Zonealarm free firewall

Discussion in 'other firewalls' started by The Red Moon, Mar 30, 2013.

Thread Status:
Not open for further replies.
  1. SnowFlakes

    SnowFlakes Registered Member

    Joined:
    Jun 29, 2011
    Posts:
    194
    thank you for the info.
    It maybe have HIPS but not as good as other, (maybe)
     
  2. SweX

    SweX Registered Member

    Joined:
    Apr 21, 2007
    Posts:
    6,429
    Oki doki :)
     
  3. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    I am at home so should i change the default ZA FW Zones from the installed Trusted Settings for my Home Network and DHCP Server to The Public setting.
     
  4. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    Why would you set your LAN and DHCP to Internet (public)?
    Your LAN start with 192.168....? In other words... do you have a router?
     
  5. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    Should i lock my Hosts File in ZA FW Settings.
     
  6. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    I have a router so i guess the public setting is for home Wireless which i don't use now.
     
  7. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    Does the Hosts File have something to do with the DNS. I use OpenDNS so if i change my DNS i would have to unlock it.
     
  8. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    Then, the default (trusted) is fine when you are at home (wireless or not). :thumb:
    If you want to prevent the access by anyone or anything to the hosts file then tick that option.
    If opendns use hosts file to work then better not to lock it.
     
  9. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    To modify general security settings:
    Select COMPUTER | Advanced Firewall and click Advanced Settings.
    In the General area, choose your security settings.
    Block all fragments
    Blocks all incomplete (fragmented) IP data packets. Hackers sometimes create fragmented packets to bypass or disrupt network devices that read packet headers.
    Caution: If you select this option, ZoneAlarm security software will silently block all fragmented packets without alerting you or creating a log entry. Do not select this option unless you are aware of how your online connection handles fragmented packets.
    Block trusted servers
    Prevents all programs on your computer from acting as servers to the Trusted Zone. Note that this setting overrides permissions granted in the Programs panel.
    Block Internet servers
    Prevents all programs on your computer from acting as servers to the Public Zone. Note that this setting overrides permissions granted in the Programs panel.
    Enable ARP protection
    Blocks all incoming ARP (Address Resolution Protocol) requests except broadcast requests for the address of the target computer. Also blocks all incoming ARP replies except those in response to outgoing ARP requests.
    Allow VPN Protocols
    Allows the use of VPN protocols (ESP, AH, GRE, SKIP) even when High security is applied. With this option disabled, these protocols are allowed only at Medium security.
    Allow uncommon protocols at high security
    Allows the use of protocols other than ESP, AH, GRE, and SKIP, at High security.
    Lock hosts file
    Prevents your computer’s hosts file from being modified by hackers through sprayer or Trojan horses. Because some legitimate programs need to modify your hosts file in order to function, this option is turned off by default.
    Disable Windows Firewall
    Detects and disables Windows Firewall.
    Filter IP over 1394 traffic
    Filters FireWire traffic. You will need to restart your PC for these filter changes to take effect.
     
  10. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    With ZA FW in dafault settings i was getting resolving hosts messages with Chrome and computer slowed down a lot. No more resolving messages and normal speed back after changing Public Zone to Medium Setting.
     
  11. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    Is your LAN and DHCP set as trusted in the ZA firewall zones and your "trusted zone" set to MEDIUM?
    EDIT: If the above is already true then ensure your DNSs IPs are included in the firewall zones as TRUSTED.
     
    Last edited: Oct 20, 2013
  12. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    So i should add a Trusted Zone for both OpenDNS IP's
     
  13. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    Yeap :thumb: ... and set Internet zone back to default. Safer...
    Even tough you still have the router facing the internet.
     
  14. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
  15. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    Nothing new under the sun... :)

    However, the author seems to forget that there is basically no difference in a software firewall and a hardware firewall other than the latter running on a dedicated hardware and software firewall also able to monitor outbound connections.

    So, bugs and crappy packet filtering can also happen on the mentioned routers brand which I, by chance, had the opportunity to use ;)
     
  16. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    I just updated to ZoneAlarm Free 12.0.121.000 from 11.0.768 and things did not go good. After restart i could not get to the internet and the background was close to frozen. Had to restart in safe mode and uninstall it then restart and install 768 again.
     
  17. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    When jumping between major version releases (e.g. 11 to 12) you should first fully remove the old before installing the new.
    Start fresh with clean setup. This will solve the problem unless you have specific third party applications in conflict with ZA12 ;)
     
    Last edited: Feb 15, 2014
  18. Sm3K3R

    Sm3K3R Registered Member

    Joined:
    Feb 29, 2008
    Posts:
    611
    Location:
    Wallachia
    So from time to time it gets new stuff ? :)
    Usually stays unchanged for many years in spite of version evolution.

    What is new in the new ?
     
  19. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
  20. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I've finally checked it out, and I already said it a couple of months ago, but the GUI is totally ruined.

    There is no fast way to see the rules in "program control", what a bunch of morons! :gack:
     
  21. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    The GUI the same since version 10 and program control too... This means been the same for the last 3 or 4 years :)
    And program rules are not in the free version... Only retail

    Of course, to each it's own...
     
  22. Amin

    Amin Registered Member

    Joined:
    May 16, 2012
    Posts:
    437
    Location:
    UK
    The free version totally sucks :( :thumbd:
     
  23. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    Yeah, of course.. very useful and in-depth insight, LoL :D
     
  24. Amin

    Amin Registered Member

    Joined:
    May 16, 2012
    Posts:
    437
    Location:
    UK
    FYI What I meant wasn't the protection but GUI and user-friendliness, and yes I insist, it sucks.

    in 'application control' tab inside 'application control settings' window you can only see one option under 'Advanced control' section and that would be "Enable Microsoft Catalog utilization" !! :blink:

    So simply I can say they literally don't know the meaning of "advanced" :thumbd:
     
  25. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    Yeap, that's normal. ZAfree does not include any advanced firewall controls and for applications you cannot setup specific rules (e.g. opening ad-hoc ports) but only broader controls on inbound Y/N /outbound Y/N + server rights Y/N + suspicious behaviour (basic HIPS).

    More advanced controls (specific rules for application or more granual controls) are only available in retails versions of the product. :)

    On the GUI, well as the latins says "De gustibus non est disputandum". I know users that likes it very much this and other that hate it...

    Of course, there are indeed plenty of free options aside ZA that do the job you are looking for. So, just use those... ;)

    For example, if you are obsessed by limiting/controlling at a very granular level the trusted applications running on the PC then ZA is not for you. If you instead just need a simple to use firewall that will warn you about "unknowns" or "unrecognised" components active in the system then, yes, it can do that.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.