Re: Firewall Setup...

From: Alan Illeman (illemann_at_surfbest.net)
Date: 04/02/04


Date: Thu, 1 Apr 2004 20:33:59 -0500


"Duane Arnold" <notme@notme.com> wrote in message
news:XP1bc.160700$po.953163@attbi_s52...
>
> "Global_Killa" <global_killa@hotmail.com> wrote in message
> news:c4i5ml$8bp$1@newsg1.svr.pol.co.uk...
> > Hey all,
> > I've been wondering for a while what svchost.exe application on my
> > Windows XP is used for. I have to set a firewall rule for this
application
> > everytime I format my computer, and I don't really know what I should
> allow
> > it to do.
> >
> > The programs location is C:\Windows\system32\svchost.exe. If I block
this
> > program from accessing the Internet, it seems to stop Internet activity.
> >
>
> As you can see, blocking svchost.exe stops your machine from accessing the
> Internet.

It doesn't in my case. Using Kerio, 'Network Security' I have denied both
Trusted in/out' and 'Internet in/out' access. In 'System Security' I permit
it
to 'Start', not to 'Modify', and permit 'Launching others'.

>From my logs, I seem to be getting a lot of TCP 'attacks' on svchost.exe,
through local port 135, which is categorized as "epmap" DCE endpoint
resolution. So without knowing what DCE is, maybe they are not 'attacks'
at all :)



Relevant Pages

  • Inside to Inside NAT
    ... I'm trying to configure my c837 to use inside-to-inside NAT, but I'm not getting anywhere, and everywhere I've looked on the Internet regarding this problem seams to tail off without resolve... ... deny ip 172.16.0.0 0.15.255.255 any ... permit icmp any any echo-reply ...
    (comp.dcom.sys.cisco)
  • Re: Win XP ICF - permit all traffic from one IP address?
    ... The firewall doesnt affect IPX traffic, ... > and connect directly to the Internet via a DSL ... > Now I would really like to have Internet Connection ... > way to add the equivalent of a "PERMIT ALL FROM IP ...
    (microsoft.public.security)
  • Svchost.exe - program security - inbound/outbound
    ... an ADSL connection and my firewall (Norton Internet ... Security 2003) is always running. ... "A remote system is attemtping to access Microsoft ... Permit [other choices are "block" ...
    (microsoft.public.security)
  • IPSECPOL filters
    ... ports which my WIN2K box adertizes out on the Internet. ... inbound and outbound traffic to the local network NT4 ... r "permit icmp" ... After assigning this policy, everything spcifically ...
    (microsoft.public.win2000.security)
  • Re: [JOSHIDIOCY] Joshs Idiocy
    ... Hey, that's MY line! ... You are too much of a stupid liar to permit yourself Internet ...
    (misc.writing)