This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall Disabled?

Hi!

SESC 9.5 firewall is telling me that it's deactivated but it appears to work? Since a few days I have this strange thing that the tray bar icon is indicating a yellow exclamation mark. The tooltip tells me that the firewall configuration is letting through all data traffic. In the SESC 9.5 GUI the firewall entry says "deactivated", active location: "primary".

I tried to reconfigure the firewall but in the fw config menu the checkbox for "allow all data traffic" is disabled for the primary location. I haven't configured any secondary location.

This all started a few days ago after the update for the engine was distributed. I haven't installed it and just hibernated my win xp for several days. But then suddenly, there was a message telling me the system wanted to connect to my local network on 192.168.178.255 on UDP port 137 what I initially disallowed. It followed another alert for a connection to another LAN computer on UDP port 55400 which I disallowed, too. But then the internet connection didn't work any more so that I restarted the system. Nevertheless, this activated the SESC update but didn't solve the connection block so that I removed both firewall rules.

After another restart I got the UDP 137 alert again and allowed it as well as the UDP 55400 to the LAN computer. Now, the internet connection works again. The firewall says it has been disabled but it still prompts me from time to time with HTTP-connection requests from the SVCHOST-Service which I generally block by adding new rules each time. So the firewall appears to work from my point of view and I don't get the impression that all data traffic is going through.

What is this all about? As anyone experienced the same issue or has anybody an idea how to solve it?

Thanks in advance,

Holger

:5838


This thread was automatically locked due to age.
Parents
  • Hi Marc!

    In addition to Christian's reply regarding the meaning of the exclamation mark I can provide you with my solution. This only will suit your needs if you are facing the same "firewall disabled issue" as me.

    I downloaded the latest sophos av version from our university's web server, cut the physical network connection and removed the old installation by the windows control panel. Then I reinstalled the new version, performed a full virus scan and reconnected physically afterwards. This helped to keep the exclamation mark away for a week or two but then it reappeared with the same information "firewall disabled".

    A few weeks later there was an automatic update of the executable files of the av engine and after these have been replaced, the exclamation mark disappeared. After the restart, however, it was there again.

    However, I still believe that the firewall is working as is being pointed out by the list of blocked connections attemps. I am running in interactive mode and at every system restart, I get a request from windows media sharing service for example. I assume that something in my system configuration makes the fw believe that all connections are open. I did a tcpview and everything seemed to work fine.

    Holger

    :11855
Reply
  • Hi Marc!

    In addition to Christian's reply regarding the meaning of the exclamation mark I can provide you with my solution. This only will suit your needs if you are facing the same "firewall disabled issue" as me.

    I downloaded the latest sophos av version from our university's web server, cut the physical network connection and removed the old installation by the windows control panel. Then I reinstalled the new version, performed a full virus scan and reconnected physically afterwards. This helped to keep the exclamation mark away for a week or two but then it reappeared with the same information "firewall disabled".

    A few weeks later there was an automatic update of the executable files of the av engine and after these have been replaced, the exclamation mark disappeared. After the restart, however, it was there again.

    However, I still believe that the firewall is working as is being pointed out by the list of blocked connections attemps. I am running in interactive mode and at every system restart, I get a request from windows media sharing service for example. I assume that something in my system configuration makes the fw believe that all connections are open. I did a tcpview and everything seemed to work fine.

    Holger

    :11855
Children
No Data