View Full Version : Newbie Look 'n Stop question
TonyKlein
June 27th, 2002, 03:46 AM
I've just replaced Norton Internet Security by Look 'n Stop and AdShield, and I must say I'm impressed by both.
They replace NIS quite nicely.
I'm just a newbie as regards configuring firewall rules, so here's a question.
When I run Neotrace, two things happen:
I found I need to allow my computer "to receive
and to send packets of type 11 on ICMP
protocol."
And the default "Block all other UDP packets" rule (destination Nebios-ns) is invoked as well.
Is it safe to allow the first one without modifying the rule any further?
Or does anyone have any other recommendations.
BTW I have seen this article (http://itsec.commontology.de/firewalls/lns/lns-rules.html[/url), and it certainly is quite useful.
Now if only I knew what to do with it... ::) (and I'm only half kidding...)
Paul Wilders
June 27th, 2002, 08:07 AM
Tony,
Frederic (the LnS author) has his own dedicated forum over on Becky's:
http://66.119.216.59/cgi-bin/ubb-cgi/ultimatebb.cgi?ubb=forum&f=35&DaysPrune=20
He'll be glad to answer all questions in regard to LnS.
In case you drop over there: make sure to give all my best regards!
regards.
paul
root
June 27th, 2002, 10:05 AM
When it comes to ICMP, I have always allowed types 0,3,and 11 in and type 8 out. This should allow you to Ping and traceroute, but leave you unpingable. I believe I got this from Andrea's ruleset a long time ago.
I might get some flack on this as there seems to be differences of opinion about ICMP being safe at all. I haven't had any problem with the settings I mentioned, and I have been set up like that for a long time. I go all over the web just asking for trouble some times, so I think that's safe.
Paul is right of course about Frederic. He is always very helpful and has the patience of a Saint.
TonyKlein
June 27th, 2002, 02:22 PM
Thanks guys, I will take a look there.
And about Fréderic "having the patience of a saint", I'm sure he'll need it with me...LOL ;)
TonyKlein
June 27th, 2002, 06:21 PM
As a follow up, I did post at Becky's LnS board, and have already received satisfying answers from Frederic to all my questions.
I've just purchased LnS. I like it!
Thanks again,
Paul Wilders
June 27th, 2002, 06:39 PM
Tony,
-{ Quote: "As a follow up, I did post at Becky's LnS board, and have already received satisfying answers from Frederic to all my questions." }-
Good! Frederic indeed takes care of LnS users.
-{ Quote: "I've just purchased LnS. I like it!" }-
Agreed; it's an awesome software firewall ;)
regards,
paul
TonyKlein
June 27th, 2002, 06:47 PM
I can only say that when I first discovered your site, I was just running Norton Internet Security including NAV, and by now I'm running Nod32, LnS, and BOClean, so what about that!?
There must be some subliminal advertising going on here that goes directly to your inner cortex.... ;D
Paul Wilders
June 27th, 2002, 06:54 PM
I'm going to copy and paste your last post, and mail it to the software vendors - merely to cash in ;D ;D ;D
regards,
paul
TonyKlein
June 28th, 2002, 06:06 AM
:D
By the way, I just registered LnS, and was pleasantly surprised to find a new 'Track Source' button on the Log tab, with Tracert and Whois functionality.
Great: I don't even need to use Neotrace any more.
I'm liking this firewall better all the time.
I even configured a rule to allow time servers to connect through UDP port 123.
Hey this is easy! ;)
vBulletin® Copyright ©2000-2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums