Log in

View Full Version : SP3 Success - Need new firewall


Reece
06-09-08, 09:12 PM
First off thanks to all who helped me to persist with installing SP3, the cause of the BSOD was ZoneAlarms "TrueVector Internet Monitor" service.:yep:
This leaves me now with no firewall, I don't like microsoft's firewall so I was wondering about Sygate, can anyone advise me on what this is like or suggest a better alternative, the less services running though the better!:yep:
Many Thanks.

kiwi_2005
06-09-08, 09:22 PM
Sygate Personal FW or Tiny Personal FW are both free and pass leak tests. I would say they're good freebies. Comodo FW is another good freebie.

Reece
06-09-08, 09:44 PM
yes it seems that Sygate was taken over by Symantec and not free anymore, this version I downloaded from Tucows & is version 5.6 (2004), I might give it a go, better search for some docs on it first.:yep:

kiwi_2005
06-09-08, 10:04 PM
yes it seems that Sygate was taken over by Symantec and not free anymore, this version I downloaded from Tucows & is version 5.6 (2004), I might give it a go, better search for some docs on it first.:yep:

Your right, just googled damn Norton took it over:nope: typical.

Skybird
06-09-08, 10:17 PM
Advice from this forum lead me to Comodo, which is not only a free but downgraded or limited version, but the full version which no longer is on sale, but went to no charges and is regularly updated. All features are included. not just some (like Zonealarm Free). Behavior and handling is a bit different, but one gets used to it.

Recommended! Use Google.

Reece
06-09-08, 10:57 PM
Your right Skybird:
http://www.personalfirewall.comodo.com/download_firewall.html
Free, have downloaded but which to choose from, I will need to do a little research on this, I know with ZoneAlarm I couldn't get on the net with broadband till I made a few adjustments, the thing is once I'm offline that's it, I'm on my own!:yep:
Thanks.

Skybird
06-09-08, 11:09 PM
Once installed, you need to set (via icon ion task bar, down right corner), the "Firewall Security Level" to customm Policy Mode, and the "Defense + Security Level" to Safe Mode for all normal activity. The firewall of course needs to learn the software behavior of all that you have installed, and will do that whenever somethign gets called up the first time. This could lead to an annoying ripplefiring of confirmation - and choice boxes as long as you haven't set the Defense+Security Level to "Training Mode", where the alarms will be silent, and the firewall will assume that you really want the components you have started to be carried out undisturbed by the fireewall. So whenever you starts words or a game for the first time, or when you install something!!! - set it to Training Mode. Do not forget to reset it to Safe Mode when having finished, and even more so when connecting to the web.

After a short time, once the wall has learned your software habits, you will not be harmed by alarms anymore, and usually adjuist the security leveol only when in stalling new software, becasue every software installer is understood to be new software and thus alarms the Firewall, so for installing: switch to training mode, and also during the first ever-run of new software.

Reece
06-09-08, 11:35 PM
Well due to the fact that I can't find any docs & is no longer supported I think I will give Comodo a try, the popups you describe when an app is accessing the net is the same on ZoneAlarm when first installing so quite used to it,:yep: I will take some notes on the settings in ZoneAlarm first, they may help. No use puting it off, time to take the plunge, since I had to re-ghost to get here I have to clean up the system, install SP3, then setup the net, maybe awhile before I post again.:doh: A little nervous!:oops::yep:
Cheers.

Skybird
06-10-08, 12:00 AM
I had zonealarm before, until it caused me problems, so I know how it handles and behaves. some things work differently in Comodo. the popup thing I told you because this one was very different between the two, in Zonealarm you could filter alarms easier. In fact, by interface I like Zonealarm better, it is easier to exclude a software from web activity, for example, in Comodo you need to install an individual software policy for each item, but as long as no special things are being wished for, Comodo interface all in all works okay. The security standard I checked with online test-sites, and it passed them all and proved to fully stealthen the system - completely.

Reece
06-10-08, 01:04 AM
OK, I'm back, little white shield on the taskbar shows a red flash everynow and then, the only popup I've had is when the modem was turned on & asked if this network was a trusted zone, so far firefox & outlook just connected, no popups! but I assume this is correct, they show in the traffic box.:yep: I'll wait awhile before switching on the ethernet hub to my wifes PC, thanks Skybird, I know it was a little naughty but I didn't check the Defence+ or Leak Protection, only the basic firewall, can't seem to find a list of programs that I can mark as trusted or don't allow, maybe you can point me straight to it,:yep: for example adobe reader just popped up wanting to update, I don't want this. Cheers.
I think it's the "Network Security Policy" screen.:-?

