Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • E-Books
  • Lounge
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>LangaList Plus>Avoid firewall confusion with insider secrets

Avoid firewall confusion with insider secrets

Tweet

Mark edwards Firewalls are great tools, but some people find them a bit frustrating.

This week I explain a bit about firewall technologies, firewall performance, how to extract and use information from firewall logs, and how to remove a certain firewall if the need should arise.


How to uninstall the Comodo firewall

Several weeks ago in the Jan. 11 edition of this newsletter I mentioned Comodo firewall, which was recommended by one of our readers. Many of you tried it and found it to be problematic. Lloyd Lamouria wrote to share his experience:
  • “After seeing the recommendation about Comodo, I decided to try it. After half a day of unsuccessfully trying to get it to play nice with my system, I finally decided to uninstall it. After the uninstall, nothing worked. No Internet connection, nothing in the Control Panel would work, Firefox would not start, Spy Sweeper hung, etc. Had to resort to a system restore. After doing some research, a lot of others have had problems as well. Just a word of caution.”
Thanks for the warning, Lloyd. If any of you readers need help uninstalling Comodo, a thread in the Comodo Support forums mentions a standalone tool that can remove the firewall completely. You can download the tool from the forum, but be aware that you must be signed up for an account and be logged in to see the download link. If you don’t want to use your real e-mail address when signing up for an account, try using Mailinator for a temporary inbox.

What ‘stateful inspection’ means for you

There are two basic types of firewalls; one is a "stateless" filtering system, while the other is a "stateful" inspection system. Bill Norrie wrote to ask about this:
  • “I installed Comodo on my wireless laptop after reading the article in the Jan. 11 edition. However, I came across this information below on a forum and wonder if you would like to comment on it:
    • “Comodo is not a stateful firewall. It makes little difference how good Comodo does in the leaktests; it omits the one thing the firewall was originally invented for, and that’s keeping ALL intruders out at ALL times, not just when ports are closed and hidden. The only technology with this capability is SPI, which is why it’s the one you’ll find in a hardware firewall.”
Bill, whoever wrote the post you quoted is misinformed. Comodo is, in fact, a stateful inspection firewall.

A stateless filtering system is basically a system that filters data packets without any regard to why the packet is arriving at your computer. It performs its filtering based on a simple set of rules that govern whether packets are allowed in or not, and it bases its design on parameters such as desination port numbers, protocol types, etc.

Stateful packet inspection (SPI) also filters packets, similarly to a stateless system. But it does its work based on a table of "connection states," thereby offeringan added layer of protection.

For example, when your browser opens a connection to a Web site, the firewall makes a record of that connection and keeps track of the state of the connection — whether it’s open or closed, etc. Then, when a packet arrives at your computer, the firewall compares data in the packet to the firewall state table to determine if the packet was intended for any of the connections the firewall knows about. A stateful inspection system can also base its decisions on the actual data content of the packets it receives. Overall, stateful inspection makes for a stronger type of firewall.

Stateful inspection can slow down your system

In the previous item, I briefly explained stateful inspection, but what I didn’t discuss was how stateful inspection affects system performance. Adib Behi noticed a performance lag on his system and wrote to ask about it:

  • “Whenever there is a noticeable slowdown in response time on my system, I check Comodo and it reports a flurry of ‘Inbound Policy Violation.’ Most of the time, those violations come from the same few IP source addresses, mostly based in Australia or China.

    “I’m happy that Comodo catches them and prevents access. Now, since this attack happens a few times every second, sometimes with short delays of five seconds in between, I presume this may be causing the slowdown. I’m no techie or Internet wiz, but that’s the only odd activity that I see.

    This article is part of our paid content. Subscribe.

    Already a paid subscriber? Click here to login.

    Related posts:

    1. Outpost Firewall Updated
    2. Comodo Firewall: Friend or Foe?
    3. Firewall Incorrectly Blocks Local Traffic
    4. Promising New Free Firewall!
    5. Flaw in Kerio Firewall
= Paid content

All Windows Secrets articles posted on 2007-02-22:

  • Top Story Pop-up ads can land you in jail
  • LangaList Plus Make more space by deleting log files
  • Wacky Web Week Gollum and Smeagol get their groove on
  • LangaList Plus Avoid firewall confusion with insider secrets
  • Woody's Windows Vista Timesaver #4 — the Windows Experience Index
  •  Show all articles on a single page
E-books

We’ve pored through years of back issues, picking the best tips, to create these ebooks:

E-book series
  • PC Maintenance Guide
  • PC Security Guide
  • Windows 7 Guide Vol 1
  • Windows 7 Guide Vol 2
  • Win XP Survival Guide
See the e-book series
Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.53
  • The sorry tale of the (un)Secure Sockets Layer 4.42
  • RPV: Win7′s least-known data-protection system 4.33
  • Recovery: the last step in total data security 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Pros and cons of a ‘keyfile’ password 4.21
  • Beating back Duku and a plethora of other threats 4.21
  • Office 2007 gets its final service pack 4.19
  • Putting Registry-/system-cleanup apps to the test 4.19
  • One year and 99 security bulletins later 4.18
  • 1.8TB external drive goes down hard 4.17
  • Don’t pay for software you don’t need — Part 3 4.16
  • Internet Explorer gets another round of patches 4.15
  • Is your free AV tool a ‘resource pig?’ 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Remote access leads to remote attacks 4.15
  • Keeping you up to date: say no to .NET — again 4.14
  • Take control of Google’s privacy policy settings 4.14
  • Office File Validation patch leads to problems 4.14
  • The advanced system-recover toolkit 4.13
  • New “419″ scam involves PayPal and Western Union 4.12
  • Readers’ best personal-privacy tips 4.11
  • Getting the most from Windows Search — Part 2 4.11
  • Re-examining Dropbox and its alternatives 4.10
  • Don’t pay for software you don’t need — Part 2 4.10
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb