Firewall policies and ICMP blocking do not work. Makes Comodo next to useless.

I’ve been with Comodo Firewall for several versions, but it has some problems in every version that hasn’t been fixed for a long time now. It’s up to the point that I’m starting to consider switching to another brand entirely due to the lack of trust in Comodo.

Two problems that I’ve encountered that simply make the firewall next to useless are:

  1. Predefined Firewall Policies do not work. When I want to block a host, it simply refuses to do so.
    Example settings that create this problem:

Action: Block (& log event)
Protocol: TCP or UDP
Direction: IN/OUT
Source address: Any
Destination address, Host name: anyurl.com
Source port: any
Destination port: any

It does work if I add the host in “My blocked network zones”, however that doesn’t allow for an ask-popup, while firewall policies do allow for that. Firewall policies seem to be more extensive, but simply do not work.

  1. ICMP blocking doesn’t work. This exposes your pc on the internet and prevents it from being stealthy.
    Example settings that create this problem:

Got to Network Security Policy and create the following global rule:

Action: Block (& log event)
Protocol: ICMP
Direction: IN/OUT
Source address: Any
Destination address: Any
ICMP details, message: Any

Now test it on grc.com. Failed.

Next to these things there are more problems. When you for example accidentally block svhost.exe or system services through a “firewall ask-popup” and those processes keep getting marked as blocked in the event list, then there’s no way to unblock them again. One has to restart windows in order to get a new ask-popup in order to allow them.

Another problem has surfaced in V4. Some things get automatically sandboxed. Now this wouldn’t be a problem if said sandboxing wouldn’t isolate parts of Windows that make it unusable. One such a critical problem is preventing a rightclick in windows. Not being able to rightclick in Windows makes it unusable to the point that you can’t do anything. The only thing that restored rightclicking in Windows is double clicking on the Comodo Firewall icon and disabling sandboxing entirely. And voila, rightclicking is restored again after a reboot. If you turn it on again rightclicking is locked again. There’s no way to prevent the sandboxer from sandboxing that part of Windows that allows right clicking. I know it’s not a setting that I accidentally messed up, it happens after a clean install of Comodo and when no application is sandboxed. However if you look in the event list(more), then you can see that several things are automatically sandboxed and/or isolated. I suspect that it’s one of these automatically sandboxed and/or isolating elements of Windows that prevent the user from right clicking in Windows. No right clicking means no right click menus.

There’s just so much wrong with Comodo Firewall, that I’m not sure what to think about it anymore.

Re. point 1 - I have only seen the host blocking bypassed when either A) the IP address changes (CIS blocks by resolved address, not by name) or B) the host is redirected (sort of the same as a changed IP).

Can you give an example please.

2. ICMP blocking doesn't work. This exposes your pc on the internet and prevents it from being stealthy. Now test it on grc.com. Failed.

Are you behind a router? If so, the grc.com test is receiving ICMP repies from your router, not from the firewall.

Next to these things there are more problems. When you for example accidentally block Windows svhost.exe or system services through a "firewall ask-popup" and those processes keep getting marked as blocked in the events lists, then there's no way to unblock them again. One has to restart windows in order to get a new ask-popup in order to allow them.

It is doing exactly what you accidentally told it to do. The block action is applied on a per session basis.

Ewen :slight_smile:

Regarding the Firewall Policies. Try to add a policy based on the settings I posted and simply use any url for the host name. Apply the policy and then load that url in your browser. In my browser it’ll then load, regardless of the used url.

Regarding ICMP. My modem has a built-in router. I suspected that could be the issue. My applogies for blaming Comodo for that.

Regarding the per session blocking. Well I guess I can live with that, however the rebooting is a minor nuisance when there’s work to be done.

I’m still wondering about the sandboxer preventing right-clicking though.