new user web access problem [Resolved]

Hi .
I have just changed over to Comodo firewall pro after installing it I seem to have a problem, I cannot access the net unless I have the Security level set to “allow all”, and this tells me that the security level is bad. When set to custom I am told that the security level is excellent but I cannot get site access to anything. I get message “unable to load page” Firefox is unable to connect to …
what am I doing wrong

Hi duckfeet
Have you blocked anything.
Look under activity- logs for block entries.
Look under App Monitor for
svchost or your browser
If either of these are blocked then remove the rule. Restart the firewall or even better a system restart.

Have you made any changes to the default network monitor rules?

Sullo

thanks for your prompt reply.
No I have not blocked anything ,& I have checked out all your suggestions,
still same problem.
regards

duckfeet,

A couple things to do:

Reboot. See if the problem persists. If yes, then:

Go to Activity/Logs. Right-click and select “Clear all Logs.”

Try to browse. When it fails, go back to Activity/Logs.

Right-click and select “Export to HTML.” Save and reopen the file.

Highlight the entries and Copy. Then Paste into your next post here. You may mask out your personal IP address using “x” for privacy (this will be the IP address matching what shows in the lower right corner of your posts here).

LM

PS: If Allow All makes it work, you have a problem with some rules. Chances are, you’ve temporarily blocked something (thus the reboot).

Little mac.
Many thanks, problem solved when activity logs were cleared
regards
brian… uk

No problem, Brian. I’ll go ahead and mark the topic resolved, and close it. If you find you need it reopened, just PM a Moderator (please include a link) and we’ll be glad to do so.

LM

Okay, let’s talk about your “new” problem… You say it’s returned; is it just the same as before? How long did it work?

Give as many details as you can think about your scenario.

LM

Hi.
As before I cannot connect to any website unless I set my security level to “Allow” this indicates that my security strength is bad, If I move the slider to custom the security level is indicated as excellent and I am able to connect to any site. Your first solution worked fine for about 2 day’s then it reverted back, I then followed you instructions as befor clearing the activity logs but this time it made no difference.
regards.
PS
I use Avast antivirus

Okay, good. (Not good, for you, but good, for our needs at this point). Please do this:

Go to Activity/Logs. Right-click and select “Export to HTML.”

Save the file, then reopen it. Highlight the entries there, and Copy them. Then Paste into your next post here.

You can then mask out/edit your personal/external IP address for privacy, if it shows in the logs. This will be the same IP address as shows in the lower right corner of your posts here.

This will allow us to see what’s being blocked, so we can address it and get it fixed.

LM

Logs as requested
Date/Time :2007-04-26 19:23:26
Severity :Medium
Reporter :Network Monitor
Description: Inbound Policy Violation (Access Denied, IP = xxx.179.212.149, Port = nbsess(139))
Protocol: TCP Incoming
Source: xxx.179.212.149:4243
Destination: xxx.179.236.192:nbsess(139)
TCP Flags: SYN
Reason: Network Control Rule ID = 5

Date/Time :2007-04-26 19:23:10
Severity :Medium
Reporter :Application Monitor
Description: Application Access Denied (firefox.exe:xxx.241.163.201: :dns(53))
Application: C:\Program Files\Mozilla Firefox\firefox.exe
Parent: C:\WINNT\explorer.exe
Protocol: UDP Out
Destination: xxx.241.163.201::dns(53)

Date/Time :2007-04-26 19:23:06
Severity :Medium
Reporter :Application Monitor
Description: Application Access Denied (firefox.exe:xxx.241.1xxx.200: :dns(53))
Application: C:\Program Files\Mozilla Firefox\firefox.exe
Parent: C:\WINNT\explorer.exe
Protocol: UDP Out
Destination: xxx.241.1xxx.200::dns(53)

Date/Time :2007-04-26 19:23:02
Severity :Medium
Reporter :Application Monitor
Description: Application Access Denied (firefox.exe:xxx.241.163.201: :dns(53))
Application: C:\Program Files\Mozilla Firefox\firefox.exe
Parent: C:\WINNT\explorer.exe
Protocol: UDP Out
Destination: xxx.241.163.201::dns(53)

Date/Time :2007-04-26 19:23:01
Severity :Medium
Reporter :Application Monitor
Description: Application Access Denied (firefox.exe:xxx.241.1xxx.200: :dns(53))
Application: C:\Program Files\Mozilla Firefox\firefox.exe
Parent: C:\WINNT\explorer.exe
Protocol: UDP Out
Destination: xxx.241.1xxx.200::dns(53)

Date/Time :2007-04-26 19:22:53
Severity :Medium
Reporter :Application Monitor
Description: Application Access Denied (firefox.exe:xxx.241.163.201: :dns(53))
Application: C:\Program Files\Mozilla Firefox\firefox.exe
Parent: C:\WINNT\explorer.exe
Protocol: UDP Out
Destination: xxx.241.163.201::dns(53)

Date/Time :2007-04-26 19:22:49
Severity :Medium
Reporter :Application Monitor
Description: Application Access Denied (firefox.exe:xxx.241.1xxx.200: :dns(53))
Application: C:\Program Files\Mozilla Firefox\firefox.exe
Parent: C:\WINNT\explorer.exe
Protocol: UDP Out
Destination: xxx.241.1xxx.200::dns(53)

