The bug/issue
-
What you did:
Created a rule with folowing settings:
Action: Allow
Protoco:l TCP or UDP
Direction: In/Out
Source address: Type:Host name with host name registerd at dyndns
Destination Address: Any Address
Source port: Any
Destination port: 3389 -
What actually happened or you actually saw:
The rule worked until the ip-address the host name resolves to changed. The host name still works for other applications. -
What you expected to happen or see:
I expected the rule to resolve the ip-address behind the host name and use the current ip-address when evaluating the rule. -
Have you tried to fix it & what happened:
Yes. What happend was that I discoverd that the rule do not use the current ip-address when evluating. It seams to use the ip-address that was assigned to the host name when the rule was created. -
If its an application compatibility problem have you tried the application fixes here?:
Na. -
Details & exact version of any application (execpt CIS) involved with download link:
Na. -
Whether you can make the problem happen again, and if so exact steps to make it happen:
Steps to recreate:
1 Create rule that use host name.
2 Test rule. Evaluated to Allowed
3 Change the ip-address that the name resolves to.
4 Test rule. Evaluated to Blocked -
Any other information (eg your guess regarding the cause, with reasons):
By testing and updating/re-save the rule while watching the changes of the ip-address behind the host name. I have come to the conclusion that the Host name option works like entering a static ip-address.
The ip-address behind the Host name seams to be resolved and cached/stored when the rule is created and not updated after the save.
As long as the Host name resolves to the same ip-address as when the rule was saved the rule works as expected. When the ip-address change the rule stops working directly afterwards.
Files appended. (Please zip unless screenshots).
-
Screenshots illustrating the bug:
Na -
Screenshots of related CIS event logs and the Defense+ Active Processes List:
Na -
A CIS config report or file.
Do not know where to find. Please advise. -
Crash or freeze dump file:
Na -
Screenshot of More~About page. Can be used instead of typed product and AV database version.
Attached
Your set-up
-
CIS version, AV database version & configuration used:
COMODO Firewall 5.5.195786.1383 -
a) Have you updated (without uninstall) from CIS 3 or 4:
No -
a) Have you imported a config from a previous version of CIS:
No -
Have you made any other major changes to the default config? (eg ticked ‘block all unknown requests’, other egs here.):
No -
Defense+, Sandbox, Firewall & AV security levels: D+= Disableld , Sandbox= Disabled, Firewall = Safe Mode, AV =
-
OS version, service pack, number of bits, UAC setting, & account type:
Windows XP Sp3, 32, Na, Administrator -
Other security and utility software installed:
Avast anti virus -
Virtual machine used (Please do NOT use Virtual box):
None