Problems with logging firewall events

I have installed CFP v3.0.14.276 on WinXP Pro SP2 and have removed all presets (trusted apps, firewall rules, etc.), I have set everything up manually, and all is working just about perfectly. I have two questions:

  1. I had an issue with Ghost and it took a long time to figure out. To figure it out, I defined it as a trusted app, and CFP created an allow rule for it. It started working, so I changed the rule to ALLOW AND LOG so that I could see specifically what was going on. The logging function did not log anything. When I removed the rule, Ghost no longer worked. When I put it back, it worked, but still no log entries (tried refresh, all times, etc.). I eventually narrowed it down, but was wondering why the logging function did not work. On a related note, is there any way to have the firewall log everything, without creating a specific rule? It would be very helpful to be able to turn a log on to troubleshoot unknown requests that the firewall is seeing but there are no specific rules for.

  2. I can’t figure out how I am getting a DHCP address. I saw the request to SVCHOST to 255.255.255.255:67 and allowed it, but after that I was expecting to see a request to/from the router on port 67, but it either never came or was automatically allowed somehow. I have an address, I just don’t know how :0

Any insight would be appreciated.

Thanks!

Hi SW,

I have the problems with logging as well and raised a topic “CFP V3 not logging every event” earlier on. May be one of the moderators should merge the two topics as they are related.

Hilmi