TinyWall Firewall

Discussion in 'other firewalls' started by ultim, Oct 12, 2011.

  1. ultim

    ultim Developer

    Joined:
    Oct 12, 2011
    Posts:
    703
    Location:
    Hungary
    Enable the option in TinyWall, then mount your network drive as a fixed drive letter. Select to auto-mount on every boot. It will work.
     
  2. ron spencer

    ron spencer Registered Member

    Joined:
    Nov 17, 2007
    Posts:
    9
    Thanks...here is my situation.

    I am running TinyWall on a PC that is headless (I remote desktop to it). On it are two hard drives. I share the second drive. Once I set the headless machine to share that drive, all is ok. But when I reboot the machine, the share is gone. I can remote desktop to the machine and then I note that network discovery and file sharing is turned off. If I disable TinyWall this does not happen. I seems that TinyWall is turning off network discovery and sharing on reboot. Not sure it is, which is why I say "seems." Any ideas?
     
  3. ultim

    ultim Developer

    Joined:
    Oct 12, 2011
    Posts:
    703
    Location:
    Hungary
    As I said, mount the share on the client as a permanent drive letter, and it will work even if the server tells you that sharing is disabled (as long as you configured file sharing and it is enabled in TinyWall). File and printer sharing is not disabled by TinyWall, it's just stupid Windows thinking it is disabled because it checks for specific firewall rules instead of actually giving things a try. Huuuurrrr Microsoft can be annoying. This will be corrected (or better said, worked around) in a few months.
     
  4. Bleed

    Bleed Registered Member

    Joined:
    Mar 3, 2015
    Posts:
    7
    I'm really trying to like this app, it's lightweight, easy to use and it doesn't bother you with useless stuff, but i don't know what i'm doing wrong, it just seems to block applications even though they are whitelisted.
    Maybe it's a symptom of waking windows up from sleep, or most likely because of my ignorance, not knowing about random ports etc. What's the point of white-listing an app if it's still gonna block it at random anyways.
    Can anyone tell me what I'm doing wrong? I've tried, No Restrictions, Unrestricted UDP and TCP, I've tried switching options on/off at no change. At random points applications are gonna get blocked whether they are whitelisted or not.

    16jiv7m.png
    http://i58.tinypic.com/16jiv7m.jpg

    I really want this to be the last stop for a working firewall, but i have no idea what I'm doing wrong here.
     
    Last edited: Mar 7, 2015
  5. Jarmo P

    Jarmo P Registered Member

    Joined:
    Aug 27, 2005
    Posts:
    1,207
    Other than having the port based malware blocklist in Manage/General checked, I don't see any reason why that program should get or show blocked connections. Or if that executable changes starting location.
     
  6. Bleed

    Bleed Registered Member

    Joined:
    Mar 3, 2015
    Posts:
    7
    I do not have it checked. And it's not just the one program, it's most other white-listed apps that get blocked too. I do have avast installed but it's shields are not, could that be the cause;
     
  7. XJDHDR

    XJDHDR Registered Member

    Joined:
    Mar 9, 2015
    Posts:
    3
    I'm currently having two problems with TinyWall:

    The first involves the two files I've zipped here which are part of a program called SmartGit:
    https://onedrive.live.com/redir?resid=ECA203659010B63C!5248&authkey=!AFA0RgP9jaxV3e0&ithint=file,zip

    My problem is that these two EXEs get blocked from a network connection by TinyWall by default (this is normal) but neither of them show up properly in the "Show Connections" window with "Show blocked apps" ticked (this is not normal). Instead, each line has a Process ID listed in brackets with nothing at all listed for the process name. Furthermore, if I right-click on the two lines in question and click on Unblock, TinyWall doesn't add anything to it's list of exeptions (presumably because it can't figure out which executable it is supposed to be unblocking).To get these EXEs unblocked, I had to open Task Manager and figure out which EXE was being assigned the listed Process ID then use the "Whitelist by Executable" option.

    Edit:
    My second problem concerns a program I use with my smartphone called BlackBerry Blend. The program allows me to access my phone's messaging capabilities, calender, contacts and files from my PC either via USB or WiFi. Unfortunately, TinyWall is blocking the program's ability to accomplish it's task and I can't figure out how to whitelist the program.

    This first picture shows TinyWall's "Show Connections" window with "Show blocked apps" ticked after I attempted to connect to my phone with BB Blend and failed.
    BB connections blocked.png

    The only way I could get BB Blend to connect to my phone was by completely disabling the firewall (even "Allow outgoing" mode blocked the connection). The next two pictures show TinyWall's "Show Connections" window with "Show Active Connections" ticked after I established a connection to my phone with TinyWall in disabled mode.
    BB connections  allowed 1.png
    BB connections allowed 2.png

    BTW, most of those processes you see are created by BB Blend. And before anyone asks, I did whitelist all of them before I captured any of these pictures or tested for this problem. The problem is that whitelisting all of those executables is not enough to make BB Blend work and TinyWall isn't showing me what else I need to unblock.