Skybird
06-10-08, 01:20 AM
can't seem to find a list of programs that I can mark as trusted or don't allow,

I alrready touched that topic, but maybe did not make myself clear enough: a list of software where you just tick and untick the titles quickly, like in Zonealarm, Comodo does not have - for any exception from the basic rules you control via the general setting accessible in the task bar (or the rules you have created when allowing or forbidding action in the pop up windows) you need to create an individual item policy describing what this item should be able to do and what not. At least that'S what I found out, maybe I am wrong, since I am no expert for Comodo - I set it up, got it running, tuned it to "tight", and did not care for any of the additonal options it has. The help-centre is build into the software, you can find it all there, so open the main screen, and go right there.

Skybird
06-10-08, 01:23 AM
You can check wether or not your ports are shut and stealthed by using the options available here:

http://www.grc.com/x/ne.dll?rh1dkyd2

Under "All Service Ports" you wish to have nothing but green lights.

Reece
06-10-08, 01:36 AM
Whoops I posted at the same time (edited post #10), ok it does have a sort of file list in the "Network Security Policy" section, I will have to do as you say though & "Define a New Blocked Application" for each program, I don't want things like games trying to access the net! I have tried setting the Network Security Policy - Global Rules to block outgoing requests, see what that does!:yep:
This will take awhile to work out but seems quite good so far!:up:

Skybird
06-10-08, 01:40 AM
I did not trust into the firewall successfully blocking games to access the web, too, like you, but learned meanwhile that it reliably does that. You can leave it to the automatic learning, just deny any requests in popup windows, and after some time your major software pool is covered, and you have your peace then. and really - no need to spend the time working so hard with it. Leave it to the software, and it will serve its purpose.

I meanwhile got the impression that Comodo really outshines Zonealarm, at least the free version of it.

If you spend the time nevertheless, do not forget to export and save your settings and options afterwards to an external file. There is an option for that somewhere. Else you need to do it again when reinstalling your system.

Reece
06-10-08, 01:59 AM
do not forget to export and save your settings and options afterwards to an external file. There is an option for that somewhere. Else you need to do it again when reinstalling your system. Thats good to know, I will search for that now, thanks,:yep: Seems the link you provided just displays a page error.

jumpy
06-10-08, 06:25 AM
I used ZA Pro for ages, but when my last subscription expired I just turned the window$ firewall on instead. Granted I run through a router before connecting to the internet, as well as having a software firewall, but since then I've never had any 'issues' related to infection or instability or resource hogging. I seem to recall some versions of ZA used to add to boot time.

I liked the layout of ZA and how you could see all of the permissions and stuff, but everything seems to work ok without it :-?

lesrae
06-10-08, 06:37 AM
Granted I run through a router before connecting to the internet, as well as having a software firewall, but since then I've never had any 'issues' related to infection or instability or resource hogging.

Ditto for me, no problems with the Microsoft one.

Arclight
06-20-08, 09:47 AM
I've been using Comodo for a while now, only issue I ever had was getting ICS to work properly so other PC's on my network could actually connect. No problem setting it up, but after reboot the settings seemed to have been erased, requiring everything to be set up again. Fairly anoying.

"Fixed" it by not running the internet connection through my PC, but instead to a switch and then to each individual PC. Downside is that every PC needs to run it's own protection (and no networking), but that's just minor. Never had any infections of any kind while using Comodo firewall + defense shield.

Never really made any changes to the options, when a program tries anything you get a pop-up. You can allow, block or specify a policy for it then and there.

SUBMAN1
06-20-08, 10:08 AM
First off thanks to all who helped me to persist with installing SP3, the cause of the BSOD was ZoneAlarms "TrueVector Internet Monitor" service.:yep:
This leaves me now with no firewall, I don't like microsoft's firewall so I was wondering about Sygate, can anyone advise me on what this is like or suggest a better alternative, the less services running though the better!:yep:
Many Thanks.Use Comodo. The likes of Tiny seem to be leaky. ZoneAlarm was never a good choice.

The MS one is fine if you don't care about whats going out, just whats coming in.

-S