Re: Win xp sp2 firewall



Volker Birk wrote:
Mr. Arnold <"Mr. Arnold"@arnold.com> wrote:

At most, the application would say that an unauthorized program was trying to access the Internet, that you the user didn't approve. I am not a proponent of Application Control in PFW(s) but at least ask me.


This is ridiculous.

I personally know which programs I have on my computer. So I don't need
to be asked by one of those programs about others. I'm just configuring
them all.

So do I. I know what's running on my machines both MS and Linux, which are setting behind a Watchguard running no PFW/personal packet filters on the MS platforms or host based FW on Linux platform. I do have one running on the laptop when it's not on my network, otherwise, it's disabled.


With a typical home user, this may be different. But she/he will not be
able to answer such questions correctly.

Yeah, I agree.


So already the basic idea of "application control" is completely
nonsense.

You tell it to someone that doesn't know. But the fact is that at least some kind or warning flag is raised to them. While in the meantime, the XP FW is doing nothing.


If I don't want to be asked, then I'll disable it. But don't *you* the PFW start making rules, because I installed an application on the computer.


If you don't know what you're doing, try to see yourself as home user.
Maybe it's better for you to buy a Macintosh and let Apple do the job,
if Windows is too complicated for you.

Well it's not a problem for me, period. I have been in the IT field since 1971 and coming to this NG since 2000. I absolutely know what's happening, believe it.


And MS and its PFW somehow knows the intent and knows the correct decision to make?


No. And because of this, Windows-Firewall is behaving like designed and
documented.

A designed and documented program doesn't mean a thing, when the over all design concepts of the XP FW as a program/PFW doesn't fit the bill in some areas.


PFW, will you please prompt someone about what you're about to do?


Why?

That's because the buck stops with me and not the PFW or XP's FW.

I make the decisions as to what is going to happen on my machines, period. For those that do know what they are doing, that's not a problem. You prompt me PFW and if I don't want it to happen, then PFW don't you do it. If I want it to happen, then I'll let you do it PFW, if I have that feature enabled.

If someone doesn't know what's happening, then they don't know prompt or no prompt, period. But again, don't you PFW start doing something in setting rules that I don't know about. I want to be informed about what you're doing or have a chance of being informed, if that's enabled.

The XP FW has none of it, period. And again, the buck stops with me not the XP FW, if I happen to be using it.


You just don't understand, that when you're configuring a program as
network listener, it's a good idea not to filter that away again. Or
just don't configure this.


Oh, I more than understand and you can count on it.

BTW, the one PFW/personal packet filter I do use, which is on my laptop and is enabled when it's not on my network, has Application Control disabled, because I absolutely know how to go and look for myself as to what's running on them and happening with my machines, with the proper tools.

.



Relevant Pages

  • Re: Firewall yes, but where?
    ... The PFW solutions do have a ... Control that can be fooled. ... A real firewall has some specific characteristics ... people do use a PFW solution on a gateway computer as well, ...
    (comp.security.firewalls)
  • Re: Recommend a free firewall or stick with xp?
    ... > I've ran my XP box with XP SP2 Firewall, Kerio, ZA, and Sygate and it ... > has nothing to do with being smart or not you arrogant dorks. ... Just believe in the "control" you get. ... here is you to believe in the power of control the PFW gives you. ...
    (comp.security.firewalls)
  • Re: Firewall newbie! Which free one??
    ... that it can detect because it's running, which is not even a FW function the beloved App. ... Actually, I don't care about app control, I care about port control, and I want the PFW to tell me what is in/out in real time. ...
    (comp.security.firewalls)
  • Re: Zonealarm driving me crazy.
    ... of who is "calling home" so to speak. ... That's not true and as a matter of fact, on the lone machine that I have a PFW solution running on it, a dial-up computer laptop, the App Control or phone home feature is disabled. ...
    (comp.security.firewalls)