PDA

View Full Version : Address temporarily blocked


dorgane
December 22nd, 2009, 04:03 PM
bug :firewall IDS block connexion in ESS4.2 Seven 64

i have not connexion now (automatic and interactive mode) disable it is run :

22/12/2009 19:50:02 Address temporarily blocked by active defense (IDS) 192.168.1.20:54971 192.168.1.1:53 UDP
22/12/2009 19:50:01 Address temporarily blocked by active defense (IDS) 192.168.1.20:56928 192.168.1.1:53 UDP
22/12/2009 19:50:01 Address temporarily blocked by active defense (IDS) 192.168.1.20:51064 192.168.1.1:53 UDP


~Private email removed per the TOS. (http://www.wilderssecurity.com/tos.php)~


I can't firewall :'(

DooGie
December 22nd, 2009, 04:08 PM
-{ Quote: "sysinspector not working here gets stuck on 50% then locks up pc. works fine previous version.
edit working now deleted file re booted and ran again." }-

Yup I can confirm this. Otherwise everything appears to work ok up to now.

Running Windows 7 x64.

Marcos
December 22nd, 2009, 04:25 PM
There must be a reason why the connection was blocked. To get detailed information about the rule that blocked the connection, enable "Log all blocked connections" option in the IDS setup, replicate the problem and eventually check the firewall log for details. Then post here the relevant portion of your firewall log here.

dorgane
December 22nd, 2009, 04:35 PM
Log all blocked connections ->it is enale,
line IDS is here when i enable it.

i try reset settings, i re come for say.

Marcos
December 22nd, 2009, 04:42 PM
Is the IP address 192.168.1.1 in the Trusted zone? If you don't use automatic mode, do you have the rule "Allow outgoing DNS requests" enabled?

dorgane
December 22nd, 2009, 04:42 PM
after reset, internet work but I have :

-{ Quote: "
22/12/2009 22:41:08 Communication denied by rule 192.168.1.1:2111 192.168.1.20:2869 TCP Block incoming ICSLAP (UPNP) requests System
22/12/2009 22:40:56 Communication denied by rule 192.168.1.1:2111 192.168.1.20:2869 TCP Block incoming ICSLAP (UPNP) requests System
22/12/2009 22:40:50 Communication denied by rule 192.168.1.1:2111 192.168.1.20:2869 TCP Block incoming ICSLAP (UPNP) requests System
22/12/2009 22:40:47 Communication denied by rule 192.168.1.1:2111 192.168.1.20:2869 TCP Block incoming ICSLAP (UPNP) requests System
" }-

Marcos
December 22nd, 2009, 04:45 PM
Ok, so if the IP address 192.168.1.20 is actually in the Trusted zone, make sure that the "Allow UPNP in the Trusted zone" option is enabled in the IDS setup. If you're not experiencing any problems, there's no need to enable UPNP.

dorgane
December 22nd, 2009, 04:49 PM
is it ?

214382


In interactive mode

dorgane
December 22nd, 2009, 04:52 PM
now it is other port :

-{ Quote: "22/12/2009 22:46:51 Communication denied by rule 192.168.1.1:2147 192.168.1.20:2869 TCP Block incoming ICSLAP (UPNP) requests System
22/12/2009 22:46:39 Communication denied by rule 192.168.1.1:2147 192.168.1.20:2869 TCP Block incoming ICSLAP (UPNP) requests System
22/12/2009 22:46:33 Communication denied by rule 192.168.1.1:2147 192.168.1.20:2869 TCP Block incoming ICSLAP (UPNP) requests System
22/12/2009 22:46:30 Communication denied by rule 192.168.1.1:2147 192.168.1.20:2869 TCP Block incoming ICSLAP (UPNP) requests System" }-

Marcos
December 22nd, 2009, 04:58 PM
Please add 192.168.1.1 to the Trusted zone, this should eventually allow UPNP requests in the TZ providing that you have this option enabled in the IDS setup.

dorgane
December 22nd, 2009, 05:03 PM
i don't understand, it is default settings :-\

.20 is my IP local :

214383

i add .20 with my local : 127.0.0.1?

dorgane
December 22nd, 2009, 06:59 PM
HELP
flood interactive or automatic :

http://www.cijoint.fr/cjlink.php?file=cj200912/cijVq0wHqK.zip

thx

dorgane
December 22nd, 2009, 11:54 PM
I have make uninstall and clean install :


