I’m currently running CIS (Firewall and Defense) on my Windows 7 64bit PC.
CFP version is 5.0.162636.1135

On the Summary tab, I’ve got (right now):

  • “Firewall blocked 976 intrusion(s) so far”
  • “Defense+ blocked 8 intrusion(s) so far”

Clicking on either number link, I get a completely empty “Firewall Events” / “Defense+ Events” window respectively.


The bug/issue

  1. What you did:
    Switched Firewall and Defense+ to Training Mode for some time.

  2. What actually happened or you actually saw:
    After a while, I got a number of several blocked intrusions.

  3. What you expected to happen or see:
    Not show them being blocked if they are not since I am in training mode

  4. How you tried to fix it & what happened:
    Not a fix in itself, but my intuition told me to press “more” to maybe see more info (in the detailed event log system), but it was empty as well.

  5. Whether you can make the problem happen again, and if so exact steps to make it happen:
    Yes. Switch to training mode and wait till the Firewall or Defense+ blocks some “intrusions”.

  6. Any other information (eg your guess regarding the cause, with reasons):
    The issue is somewhat logical. It shouldn’t log events in training mode (by design) but then again, one shouldn’t see an amount of blocked intrusions/events.

Files appended. (Please zip unless screenshots).
1./2. Screenshots illustrating the bug:

Your set-up

  1. CIS version, AV database version & configuration used:

  2. a) Have you imported a config from a previous version of CIS:

  3. Have you made any other major changes to the default config? (eg ticked ‘block all unknown requests’, other egs here.):

  4. Defense+, Sandbox, Firewall & AV security levels:
    D+=Training , Sandbox=Disabled , Firewall=Training , AV=(different vendor)

  5. OS version, service pack, number of bits, UAC setting, & account type:
    Win7 64bit Ultimate, UAC is OFF, Account is Administrator

  6. Other security and utility software installed:
    Avast 4 on-demand.

  7. Virtual machine used (Please do NOT use Virtual box):
    n/a: Test case ran on native system.

Hello Dennis,

I use Training Mode whenever I’m installing a lot of stuff. Going to give that link a look.