Date/Time :2007-04-26 19:22:45
Severity :Medium
Reporter :Application Monitor
Description: Application Access Denied (firefox.exe:xxx.241.163.201: :dns(53))
Application: C:\Program Files\Mozilla Firefox\firefox.exe
Parent: C:\WINNT\explorer.exe
Protocol: UDP Out
Destination: xxx.241.163.201::dns(53)

Date/Time :2007-04-26 19:22:44
Severity :Medium
Reporter :Application Monitor
Description: Application Access Denied (firefox.exe:xxx.241.1xxx.200: :dns(53))
Application: C:\Program Files\Mozilla Firefox\firefox.exe
Parent: C:\WINNT\explorer.exe
Protocol: UDP Out
Destination: xxx.241.1xxx.200::dns(53)

Date/Time :2007-04-26 19:22:36
Severity :Medium
Reporter :Application Monitor
Description: Application Access Denied (firefox.exe:xxx.241.1xxx.200: :dns(53))
Application: C:\Program Files\Mozilla Firefox\firefox.exe
Parent: C:\WINNT\explorer.exe
Protocol: UDP Out
Destination: xxx.241.1xxx.200::dns(53)

Date/Time :2007-04-26 19:22:32
Severity :Medium
Reporter :Application Monitor
Description: Application Access Denied (firefox.exe:xxx.241.163.201: :dns(53))
Application: C:\Program Files\Mozilla Firefox\firefox.exe
Parent: C:\WINNT\explorer.exe
Protocol: UDP Out
Destination: xxx.241.163.201::dns(53)

Date/Time :2007-04-26 19:22:31
Severity :Medium
Reporter :Application Monitor
Description: Application Access Denied (firefox.exe:xxx.241.1xxx.200: :dns(53))
Application: C:\Program Files\Mozilla Firefox\firefox.exe
Parent: C:\WINNT\explorer.exe
Protocol: UDP Out
Destination: xxx.241.1xxx.200::dns(53)

End of The Report

Okay, thanks. I edited your post to mask your personal IP address, and cut down the log file a bit (I don’t think we need all of it, as it’s repetitive). Here’s what it looks like has happened.

You have certainly blocked your browser from verifying with your ISP, your IP address (by connecting to the DNS server, Port 53). Your whole problem may clear up by simply doing the following:

Go to your FF rule, and open it to Edit. Add 53 as a Destination Port, then click OK. Make sure UDP is listed as one of the Protocols.

LM

Hi little mac.
You have lost me a little bit with the techno speak.
please explain what you mean and how I do it

“Go to your FF rule, and open it to Edit. Add 53 as a Destination Port, then click OK. Make sure UDP is listed as one of the Protocols”

many thanks
brian.

Brian,

Sorry for any confusion. I’ll try to explain better. Here’s one log entry that is an example of what I’m talking about (with a few details highlighted):

Date/Time :2007-04-26 19:22:32
Severity :Medium
Reporter :Application Monitor
Description: Application Access Denied (firefox.exe:xxx.241.163.201: :dns(53))
Application: C:\Program Files\Mozilla Firefox\firefox.exe
Parent: C:\WINNT\explorer.exe
Protocol: UDP Out
Destination: xxx.241.163.201::dns(53)

This shows the block is occurring because of a rule in the Application Monitor; in this case for Firefox. There are three details to this rule: Destination IP address (which in this case is your Internet Service Provider); Destination Port (which as Port 53, indicates an attempt to verify DNS - which deals with your internet connectivity); Protocol (in this case, UDP, which is the type of traffic used/generated by a DNS request - so this is consistent with the IP address and Port in this alert).

So one of two things have occurred:

  1. You have either actively Blocked this from happening, by Denying a popup alert for Firefox, or
  2. Your Application Monitor rule for Firefox is not configured to allow FF this traffic.

So if you will, please do the following:

Open Application Monitor to full-screen size (so that no text is cut off). Find a rule for Firefox which mentions UDP Outbound, and single-click to highlight that rule. (If you don’t have a UDP Out rule, please highlight what you do have). Capture a screenshot, save it as an image file (.jpg, .png, or .gif) and attach to your post under Additional Options. If you need help with the screenshot (how to do it, etc), here’s a good little explanation: https://forums.comodo.com/index.php/topic,6770.0.html

That will give me a better idea of exactly what needs to change, and how. Then we’ll do that.

LM

Hi LM
screen shot as requested.
regards.
brian

[attachment deleted by admin]

Tnx for the screenshot, Brian. I think that highlighted Block rule for Firefox speaks volumes. In fact, I’m surprised that none of the five viewings by the time of this post have resulted in a comment…

If you are not intending to have that Block rule for Firefox, please just click it to highlight, then select Remove. Then change back to Custom from Allow All and see if your issue remains.

If you do intend to have that Block rule for Firefox, please let me know what exactly you are wanting to do, so we can get it working properly; as it is, that appears to be the source of your issue.

LM

Many thanks LM, problem sorted
regards

No problem, I’m glad it’s working for you. I’ll mark the topic as resolved, and close it. If you should need it reopened, just PM a Moderator (please include a link to this topic) and we’ll be happy to do so.

LM