-{ Quote: "
23/12/2009 05:53:10 Packet blocked by active defense (IDS) 89.202.157.208:80 192.168.1.20:49216 TCP
23/12/2009 05:53:04 Communication denied by rule 192.168.1.20:138 192.168.1.255:138 UDP Block outgoing NETBIOS requests System
23/12/2009 05:52:27 Packet blocked by active defense (IDS) 192.168.1.20:49204 206.220.42.147:25999 TCP
23/12/2009 05:52:22 Packet blocked by active defense (IDS) 89.202.157.208:80 192.168.1.20:49216 TCP
23/12/2009 05:52:17 Packet blocked by active defense (IDS) 192.168.1.20:49204 206.220.42.147:25999 TCP
23/12/2009 05:52:12 Packet blocked by active defense (IDS) 192.168.1.20:49204 206.220.42.147:25999 TCP
23/12/2009 05:52:11 Packet blocked by active defense (IDS) 192.168.1.20:49204 206.220.42.147:25999 TCP
23/12/2009 05:52:11 Packet blocked by active defense (IDS) 192.168.1.20:49204 206.220.42.147:25999 TCP
23/12/2009 05:52:11 Packet blocked by active defense (IDS) 192.168.1.20:49204 206.220.42.147:25999 TCP
23/12/2009 05:52:11 Packet blocked by active defense (IDS) 192.168.1.20:49204 206.220.42.147:25999 TCP
23/12/2009 05:52:11 Packet blocked by active defense (IDS) 192.168.1.20:49204 206.220.42.147:25999 TCP
23/12/2009 05:52:11 Packet blocked by active defense (IDS) 192.168.1.20:49204 206.220.42.147:25999 TCP
23/12/2009 05:51:58 Packet blocked by active defense (IDS) 89.202.157.208:80 192.168.1.20:49216 TCP
23/12/2009 05:51:55 Packet blocked by active defense (IDS) 192.168.1.20:49216 89.202.157.208:80 TCP
23/12/2009 05:51:54 Packet blocked by active defense (IDS) 192.168.1.20:49213 65.55.25.60:443 TCP
23/12/2009 05:51:47 Packet blocked by active defense (IDS) 65.55.25.60:443 192.168.1.20:49213 TCP
23/12/2009 05:51:46 Packet blocked by active defense (IDS) 192.168.1.20:49216 89.202.157.208:80 TCP
23/12/2009 05:51:46 Packet blocked by active defense (IDS) 89.202.157.208:80 192.168.1.20:49216 TCP
23/12/2009 05:51:41 Packet blocked by active defense (IDS) 192.168.1.20:49216 89.202.157.208:80 TCP
23/12/2009 05:51:40 Packet blocked by active defense (IDS) 89.202.157.208:80 192.168.1.20:49216 TCP
23/12/2009 05:51:39 Packet blocked by active defense (IDS) 192.168.1.20:49216 89.202.157.208:80 TCP
23/12/2009 05:51:37 Packet blocked by active defense (IDS) 192.168.1.20:49216 89.202.157.208:80 TCP
23/12/2009 05:51:37 Packet blocked by active defense (IDS) 192.168.1.20:49216 89.202.157.208:80 TCP
23/12/2009 05:51:37 Packet blocked by active defense (IDS) 89.202.157.208:80 192.168.1.20:49216 TCP
23/12/2009 05:51:37 Packet blocked by active defense (IDS) 89.202.157.208:80 192.168.1.20:49216 TCP
" }-

dorgane
December 23rd, 2009, 08:42 AM
other :

-{ Quote: "
23/12/2009 14:39:38 Communication denied by rule 192.168.1.20:138 192.168.1.255:138 UDP Block outgoing NETBIOS requests System
23/12/2009 14:37:39 Communication denied by rule 192.168.1.20:138 192.168.1.255:138 UDP Block outgoing NETBIOS requests System
23/12/2009 14:37:22 Communication denied by rule 192.168.1.20:138 192.168.1.255:138 UDP Block outgoing NETBIOS requests System
23/12/2009 14:36:22 Communication denied by rule 192.168.1.20:138 192.168.1.255:138 UDP Block outgoing NETBIOS requests System
23/12/2009 14:35:54 Communication denied by rule ::1.:49163 ::1.:2869 TCP Block outgoing ICSLAP (UPNP) requests C:\Program Files\Windows Media Player\wmpnetwk.exe AUTORITE NT\SERVICE RÉSEAU
23/12/2009 14:35:52 No usable rule found 192.168.1.20 224.0.0.22 IGMP System
23/12/2009 14:35:51 No usable rule found 192.168.1.20 224.0.0.22 IGMP System
23/12/2009 14:35:34 No usable rule found 127.0.0.1 224.0.0.22 IGMP System
23/12/2009 14:35:34 No usable rule found 192.168.1.20 224.0.0.22 IGMP System
23/12/2009 14:35:34 No usable rule found 192.168.1.20 224.0.0.22 IGMP System
23/12/2009 14:35:34 No usable rule found 192.168.1.20 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 192.168.1.20 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 192.168.1.20 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 127.0.0.1 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 127.0.0.1 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 192.168.1.20 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 192.168.1.20 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 127.0.0.1 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 127.0.0.1 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 127.0.0.1 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 192.168.1.20 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 192.168.1.20 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 192.168.1.20 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 127.0.0.1 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 127.0.0.1 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 192.168.1.20 224.0.0.22 IGMP System
23/12/2009 14:35:33 No usable rule found 192.168.1.20 224.0.0.22 IGMP System
" }-

no body can help me?

dorgane
December 23rd, 2009, 09:05 AM
i put sysinspector :

http://www.cijoint.fr/cjlink.php?file=cj200912/cijK6kwdtl.zip

Marcos
December 23rd, 2009, 11:28 AM
First of all, please explain what problem you're having (e.g. an application XY doesn't work because the fw blocks its communication).

dorgane
December 23rd, 2009, 02:54 PM
all softwares, web browser,... run !
but in automatic or interactive mode, i have the log of firewall with a lot of line (when i active log al of connexion blocked)

Marcos
December 23rd, 2009, 05:34 PM
That's pretty normal that firewall blocks/drops a lot of unwanted connections. Logging of all blocked connections is intended only for troubleshooting purposes and should be disabled otherwise. I for one would worry if my firewall didn't block anything :)