Vista FW outbound check



Hi,
Vista FW with advanced security comes with an outbound traffic default setting "allow everything which is not denied". I think this is completely useless, because the main reason for outbound traffic filter is to block UNKNOWN programs (worm, trojans ....) so it is impossible to make a rule to deny an unknown program/destination port. On the other hand if I change the outbound setting to "block everything that does not match a rule" it is nearly impossible to design a rule for legitimate programs because, as far as I understand, there is no "display notification" for outbound breaking rule, and it is not simple to know applications/services/ports of the majority of legitimate applications (apart from browser mailer and few others).
My question is: is there a way to have a kind of display notification of the outbound offended rule with applications/services/ports of the offending programs?
Thanks in advance
Riccardo

.


Quantcast