification as above. Wireless Connection, Unite and Trustconnect were running and connected.
  8. Any other information (eg your guess regarding the cause, with reasons): Either CIS is detecting that these connections are likely to be trusted (but if so why are there no zones), or this is a bug.

B. FILES APPENDED. (Please zip unless screenshots).:
0. A diagnostics report file (Click ‘?’ in top right of main GUI) Required for all issues): Appended

  1. Screenshots of the 6.0 Killswitch Process Tab (see Advanced tasks ~ Watch Activity) or 5.x Active Process List. If accessible, required for all issues:: Appended
  2. Screenshots illustrating the bug: Appended
  3. Screenshots of related CIS event logs: Not appended
  4. A CIS config report or file: Not appended
  5. Crash or freeze dump file: Appended
  6. Screenshot of More~About page. Can be used instead of typed product and AV database version: Not appended

C. YOUR SETUP:

  1. CIS version, AV database version & configuration: CIS 6.0 Build 2674, Database version 14718, Internet security
  2. a) Have you updated (without uninstall) from a previous version of CIS: No uninstall then install using normal CIS 6.0 installer
    b) if so, have you tried a clean reinstall (without losing settings - if not please do)?: N/A
  3. a) Have you imported a config from a previous version of CIS: No
    b) if so, have U tried a standard config (without losing settings - if not please do)?: N/A
  4. Have you made any other major changes to the default config? (eg ticked ‘block all unknown requests’, other egs here.): No
  5. Defense+/HIPS, Autosandbox/BBlocker, Firewall & AV security levels: HIPS=off, BB=partially limited, Firewall=safe, AV=Default
  6. OS version, service pack, number of bits, UAC setting, & account type: Win 7 Ultimate, SP1, x64, Uac=off, Admin
  7. Other security and utility software currently installed: Vmware workstation, Logmein, Clipmate, Raser keyboard configurator, Canon Network utility, Bluetooth configurator, Vmware, Filezilla server, WAR-FTP server, Routerstats, Acrobat, Comodo Ivault, FastStone capture
  8. Other security software previously installed at any time since Windows was last installed: None
  9. Virtual machine used (Please do NOT use Virtual box)[color=blue]: None, Installed on production

Link to files on FTP server:

ftp://82.69.43.252/CisReport_v6.0.260739.2674_20121229-144436.zip

Username and password as before. If you have forgotten them please consult the Mod’s Preview Board, Mod’s password sticky.

[attachment deleted by admin]

Just to clarify, are you saying that CIS originally detects the network the laptop is in, but that after that, even if you for example start a VPN, CIS will not alert you to the new network and provide you with options for it?

Strangely enough, I was going to report something similar, I’m just going through some confirmation procedures. In the scenario I’ve been seeing:

  1. CIS 6 installed with one correctly identified Zone/rules (wired home network)
  2. Connect PC to an additional network - Different IP block/Adapter
  3. Alert received for new network and accepted
  4. Check Zones/Rules for new network but it wasn’t created.

Still need some more time to confirm this behaviour.

I don’t even get the second alert strangely.

Today’s IP situation is:

172.20.1.x TrustConnect
5.2.20.x Unite
192.168.169.lowX (Vmware 8 )
usually = 192.168.169.highX (Vmware 1), not connected today, not using NAT on Vmware today
192.168.169.7 (Wireless, probably not detected as in same marks as Home)

Home (detected= 192.168.1.1 255.255.255.0)

IN CIS 5.x I had 3-4 detects I think.

Best wishes

Mouse

In effect my computer has multiple adapters connected at once, so it has multiple IPs. (TrustConnect is different, it is on/off)

So expected behavior I guess is that each of these networks are detected when live, or at least those with different IP masks, so most would be detected at boot time or just after.

If you are happy with the report Chiron could you forward, please?

TA

Best wishes

Mouse

This does sound like a bug.

Thank you very much for your report in standard format, with all information supplied. The care you have taken is much appreciated by Comodo, and will increase the likelihood that this bug can be fixed.

Developers may or may not communicate with you in the forum or by PM/IM, depending on time availability and need. Because you have supplied complete information they may be able to replicate and fix the bug without doing so.

Many thanks again.

Just a quick follow-up to my earlier post. It would seem the additional network detection is very hit and miss.

  1. Install Windows 7 x64
  2. Install CIS v6

After five tests:-

  1. On five occasions the local area network connection was detected and added
  2. On only two occasions a new WiFi adapter/network was detected

Anther test:

  1. In a VMWare VM with bridged network - Install Windows X86
  2. Install CIS v6
  3. Bridged network detected and added
  4. Shutdown and add A NAT adapter to the VM
  5. Reboot
  6. Out of three tests the NAT adapter failed to be detected on one occasion.

