Re: Password vault software



"Ed" wrote in message news:q%Fxi.57$JD.27@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx

So are you saying that you have never heard of personal software firewalls? If not, time to get one. Get one with outbound control, like application rules. Then you can decide which applications can make Internet connections and which cannot.

Comodo's firewall is top-rated amongst the free personal firewalls.


Thanks. I use a Netgear FM114P firewall router so I assume that
a software firewall would be redundant. I'll take a look at it and
see if I can disallow particular programs for Internet access.

Firewalls in a personal router cannot provide application rules. That's because the application (and its processes) aren't running on the router. Router firewalls can provide some outbound control, like on protocols, IP or MAC addresses, time of day, IP name/address censoring, etc. They don't know what application generated what traffic that is going out through them.

If you want to control which applications can connect OUT from the host on which they execute, get a software firewall that runs on THAT same host. Very nasty malware can circumvent firewalls but you aren't talking about malware.

Didn't find an "FM114P" listed at netgear.com but did find "FR114P". They mention "Network Software (e.g. Windows)". Is that a software firewall that runs on each intranet host? Or is that just some local app to provide a web-based interface to their router device? I saw no mention of app rules (or inclusion of IPS to control what process can call what program to make the connection). I did a very cursory scan of the manual at ftp://downloads.netgear.com/files/FR114P_FR114W_FM114P_RefGuide.pdf but still saw nothing to control which applications (and their caller processes) would be allowed a network connection, to what target sites, for which ports, and for what protocols.

For example, with your Netgear router, how would you prevent the wgatray.exe program from connecting to Microsoft when you start Windows? (I actually stop it from loading by using an IPS, like System Safety Monitor, but used to block its connection attempt in the Comodo firewall.)




.



Relevant Pages

  • Re: VPN that passes firewall?
    ... Since you don't control the router, your best bet would be to use a product like GotoMyPC or Crossloop. ... These will work through firewalls and with dynamic addresses. ... A VPN end point router would not be suitable if you have to connect it to the landlords router which you can't control). ... In both locations, there is internet access but I do not have direct control of the router/firewall. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Help with finding hardware firewall that acts like software firewall
    ... level but do not truly control things as per specific program executable. ... They are basically filtering the application data within the packets. ... protection provided by some of the personal firewalls, ... > responsible for using a specific port or ports. ...
    (comp.security.firewalls)
  • Re: Cannot ping ADSL from external
    ... My phone line has a microfilter plugged into it then a 30m cable going to my Netgear DG834 router. ... The router should be able to map the external address/port combination to an internal address/port if you configure it properly. ... The home routers also act as "stateful packet inspection" firewalls which means that incoming traffic is blocked by default unless the connection was initiated from inside the firewall. ...
    (comp.os.vms)
  • Accessing systems behind uncontrolled firewall
    ... I want to be able to access these machines via SSH if nothing else. ... Two firewalls are controlled by "the guy upstairs" who was fired for computer services in favor of hiring someone else. ... Hence I have zero control and can open nothing for unsolicited outside connections. ... My general idea is to have the servers I am building open up some kind of a tunnel automatically to my home via SSH, PPTP, IPsec, whatever, and use that to pipe data back and forth. ...
    (comp.os.linux.setup)
  • Re: [fw-wiz] IPv6 support in firewalls
    ... back to the firewalls: ... with reusable credentials and you pretty-much kill the idea of document ... control at all, let alone keeping the honest people honest or a credential ...
    (Firewall-Wizards)