Firewall Sygate

Are there any decent firewalls for Windows. I use Sygate right now, but i can't block on incoming SYN which is a royal pain, because my parents forget to click "NO" and instead click "YES". This is because every time some idiot tries to connect to a port above 1024 a box pops up. I have blocked all ports below 1024 (so nothing pops up, i've allowed emule, bit-torrent) but i can't do that for the higher order ports. If i could differentiate between TCP flags i would have the perfect firewall in Sygate!

I have tried Sygate which is close to nirvana and Kerio/ZoneAlarm/Agnitum-Outpost/McAfee. I want a firewall and nothing more. No DLL super-special thingjamig or a spyware goopergipper etc. Just a plain firewall with a nice powerfull and simple interface. I should be able to backup my rules.

And please don't suggest Linux (I already use that, but my apps don't all run on it) or a hardware firewall ( i have a old cyrix but power consumption! ). I know that software firewalls are terribly insecure etc but they meet all my requirements perfectly (except the SYN block). I NEVER run weird and wonderfull apps; all my apps are dl'd from trusted sites. I use Firefox so it's unlikely that i'll get infected via yahoo(java).

My DSL modem has a firewall (SYN block) feature but i use it in bridged mode so it refuses to work; It's a Huawei MT800.

One other worrying thing about Sygate; a couple of friends and myself noticed that Sygate shuts down sometimes at night. It exits completely for no rhyme or reason (worm?). I've now enabled block all network traffic if firewall exits and set a password, however i don't beleive anyone can connect to Sygate from outside?

Reply to
Vivek.M
Loading thread data ...

You've got something weird going on there. Sygate won't prompt for any incoming TCP unless you have something listening on that/those ports. It will automatically block unsolicited inbound traffic. So I'd suggest you look at what's running on that machine and listening on those ports.

Again, it sounds more like your machine is compromised.. I'd do some serious scanning and try to find out what's going on there. Either that, or wipe it clean and reformat/reinstall, which always takes care of any problems for sure...

Reply to
Kerodo

Forget Sygate. Just use the Windows-Firewall. Popups are a b0rken concept, as you can see.

BTW: the correct answer on a SYN is RST, if the port should be "closed".

Yours, VB.

Reply to
Volker Birk

I get a lot of popups for "Services and Controller App" port 1026; Any idea what ports above 1024 are to be blocked? What port range does win 2000 allot to outgoing apps (firefox/thunderbird etc)

I doubt it; the incidents occured at different machines and at different times; mine and 3 other friends with a gap of a few months (only once, in each case). I'm not saying it's impossible that the machines were infected, just that it has to be via Sygate or through Sygate. I'm not sure how though..It doesn't happen now that i've enabled both the password and disable network on exit options.

Reply to
Vivek.M

I'm sorry, should have mentioned that i am on Windows 2000. I'm trying to block incoming SYN since there is no earthly reason why someone should want to connect to a port above 1024. I run no server apps except emule and bit-torrent.

Are there any software firewalls for windows, that do just firewall-ing and have the SYN-block feature? Something like Sygate which is neat, clean and minimal. A hardware device is ruled out - I live in Bangalore, India and don't have the same range of choices that you would have ( interpret that as expensive ).

Reply to
Vivek.M

This does not make any difference.

Usually, you don't need a firewall, if you're not offering network services. Then the RST is sent by Windows' kernel.

formatting link
As an alternative for a host based packet filter, you could just configure the packet filter in Windows' kernel, or using this:

formatting link
Yours, VB.

Reply to
Volker Birk

I had no clue that there was a IPFW1 port to Windows :) :) :) :) This is most excellent!! How do you pronounce your name? My own parents generally tend to holler at the top of their lungs when they need me, so the VeeeeeWaaaaake sort of works out..otherwise it's just Vee-Wake..Anyway many thanks!

I shall keep you posted on the install and perhaps post my cfg information for future newbies.

Reply to
Vivek.M

You could also just forward the port since RDP is encrypted -- however, keep in mind that it's only 128 bit and not all data is encrypyed.

formatting link

-Gary

Reply to
Kerodo

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.