CHX-I Setup Assistance Please

Discussion in 'other firewalls' started by glentrino2duo, Jun 17, 2006.

Thread Status:
Not open for further replies.
  1. glentrino2duo

    glentrino2duo Registered Member

    Joined:
    May 8, 2006
    Posts:
    310
    Hello again...
    I'm 'playing' a little with CHX-I v.3 but now I need some assistance in setting it up.

    Firstly, I followed the suggestions in this link https://www.wilderssecurity.com/showthread.php?t=124457&highlight=chx-i setup because I'm behind a proxy/router to allow router broadcast. After that, the log shows (left of attached thumbnail) what was being filtered and I can't used my browser. So I made a filter like what is shown in the right of the attached thumbnail. Please note that the 'Source MAC List' and 'Dest MAC List' are the four MACs shown in the log. I don't know how to enter 0x24 in the Eth. Type, so I just put any. I don't know what is it that I just opened so I named it 'Allow ARP.' After that I can use my browser already. Now, did I do the right thing? Did I set it up correctly? Or I just opened up my system as if CHX-I is not there? Assistance is very much appreciated. Thanks!
     

    Attached Files:

    Last edited: Jun 17, 2006
  2. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,456
  3. glentrino2duo

    glentrino2duo Registered Member

    Joined:
    May 8, 2006
    Posts:
    310
    Thank you very much for the reply.. If I removed that rule, I can't connect in my browser. I already have "Block unsolicited ARP reply" enabled even before making that rule. I modified my rule a bit. Instead of 'Any' in the Eth. Type, I just put 'ARP' and now I can connect again. It is still blocking some 'ARP things' that does not match to MAC address I put in the condition. It is also blocking '0x24' from the same set of MAC address I have in the ARP rule I made, but I still can connect without any problem. I don't know yet what problem I will run into with CHX-I blocking that Eth. Type of '0x24', whateve that is...

    Am I on the right track? BTW, how do I convert '0x24' into hex that I can type in the hex field? The field only accepts numbers...
     
  4. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,456
    It seems that you haven't a good rules to start using CHX.
    I know that the CHX site doesn't provide them, but they will improve that...

    You should start with this sample: wan_start.zip

    After import the sample, change the "***Deny Ingress filters" rule to this, to avoid problems on local networks...:
    http://img71.imageshack.us/img71/9531/chxdenyingressrule7or.png

    Define the properties for each network adapter that you have, and then try a scan on Shields UP! to see if you have your system stealth... ;)
     
  5. glentrino2duo

    glentrino2duo Registered Member

    Joined:
    May 8, 2006
    Posts:
    310
    Thanks! I'll try that ASAP... Thanks very much for all the assistance.. :)
     
  6. glentrino2duo

    glentrino2duo Registered Member

    Joined:
    May 8, 2006
    Posts:
    310
    Imported, but it doesn't contain the rule '***Deny Ingress filters' and the 'Deny Ingress filters' list... I could add the '***Deny Ingress filters' myself, but I don't know what's in the defined IP list...
     
  7. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,456
  8. glentrino2duo

    glentrino2duo Registered Member

    Joined:
    May 8, 2006
    Posts:
    310
    Thanks. Right now, I won't bother with CHX-I blocking this 0x24 since it doesn't seem to affect my connection. I'll observe in a few days...

    BTW, I downloaded wan_start.zip and imported the filters, but it doesn't have the rule and defined list 'Deny Ingress filters'
     
  9. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,456
    I made a backup of my rules, and then import the sample to see if the rule "***Deny Ingress filters" was there, but it wasn't...

    Then I go back to my rules, but now I can't import the "***Deny Ingress filters" like I showed above! Maybe a bug...

    I will ask about this on CHX forum...

    You can try to enter this rule, and this is the list: Deny_Ingress_filters.rar
    Tell me if you can added it...
     
  10. glentrino2duo

    glentrino2duo Registered Member

    Joined:
    May 8, 2006
    Posts:
    310
    Same result here:
    I was able to import the defined list 'Deny Ingress filters' but I cant import the rule so I tried making it myself but I can't. When I press OK, nothing is added to the filter rules..

    --
    Sorry to bother you with more questions, but what are those IP address in the list 'Deny Ingress filters'? Are they internal IPs? Why are we denying them access?
    BTW, thanks for handholding me on this... This is such a great forum.
     
  11. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,456
    I already reported this on the CHX forum :)
    http://www.fluxgfx.com/ssc/showthread.php?t=301

    Take a look here: http://www.fluxgfx.com/ssc/showthread.php?t=285
    And here, starting on post #15: http://www.fluxgfx.com/ssc/showthread.php?t=140
     
  12. glentrino2duo

    glentrino2duo Registered Member

    Joined:
    May 8, 2006
    Posts:
    310
    Figured out how to enter 0x24 in the hex field: Using Windows calculator, it converted 24 to 18, so entered 1800 in the hex field and it worked okay! :)
     
  13. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,456
    Nice :)
     
  14. glentrino2duo

    glentrino2duo Registered Member

    Joined:
    May 8, 2006
    Posts:
    310
    I was able to add '***Deny Ingress filter' and the list but applying the adjustment mentioned in Post#4 is causing an error. I always received a Windows XP error and MMC has to be closed. Having the '***Deny Ingress filter' , I can't connect to my router. So I followed Alphalutra1's method in Post #5 here: http://www.fluxgfx.com/ssc/showthread.php?t=285, after that I can already connect to my router.
    Slowly, I'm getting the hang of it. I just hope I am doing the right thing in correctly setting CHX-I up... :)
    BTW, thanks so much for the links. I didn't realize there is so much information in the CHX-I forum. The forum is defaulted to show only the threads in the last 1 month, so I didn't realize there are other useful threads in there... :)
     
  15. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,456
    Glad that works fine to you... ;)
     
Thread Status:
Not open for further replies.