Forums have been very helpful, but i had to figure one thing out for myself - just wanted to mention it incase anyone else comes across a similar problem.
On a small local network, it is generally advised on this forum to create a zone using ‘tasks’ and then create a network rule to:
allow IP, from IP: local zone, to IP: any
Taking the approach of opening as little as possible, I allowed IP to the local zone only (eg. to 192.168.1.1 to 192.168.1.5).
Whilst it was possible to connect to local machines/printers by IP address, connection by name (ie \computername\sharename ) was not possible. Assuming your machine name is not given out by a DNS server, but the one you entered into windows (as mine is), you also need to allow UDP traffic (only) from the local zone to 192.168.1.255
I’ve attached a picture of the resulting network rule
Ofcourse this could be done more elegently by just making the local zone 192.168.1.1 - 192.168.1.255, or even more so by allowing the local zone to contact ANY IP, but I just mentioned it incase it helps anyone else who likes to open up as little as possible :s
Thanks for great firewall btw - zonealarm pro licence pretty useless now!
Sorry, pepoluan, I don’t have any significant input for you… I’m not the wizkid of file/print-sharing, I’m afraid. I try to stay thoroughly away from implementing that. ;D
However, I know some wizkids are here, so someone should help you out shortly…
If the server has NetBT enabled, it listens on UDP ports 137, 138, and on TCP ports 139, 445. If it has NetBT disabled, it listens on TCP port 445 only.
Still testing it…
But these network rules could be put on top of the others.
modify your network range accordingly…
BLOCK and LOG TCP or UDP IN FROM IP NOT IN RANGE 192.168.0.0 -192.168.255.255
TO IP RANGE 192.168.0.0 -192.168.255.255 WHERE SOURCE PORT IS [ANY] AND DESTINATION PORT IS IN [135,137,138,445]
BLOCK and LOG TCP or UDP OUT FROM IP RANGE 192.168.0.0 -192.168.255.255 TO IP NOT IN RANGE 192.168.0.0 -192.168.255.255 WHERE SOURCE PORT IS IN [135,137,138,445] AND DESTINATION PORT IS [ANY]