Out of interest has the ability to create a new ‘trusted’ network been removed in version 6? I can’t seen to find a way, other than manually, to create the necessary rules.
4.

Can you please check and see if this is fixed with the newest version? Please let us know whether it is fixed or you are still experiencing the problem.

Thank you.

Not fixed in 2813

Best wishes

Mouse

A. THE BUG/ISSUE (Varies from issue to issue)
[ol]- Summary - Give a clear summary in the topic subject, NOT here.

  • Can U reproduce the problem & if so how reliably?: Reproduced 100% of the time on fully patched versions of Windows 8 Pro, Windows 7 Pro/Enterprise regardless of hardware configuration and network location, for example Home and Work LAN’s.
  • If U can, exact steps to reproduce. If not, exactly what U did & what happened: Create your VPN profile. Make a successful connection and verify you can access the remote resources.
  • If not obvious, what U expected to happen: Expect the New Network Detected popup to be displayed upon 1st time successful VPN connection as it appears when connecting to a New Physical Network.
  • If a software compatibility problem have U tried the conflict FAQ?: N/A
  • Any software except CIS/OS involved? If so - name, & exact version: Shrewsoft VPN client version 2.2.1 and OpenVPN 2.3.2
  • Any other information, eg your guess at the cause, how U tried to fix it etc: Cannot guess the root cause.
  • Always attach - Diagnostics file, Watch Activity process list, dump if freeze/crash. (If complex - CIS logs & config, screenshots, video, zipped program - not m’ware) Cannot provide attachments. VPN tunnel appears to work as intended and have not noticed reduced or imparred functionality.
    [/ol]

B. YOUR SETUP (Likely the same for each issue, so you can copy forward)
[ol]- Exact CIS version & configuration: CIS version = 6.1.276867.2813 & Internet Security Configuration Active

  • Modules enabled & level. D+/HIPS, Autosandbox/BBlocker, Firewall, & AV: D+/HIPS disabled (default), BBlocker all tick boxes enabled at “Partially Limited”, Firewall enabled at version defaults, AV enabled at version defaults.
  • Have U made any other changes to the default config? (egs here.): BBlocker has exceptions to my VMWare View Client directory. AV has exceptions to my Games directory. Firewall has additional “Filter IPv6 traffic” setting enabled above the version default.
  • Have U updated (without uninstall) from a CIS 5?: This has been attempted on Windows 7 Pro only.
    [li]if so, have U tried a a clean reinstall - if not please do?: Clean install on Fresh Windows Install has been tested on Windows 7 and Windows 8.
    [/li]- Have U imported a config from a previous version of CIS: Never attempted Import.
    [li]if so, have U tried a standard config - if not please do:
    [/li]- OS version, SP, 32/64 bit, UAC setting, account type, V.Machine used: Windows 8 Pro (version 6.2 build 9200) 64bit, UAC = Windows 8 Default, Account Type = Local Admin, Physical Machine. Windows 7 Pro (version 6.1 build 7601:SP1) 64bit, UAC = Windows 7 Default, Account Type = Local & Domain Admin, Physical Machine.
  • Other security/s’box software a) currently installed b) installed since OS: a= None b= None
    [/ol]

Initial Help requested on thread:
https://forums.comodo.com/firewall-help-cis/vpn-not-detected-problems-with-fw-network-profiles-t92915.0.html

[attachment deleted by admin]

Please run the CIS diagnostics and attach it to this post. Also, attach the Watch Activity Process list to the post?

I cannot forward this bug report to the devs without these attachments. If you have any questions about how to create these please let me know. I’ll be happy to help.

Thank you.

Do you need these created whilst successfully connected to the VPN ?

Yes, that would be best.

Thank you.

Attached to Original Post.

Cheers

Thank you very much for your report in standard format, with all information supplied. The care you have taken is much appreciated by Comodo, and will increase the likelihood that this bug can be fixed.

Developers may or may not communicate with you in the forum or by PM/IM, depending on time availability and need. Because you have supplied complete information they may be able to replicate and fix the bug without doing so.

Many thanks again.

Actually, I just realized that this bug has already been reported, albeit for a slightly different case. Thus, I have merged them together into one report.

Can you please check and see if this is fixed with the newest version (6.2.282872.2847)? Please let us know whether it is fixed or you are still experiencing the problem.

Thank you.

PM sent.

Actually, I just noticed that the devs have flagged this bug as Confirmed and Deferred. This means that they will eventually fix this, but at the moment there are many other bugs which must first be addressed.

I hope you understand and can coexist with this bug until they are able to fix it.

Thank you.

Not fixed in 2847

Can you please check and see if this is fixed with the newest version (6.3.294583.2937)? Please let us know whether it is fixed or you are still experiencing the problem.

Thank you.

PM sent.