    Since I doubt anyone here uses a BlackBerry 10 phone that they can test this issue with, what else can I do to help fix this problem if it can be fixed?
     
    Last edited: Mar 10, 2015
  8. Bleed

    Bleed Registered Member

    Joined:
    Mar 3, 2015
    Posts:
    7
    I ended up uninstalling Avast! antivirus and I'm not experiencing connection and blocking problems anymore as far as i can tell. Just as well, antivirus apps are a nuisance anyway and slowly becoming obsolete, I'll just rely on my common sense when it comes internet security, served me well thus far.
    I'll hold on to Malwarebytes for now and continue to use Tinywall for my firewall needs.

    Nifty little app that's starting to grow on me, thank you.
     
  9. Jarmo P

    Jarmo P Registered Member

    Joined:
    Aug 27, 2005
    Posts:
    1,207
    Bleed, I don't know what to say. I have been running avast all the time with my computer. I did not experience any problems that I noticed. I somehow had secureline running that I disabled. It did not make much bother to me, I was just wondering why I had it running. since I had not subscribed to that VPN.

    I agree if you are running your computer sandboxied that the need for an AV is not much if at all. Or with my AppGuard. Still I would like to keep an active AV in my computer. It might just be your internet connection that does not agree with avast, but what do I know.
     
  10. bollity

    bollity Registered Member

    Joined:
    May 9, 2009
    Posts:
    190
    Did you try to change mode to auto-learn before starting your software?
     
  11. Bleed

    Bleed Registered Member

    Joined:
    Mar 3, 2015
    Posts:
    7
    I spoke too soon, now it's blocking Steam and Chrome even though they are whitelisted. Yep, this firewall is not working for me, will have to uninstall it. Too bad, i kind of liked it.
    Guess the Author is on vacation?
     
  12. XJDHDR

    XJDHDR Registered Member

    Joined:
    Mar 9, 2015
    Posts:
    3
    Thank you for the reply. Unfortunately, your suggestion only worked for my first problem. SmartGit now gets properly whitelisted while I have autolearn mode activated. However, BB Blend is still blocked by TinyWall even in Autolearn mode.

    I've managed to take a screenshot of TinyWall's "Show Connections" window with "Show blocked apps" ticked when it blocks SmartGit, to better illustrate the problem that i think should be fixed. The two processes inside the red box are the processes associated with SmartGit. I believe that the problem of a process name not being shown should be fixed:
    SmartGit blocked.png

    Also, I don't really like Autolearn mode because I have no way of knowing what got whitelisted at the time. I would thus like to request that when Autolearn mode gets switched off, TinyWall will display a window showing a list of processes that were whitelisted by Autolearn mode.
     
  13. homeless_sapient

    homeless_sapient Registered Member

    Joined:
    Apr 11, 2012
    Posts:
    34
    TinyWall is a likeable program but it is useless for me in its actual form. It would very nice and helpful if – under explicite conditions – TinyWall would allow the user to make advanced fine tunings on Windows Firewall rules. For example I have to filter (block) some IPs for a program (executable). It is impossible if TinyWall is installed. TinyWall never let me fine tune the rules in Windows Firewall interface. Please make a switcheable option to allow users to fine tune the advanced settings of the firewall rules in Windows Firewall.
     
  14. Jarmo P

    Jarmo P Registered Member

    Joined:
    Aug 27, 2005
    Posts:
    1,207
    There was one special interface of a firewall I liked a lot, in a sense of configurability. It was Kerio 2.1.5. Well it lost sometimes its rules and there was rumor of fragmented packets passing. Nothing perfect, except the interface and idea.

    TinyWall is nice and satisfies most needs for the outbound control. I am quite happy with it. Kerio 2.1.5 is just a dream of an interface :)
     
    Last edited: Mar 28, 2015
  15. homeless_sapient

    homeless_sapient Registered Member

    Joined:
    Apr 11, 2012
    Posts:
    34
    :) I need to block some IP address ranges for a program. TinyWall doesn't allow this beacuse TinyWall blocks (protects) the access to the Windows Firewall rules from the Control Panel. These rules are read-only if the TinyWall service is running. It would be nice if this blocking (protection) would be an optional, selectable security feature, otherwise TinyWall forces, imposes the excessive simplification of the Windows Firewall rules.
     
  16. homeless_sapient

    homeless_sapient Registered Member

    Joined:
    Apr 11, 2012
    Posts:
    34
    […] A humble suggestion to enable the advanced editing for the rules but at the same time to preserve the protection of the TinyWall service (read-only rules for external applications):
    There is a list in TinyWall with the rules created with TinyWall. It would be magnificent a right-click option for these rules (from this list) to open the advanced configuration window of Windows Firewall for the selected rule (with read-and-write rights – only if this configuration windows is opend from the rule-list of TinyWall).
     
  17. rm22

    rm22 Registered Member

    Joined:
    Oct 26, 2014
    Posts:
    357
    Location:
    Canada

    Jarmo P - i've recently put Avast free and Tinywall on a Win 8.1 pc for another user. Avast is selected in 'special exception' in Tinywall, but Avast update failed part way through the file downloads. with tinywall disabled avast updated fine...

    have you also seen this? i'm thinking i should have switched on learning mode during the avast update - could try that next time to see if that fixes it.

    EDIT - just read post #941 re - 'show blocked connections' - i guess that would be a better option then learning mode...
     
    Last edited: Apr 11, 2015
  18. Jarmo P

    Jarmo P Registered Member

    Joined:
    Aug 27, 2005
    Posts:
    1,207
    Learning mode is not as drastical solution as in hips type of firewalls, if you are behind a router firewall. You can safely afterwards disable unnecessary allowances, and certainly the incoming connections from your rules that the learning mode gives. Just allow outgoing TCP and UDP. I myself don't need the learning mode as whitelisting by other means and by that connections window work for me.

    I think with latest 2015 avast there came some other executable you need to allow. Too lazy to check mine, but the blocked connections is a good aid. Turn that window on before trying the update and it should show.
     
    Last edited: Apr 11, 2015
  19. rm22

    rm22 Registered Member

    Joined:
    Oct 26, 2014
    Posts:
    357
    Location:
    Canada
    ok - thanks for the feedback
     
  20. Jarmo P

    Jarmo P Registered Member

    Joined:
    Aug 27, 2005
    Posts:
    1,207
    I think the executable what is needed for Avast is: C:\Program Files\AVAST Software\Avast\ng\ngtool.exe

    For the program update perhaps C:\Program Files\AVAST Software\Avast\Setup\instup.exe
    When updating programs the smartest thing would be propably to do reboot before doing that and perhaps reset the router. And then not so bad to allow all outgoing mode if wanting to be lazy, and not the learning mode. And then do a reboot again even if the program does not need that after changing the protection to Normal. Normal protection is what TW should be run.

    What I meant about hips firewalls. They are now not so many existing, is that they if I remember right allow something like svchost.exe out and then depend on their hips part strongly. And if hips is disabled what good are they for? And also the their learning mode might allow already something nasty out. And still you will be always in some kind of paranoia about popups if the hips is enabled.

    Now I don't know any about the other windows firewall controllers but at least TinyWall can be very strict in what to allow, as a packet filter.
    There is the Windows update rule that allows too much by default:
    https://www.wilderssecurity.com/threads/beta-testing-tinywall.309739/page-37#post-2430342
    What you can do with Windows 7, is disable it and make your own rule. I posted what to do in some previous post of that. And I think with Windows 8.1 to only allow it when updating the Windows.
     
  21. rm22

    rm22 Registered Member

    Joined:
    Oct 26, 2014
    Posts:
    357
    Location:
    Canada
    Jarmo P - thanks again for the info.

    still having problems with various software updates so thought i'd give autolearn a try & still having problems... i think for updates that require a reboot there is potentially a problem with TW reverting to 'normal mode' on the reboot. if TW is in autolearn then shouldn't restart in autolearn on reboot so the install can finish before changing back to 'normai' mode?
     
  22. Jarmo P

    Jarmo P Registered Member

    Joined:
    Aug 27, 2005
    Posts:
    1,207
    I think you don't need or should not need TinyWall to be disabled/in learning mode after the reboot. I have no knowledge of this, so unable to help any. There should be time allowed to change TW to a more allowing mode after reboot, if you really need it. Perhaps someone else can confirm indeed that such a permanent Autolearn need exists in some cases?

    I would like all programs to be able to install without internet connection once you have downloaded the executable to install. That is not possible with stub type of program installers needing a connection to internet and installing then the rest of the program. Since AppGuard is not able to protect in install mode, I really dislike those kind of stubs.
     
  23. XJDHDR

    XJDHDR Registered Member

    Joined:
    Mar 9, 2015
    Posts:
    3
    Sorry about bringing this up again but I am still experiencing the two problems I posted about nearly two months ago. I received a suggestion to try using Autolearn mode but that only helps with the first problem and doesn't help me at all with the second. I would greatly appreciate a solution to these issues.
     
  24. Herberta

    Herberta Registered Member

    Joined:
    Aug 26, 2014
    Posts:
    30
    I tested the VPN service on windows 7 and had the same problem. I made a new partition on the HD som everything is the same. Computer connected directly to the internet (also tried it behind NAT router).
     
  25. Herberta

    Herberta Registered Member

    Joined:
    Aug 26, 2014
    Posts:
    30
    I tested the vpn software "SoftEther". That one works with Tinywall but not the windows build in vpn client. However, with softether I can set "no restrictions" to the exe. What is the differences to that and "unrestricted UDP&TCP"?
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.