Outpost 2009 Free or Pro

Discussion in 'other firewalls' started by Toby75, May 4, 2009.

Thread Status:
Not open for further replies.
  1. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    Stem,

    I have all of these checked off...even the last one...is that good?
     
  2. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    It should not be a problem on a small LAN. There can be some problem if scanning/mapping is made from the gateway. But you will know that if it happens. So you can leave all enabled.

    I dont think it will be of benefit to you to block reserved ports as the IP blocklist with that entry will stop all nodes(PCs) on LAN connecting (it will also stop you connecting to them)

    We need now to check what other applications have been given access. Can you post a screen shot of the application list (no need for the rules)


    - Stem
     
  3. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    OK -- I have to let my computer run for a couple of minutes so that the apps show in OP -- I will be right back.
     
  4. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    No Problem,
    I am mainly concerned with applications such as windows explorer and task manager that dont actually need internet rules.

    If you prefer not to post a screen shot of applications, then no problem, just type a list of the window applications that are in the list.


    - Stem
     
  5. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    OK Stem, here it is!

    APPS(1).jpg
    APPS(2).jpg
     
    Last edited by a moderator: May 9, 2009
  6. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    other ones just popped up that was not included in that screen shot:
    taskeng
    wermgr

    Also svchost keeps trying to make a UDP connection with 3702...I keep blocking this...is this ok or should I keep blocking it?
     
  7. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    From the screen shots all signed applications are being given default rules. Not a real security issue, but some users dont like MS apps connecting out.


    Port 3702 is used as part of uPnP, is this an inbound attempt? What is the popup shown? (it may be from gateway)



    - Stem
     
  8. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    OK - I'll be right back I'm gonna restart to get that popup.
     
  9. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    2 more

    SVCHOST.jpg
    SVCHOST(2).jpg
     
    Last edited by a moderator: May 9, 2009
  10. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    The first popup port 49176 I think is specific to Vista, I will check the comms, but will need to restore the vista image.

    Block both for now.

    What I would like you to do, if willing, is to clear the firewall log. Then just continue as usual. Then say in about 12 hours, copy the firewall log and either attach it to a post here, or PM me and you can upload it to a file sharing site.
    I can then check to see what comms are being made and what changes should be made to make you secure.

    - Stem
     
  11. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    One thing I noticed was that when I restarted my computer....and went to wilders...I was still logged in! lol does this have something to do with the IP blocking?

    Also, my URL search history isn't working...no big deal.
     
  12. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    If you dont log out, and cookies are not cleared from your browser, then you will be remembered.

    URL search history in what?


    - Stem
     
  13. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    OK - sounds good. I should delete the text documents in the log section right?
     
  14. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    Oh yeah I checked remember me, Duh

    Never mind about the search history...I think it was always like that....I forgot that I mostly use favorites so I never have to type anything in the URL.
     
  15. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    Just open OP, go to "Firewall" log, and select "Clear"

    2009-05-08_022514.jpg

    When you want to post/PM me the log, just go to the firewall log again, select all the entries, right click, select copy. Then open notepad and paste.


    - Stem
     
  16. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    OK Stem,

    Thank You so much. You are the Man!!!!!!!!!!!!!!!
     
  17. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    No problem.

    Happy surfing.

    I will check your logs as soon as I receive them

    Time for my sleep (2:40 am here)


    - Stem
     
  18. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    Thanks again -- have a good night.
     
  19. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    Good Morning Stem,

    In the log you will see that I "allowed once" svchost on certain connections. I wanted you to see this because if you read it as "blocked" you would probably assume that it was automatically blocked and not to worry about it.

    Here are the results
     

    Attached Files:

    Last edited: May 7, 2009
  20. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    Good morning.

    Open OP, go to the applications, and select svchost.

    There are 5 rules that you should change to block(remember, change to block, do not delete them):-

    2(two) rules for; link-local Multicast Name resolution
    3(three) rules for;- LDAP

    01.jpg



    There are a couple of entries where outbound netbios as been blocked, but the attempts have been to send outside the LAN(to internet). Dont panic, but I do not like those entries. Do you have an AV installed?

    A question.
    Do you currently have anything installed from the Vendor Comodo? or have you had Comodo installed and then un-installed?


    I need to go through your log fully again, but will now wait for your reply to see if you have questions concerning the above.
    (and there may be the ICMPv6 rules to change)


    - Stem
     
  21. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    Hi Stem,

    I have blocked the rules for svchost.

    I currently do not have an AV installed but I do on-demand scans with A2, MBAM, Superantispyware, and McAfee's online scanner. I do scans very frequently.

    The connections for Comodo belong to Comodo system cleaner. I've been using this for about a month now.


    Off to work now -- TGIF
     
    Last edited: May 8, 2009
  22. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    Hi Toby,

    OK,

    Can you check your LMhosts file for any entries. There is info here of its location.

    I am just checking.


    - Stem
     
  23. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480
    Hi Stem,

    File doesn's exist...the following files are in that folder:
    hosts
    lmhosts.sam
    networks
    protocol
    services
     
  24. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    Hi Toby,

    OK.

    You should now be OK from any connections within the LAN. If you do have any further questions, then just post to forum.


    - Stem
     
  25. Toby75

    Toby75 Registered Member

    Joined:
    Mar 10, 2006
    Posts:
    480

    So am I bulletproof? lol

    What should I do with those 2 popups further up on this page?

    Thank You for your patience and time -- You are very helpful!
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.