Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of Ghost Security Forums > Other Ghost Security Software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 25th, 2006, 04:04 PM
Demoras Demoras is offline
Infrequent Poster
 
Join Date: Jul 2004
Posts: 33
Default Making Ghostwall Rules

Hello,

I've decided to try Ghostwall, I haven't installed it yet but it seems like a very good firewall to me. There's one problem though, I'm scared of rule-based firewalls. I feel like I have less control over my internet connection (which isn't really true, but I kind of feel like that), simply because I don't master rulemaking yet.

Now, I know how to forward ports on routers, that's really easy. Is forwarding ports on routers comparable to making rules in Ghostwall? So, if I want to block a certain app, I just search for what ports it's using and block those ports?
And what if I don't know the app ports, is there some kind of log I can check? Or is there another way of finding out which ports are being used (since when it's already in the log file, there has already been made a connection and I could be in danger!)?
  #2  
Old January 25th, 2006, 04:51 PM
zapjb's Avatar
zapjb zapjb is offline
Very Frequent Poster
 
Join Date: Nov 2005
Location: USA - Back in a real State in time for a real President.
Posts: 1,961
Default Re: Making Ghostwall Rules

Interested to see if anyone posts easy enough instructions for this.
__________________
PCLinuxOS - Radically simple, it just works. That's why PCLOS is "The Distro Hopper Stopper!"
http://www.pclinuxos.com/

If you don't use Linux. You're going to HELL!!!
  #3  
Old January 25th, 2006, 04:56 PM
Demoras Demoras is offline
Infrequent Poster
 
Join Date: Jul 2004
Posts: 33
Default Re: Making Ghostwall Rules

Quote:
Originally Posted by zapjb
Interested to see if anyone posts easy enough instructions for this.

Hmm, is it that complicated?
  #4  
Old January 25th, 2006, 05:04 PM
Brinn Brinn is offline
Regular Poster
 
Join Date: Aug 2004
Location: Canada
Posts: 181
Default Re: Making Ghostwall Rules

GW logs the last 50 incoming and outgoing attempts. What would also help is to have an app like Port Explorer or TCPView (free from Sysinternals) so you can see what's trying to make a connection to which port.

Blocked attempts are also logged, I believe.
  #5  
Old January 25th, 2006, 05:26 PM
Demoras Demoras is offline
Infrequent Poster
 
Join Date: Jul 2004
Posts: 33
Default Re: Making Ghostwall Rules

Quote:
Originally Posted by Brinn
GW logs the last 50 incoming and outgoing attempts. What would also help is to have an app like Port Explorer or TCPView (free from Sysinternals) so you can see what's trying to make a connection to which port.

Blocked attempts are also logged, I believe.

I see. I guess I will give Ghostwall a try this weekend, play around with it a little and stuff.
  #6  
Old January 25th, 2006, 08:08 PM
tonyjl's Avatar
tonyjl tonyjl is offline
Frequent Poster
 
Join Date: May 2004
Posts: 287
Default Re: Making Ghostwall Rules

Hi Demoras.

Have a look here http://www.outpostfirewall.com/guide/rules/index.htm it gives a pretty good list of basic preset rules.

The best way is to first of all,set the firewall to 'ask you' for permision to grant acces to the net,when a connection is attempted that no rules allow for,you'll get an alert,then create a rule/or rules to allow them. Then its just a case of keeping an eye on your logs,if something doesn't work properly,can't connect etc. check ya logs for blocked entries,retry whatever isn't working a couple of times so that you get a few entries the same to help filter out normal internet noise .

Trial 'n' error mate,you'll get the hang of it in no time at all. Hope that helps ya get started,and good luck (not that you'll need any luck).
__________________
Best Regards,
TonyJL

I am prepared to meet my Maker. Whether my Maker is prepared for the great ordeal of meeting me is another matter.
Sir Winston Churchill, on the eve of his 75th birthday
British politician (1874 - 1965)
  #7  
Old January 26th, 2006, 01:58 AM
Demoras Demoras is offline
Infrequent Poster
 
Join Date: Jul 2004
Posts: 33
Default Re: Making Ghostwall Rules

Quote:
Originally Posted by tonyjl
Hi Demoras.

Have a look here http://www.outpostfirewall.com/guide/rules/index.htm it gives a pretty good list of basic preset rules.

The best way is to first of all,set the firewall to 'ask you' for permision to grant acces to the net,when a connection is attempted that no rules allow for,you'll get an alert,then create a rule/or rules to allow them. Then its just a case of keeping an eye on your logs,if something doesn't work properly,can't connect etc. check ya logs for blocked entries,retry whatever isn't working a couple of times so that you get a few entries the same to help filter out normal internet noise .

Trial 'n' error mate,you'll get the hang of it in no time at all. Hope that helps ya get started,and good luck (not that you'll need any luck).

Hmm, Ghostwall has such a thing? It didn't have app control, did it?
By the way, those rules, aren't they for Outpost Firewall?
  #8  
Old January 27th, 2006, 02:40 PM
tonyjl's Avatar
tonyjl tonyjl is offline
Frequent Poster
 
Join Date: May 2004
Posts: 287
Default Re: Making Ghostwall Rules

Quote:
Originally Posted by Demoras
Hmm, Ghostwall has such a thing? It didn't have app control, did it?

No,but you still need to create rules to allow them access the net,eg remote port 80 in & out.

Quote:
Originally Posted by Demoras
By the way, those rules, aren't they for Outpost Firewall?

Rules can be applied to any firewall as long as they have the same features eg. you can't apply a rule with TCP Flags to a firewall that doesn't support TCP Flags etc. etc.
Ports and IP Addresses can be trasfered though.
__________________
Best Regards,
TonyJL

I am prepared to meet my Maker. Whether my Maker is prepared for the great ordeal of meeting me is another matter.
Sir Winston Churchill, on the eve of his 75th birthday
British politician (1874 - 1965)
  #9  
Old January 27th, 2006, 04:43 PM
Demoras Demoras is offline
Infrequent Poster
 
Join Date: Jul 2004
Posts: 33
Default Re: Making Ghostwall Rules

Quote:
Originally Posted by tonyjl
No,but you still need to create rules to allow them access the net,eg remote port 80 in & out.

Oh okay, so it's kinda like those rules from Kerio Personal Firewall 2.15?
Ahh no matter what it's like, I'm gonna install it now and try it out
  #10  
Old January 27th, 2006, 05:18 PM
Demoras Demoras is offline
Infrequent Poster
 
Join Date: Jul 2004
Posts: 33
Default Re: Making Ghostwall Rules

Hmm, this rule thing, they're interesting, but also a bit confusing me.
It's like, every app has acces to the internet. I can't really say that one app shouldn't make a connection, unless I know what ports it's using of course, but if I block those ports and another program wants to use those ports, it can't connect to the internet either.
Hmmm......
  #11  
Old February 2nd, 2006, 09:59 AM
SCClockDr SCClockDr is offline
Infrequent Poster
 
Join Date: Oct 2005
Posts: 24
Default Re: Making Ghostwall Rules

Demoras

Look as this link:
http://www.wilderssecurity.com/showthread.php?t=107662
and this one:
http://www.wilderssecurity.com/showthread.php?t=107904

These should get you started.
__________________
Regards
George

Windows XP Home On a Sony VAIO 1.5G 520G Storage
Disk Director
True Image
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of Ghost Security Forums > Other Ghost Security Software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:16 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums