Black Ice 3.6

Discussion in 'other firewalls' started by lynchknot, Mar 17, 2005.

Thread Status:
Not open for further replies.
  1. Kerodo

    Kerodo Registered Member

    Joined:
    Oct 5, 2004
    Posts:
    8,013
    Yes, I did try EagleX here myself. It installed and seemed to work fine, but was a little confusing to me since I know basically nothing about snort. Seemed like it was meant for use on servers(?) or maybe it turned my machine into a server(?) :D At any rate, it did appear to set up with a minimum of hassle. It's worth a look. I still have it here myself..

    Regarding Tiny, yes, to set it up well it takes some time and patience. More than I have. But it's interesting to fiddle with if you're in the mood... and has some great features as well.
     
  2. lynchknot

    lynchknot Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    904
    Location:
    SW WA
  3. Kerodo

    Kerodo Registered Member

    Joined:
    Oct 5, 2004
    Posts:
    8,013
    Sorry, no idea.. most of the stuff involved was beyond me. I decided that if I didn't understand it, then I didn't need it..

    Maybe someone else here can help out though...
     
  4. lynchknot

    lynchknot Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    904
    Location:
    SW WA
    Both snort and idscenter have network access so it seems it's working but I have no way to see it working. I'll keep trying.
     
  5. Kerodo

    Kerodo Registered Member

    Joined:
    Oct 5, 2004
    Posts:
    8,013
  6. lynchknot

    lynchknot Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    904
    Location:
    SW WA
    wow, i'm seeing nowhere near the mem usage you were. Snort is only 6mb and IDScenter is at 12mb (with gui displayed)
     
  7. Kerodo

    Kerodo Registered Member

    Joined:
    Oct 5, 2004
    Posts:
    8,013
    That's amazing.. Snort was really sucking up the ram on my machine. I'm running Win2k here, not XP, so maybe that makes a difference somehow. I just installed with all the defaults and checked ram usage and it all totalled around 70 mb. Very high...

    Good that it's low on yours though.
     
  8. lynchknot

    lynchknot Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    904
    Location:
    SW WA
    Yet i'm still unable to address the config problem. I may just go back to two firewalls then. I want an easier IDS! I noticed that I can run BI's app control (radapp) without running BI. I wish I could do the same with the IDS component.
    There's going to be some even nastier stuff coming up and I want to be geared up.
     
    Last edited: Mar 28, 2005
  9. Kerodo

    Kerodo Registered Member

    Joined:
    Oct 5, 2004
    Posts:
    8,013
    That's interesting.. BI's app control with CHX-I might be a good combo.. No IDS there though...

    While you're experimenting, you should probably take a look at Tiny 6.5 Pro, just so you can say you've seen it. :)
     
  10. lynchknot

    lynchknot Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    904
    Location:
    SW WA
    Well, I already have PG so..... I really like Outpost (now that i'm used to it) so the only security app "missing" is IDS.
     
  11. Kerodo

    Kerodo Registered Member

    Joined:
    Oct 5, 2004
    Posts:
    8,013
  12. CrazyM

    CrazyM Firewall Expert

    Joined:
    Feb 9, 2002
    Posts:
    2,428
    Location:
    BC, Canada
    You just have to ask yourself if it is something you really need in addition to those two?

    Regards,

    CrazyM
     
  13. lynchknot

    lynchknot Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    904
    Location:
    SW WA
    Well, I know it's not but all this is fun. :p I enjoy experimenting. The "F11" (true image) button can take me back to normal if need be.
     
  14. CrazyM

    CrazyM Firewall Expert

    Joined:
    Feb 9, 2002
    Posts:
    2,428
    Location:
    BC, Canada
    Not that anyone around here is into tinkering ;)

    Regards,

    CrazyM
     
  15. MushfiQ

    MushfiQ Registered Member

    Joined:
    Jan 8, 2005
    Posts:
    131
    Black Ice can be used in conjunction with Kerio 2.15 ? or Kerio alone is enuff..Kerodo or any other have tried the combo yet? :cool:
     
  16. Kerodo

    Kerodo Registered Member

    Joined:
    Oct 5, 2004
    Posts:
    8,013
    No idea... just using BI alone here...
     
  17. lynchknot

    lynchknot Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    904
    Location:
    SW WA
    Last edited: Mar 30, 2005
  18. r00t

    r00t Registered Member

    Joined:
    Sep 7, 2004
    Posts:
    33
    I have Realsecure Desktop installed and it doesn't seem to alert me when certian apps want to access the Internet. I saw that AnyDVD was updating, RSD didn't ask me if it could.
     
  19. lynchknot

    lynchknot Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    904
    Location:
    SW WA
    Neither will using Blackice alone. BI will take a baseline of all your present apps and allow network access (I think) which is why i'm using Outpost/BI combo.
     
  20. r00t

    r00t Registered Member

    Joined:
    Sep 7, 2004
    Posts:
    33
    Is there much point using BI with Sygate then?
     
  21. lynchknot

    lynchknot Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    904
    Location:
    SW WA
    I don't know. It depends on compatibility with SygaTe and what you want. So far, it's the only Ids I've been able to get to work.
    Take a look at this. General firewalls do not detect intruders(?) to this extent (as far as I know) I have allowed port 4662 yet Black Ice detected "Queso scan" - whatever that is (I imagine a higher level scanner - enough to raise flags in BI to block), and blocked it regardless of port settings - something Outpost won't do (I think)



    http://img188.exs.cx/img188/9789/scan8rh.jpg


    Edit-

     
  22. AsianTiger

    AsianTiger Guest

    very good post guys. I just had to give BlackICE a go (after reading the thread mainly because of BI's Intruder/sion Detection). Could not find any other post where anyone tried Blackice with look'n'stop running, so I've decided to give it a go. I have not enabled application protection feature as I have ProcessGuard. So far no conflicts but I will post if there are.

    Just one question though under the history tab in network traffic there seems to be nothing happening when I am online, is this ok? I have not changed any settings.
     
  23. lynchknot

    lynchknot Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    904
    Location:
    SW WA
  24. AsianTiger

    AsianTiger Guest

    would appreciate it thanks
     
    Last edited by a moderator: Jun 23, 2005
  25. lynchknot

    lynchknot Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    904
    Location:
    SW WA
    black ice updated. Here's the short list:

     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.