This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall Disabled?

Hi!

SESC 9.5 firewall is telling me that it's deactivated but it appears to work? Since a few days I have this strange thing that the tray bar icon is indicating a yellow exclamation mark. The tooltip tells me that the firewall configuration is letting through all data traffic. In the SESC 9.5 GUI the firewall entry says "deactivated", active location: "primary".

I tried to reconfigure the firewall but in the fw config menu the checkbox for "allow all data traffic" is disabled for the primary location. I haven't configured any secondary location.

This all started a few days ago after the update for the engine was distributed. I haven't installed it and just hibernated my win xp for several days. But then suddenly, there was a message telling me the system wanted to connect to my local network on 192.168.178.255 on UDP port 137 what I initially disallowed. It followed another alert for a connection to another LAN computer on UDP port 55400 which I disallowed, too. But then the internet connection didn't work any more so that I restarted the system. Nevertheless, this activated the SESC update but didn't solve the connection block so that I removed both firewall rules.

After another restart I got the UDP 137 alert again and allowed it as well as the UDP 55400 to the LAN computer. Now, the internet connection works again. The firewall says it has been disabled but it still prompts me from time to time with HTTP-connection requests from the SVCHOST-Service which I generally block by adding new rules each time. So the firewall appears to work from my point of view and I don't get the impression that all data traffic is going through.

What is this all about? As anyone experienced the same issue or has anybody an idea how to solve it?

Thanks in advance,

Holger

:5838


This thread was automatically locked due to age.
Parents
  • Hello Holger,

    the exclamation mark should correctly indicate the setting of Allow all traffic (after clicking Apply). If it doesn't "follow" your setting then something's not working as it should.

    I assume your configuration is (or should be) Interactive. Is your PC managed by SEC and if, what are the policy settings? And how is your PC connected to the outside world? UDP 137 is NetBIOS which shouldn't affect "the internet connection" (what exactly means didn't work anymore?).

    Christian

    Edit: Thought about it on my way home yesterday. 192.168.178.255 is a broadcast address so it's probably your computer searching for "something" (shares) on the LAN. The svchost to port 80 is related - it's Windows "falling" back to WebDAV when NetBIOS doesn't work.

    Excuse me for saying so but it looks like you are trying to configure SCF by trial and error. This won't work as it seems your computer needs some resources from the LAN (which exactly, I can't tell). Maybe you should start all over (there's a Restore Defaults button).

    Another one - if the icon still incorrectly reports the state you should consider un-/reinstalling SCF.

    Christian

    :5851
Reply
  • Hello Holger,

    the exclamation mark should correctly indicate the setting of Allow all traffic (after clicking Apply). If it doesn't "follow" your setting then something's not working as it should.

    I assume your configuration is (or should be) Interactive. Is your PC managed by SEC and if, what are the policy settings? And how is your PC connected to the outside world? UDP 137 is NetBIOS which shouldn't affect "the internet connection" (what exactly means didn't work anymore?).

    Christian

    Edit: Thought about it on my way home yesterday. 192.168.178.255 is a broadcast address so it's probably your computer searching for "something" (shares) on the LAN. The svchost to port 80 is related - it's Windows "falling" back to WebDAV when NetBIOS doesn't work.

    Excuse me for saying so but it looks like you are trying to configure SCF by trial and error. This won't work as it seems your computer needs some resources from the LAN (which exactly, I can't tell). Maybe you should start all over (there's a Restore Defaults button).

    Another one - if the icon still incorrectly reports the state you should consider un-/reinstalling SCF.

    Christian

    :5851
Children
No Data