Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other firewalls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 7th, 2004, 04:18 PM
Sweeney Sweeney is offline
Infrequent Poster
 
Join Date: Apr 2004
Posts: 2
Default NIS2004 blocking trusted site ?

I use NIS 2004 on win XP home sp1. I run Folding@home and have the ports it uses entered as trusted sites. These are 8080 ports entered as a range for download and port 80 ports for upload.
I have the program entered as allowing all conections.
The uploads to port 80 are fine but the downloads from the 8080 ports are blocked.
I understand that NIS lets any trusted site through without any action so I'm puzzling out why 8080 ports are blocked. If I disable NIS the downloads are fine.
The other event, which may be linked, is that I get blocks of TCP non syn/non ack packets on invalid connection, in blocks,all the time and understand that these could be TCP ping packets. I ignore them.
I always get one single TCP non syn/ack packet when the folding@home port 8080 download is requested. Could this be the problem ?
I have no special rules, I block all cookies and referrers except to selected sites, I have all my programs ruled and don't use auto.
Removing these restrictions makes no defference to the problem.
Any ideas ?

Sweeney
  #2  
Old April 8th, 2004, 02:25 AM
CrazyM's Avatar
CrazyM CrazyM is offline
Firewall Moderator
 
Join Date: Feb 2002
Location: BC, Canada
Posts: 2,433
Default Re:NIS2004 blocking trusted site ?

Quote:
quoting: Sweeney link=board=23;threadid=27383;start=0#msg157266 date=1081369101]
I use NIS 2004 on win XP home sp1. I run Folding@home and have the ports it uses entered as trusted sites.

The ports entered, or do you mean you have the remote IP(s) entered in the trusted zone?

Quote:
I understand that NIS lets any trusted site through without any action so I'm puzzling out why 8080 ports are blocked. If I disable NIS the downloads are fine.

That is my understanding of the trusted zone as well: "Trusted zone: Computers not regulated by Norton Personal Firewall."

Quote:
The other event, which may be linked, is that I get blocks of TCP non syn/non ack packets on invalid connection, in blocks,all the time and understand that these could be TCP ping packets. I ignore them.

These "TCP non-syn/non-ack packet on invalid connection. Packet has been dropped" log entries can be a few different things. Usually they are just late packets that NIS no longer considers part of valid connection. These entries are where you will also see certain types of stealth scans being dropped that the firewall previously could not stealth and were not part of the IDS signatures (the message flags are the key here). This stateful filtering was introduced in NIS/NPF2003, and I am uncertain exactly which component of NIS/NPF is actually doing it. It is not something that is configurable.

Quote:
I always get one single TCP non syn/ack packet when the folding@home port 8080 download is requested. Could this be the problem ?

This is something that could be timing out your connections from remote systems.

Quote:
I have no special rules, I block all cookies and referrers except to selected sites, I have all my programs ruled and don't use auto.
Removing these restrictions makes no defference to the problem.
Any ideas ?

If you are going to use the trusted zone, make sure all required remote IP's for the remote systems are entered.

You could also make some custom rules for these same IP's in your General rules allowing the required communication inbound and outbound and place them at or near the top.

Regards,

CrazyM
__________________
"The best thing we can do in cyberspace is exactly what we do in the real world: do our best to manage the risks."
- Bruce Schneier
  #3  
Old April 8th, 2004, 04:19 AM
Sweeney Sweeney is offline
Infrequent Poster
 
Join Date: Apr 2004
Posts: 2
Default Re:NIS2004 blocking trusted site ?

Thanks for the help CrazyM.
Yes, quite right, I meant that I entered the IP address' in trusted as a range; there are around 70 possible servers that could be selected for download on port 8080.
I'll try a specific rule to get more logging. I may get lucky early.
The tcp syn/acck looks like it may be red herring then.
I'll post back when I get more to go on.

Regards,

Sweeney
 

Wilders Security Forums > Security Products > other firewalls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:22 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums