windows 7 firewall

General Network security, firewalls, port filtering/forwarding, wireless security, anti-spyware, as well as spam control and privacy discussions.
Post Reply
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

windows 7 firewall

Post by id1x »

hi , i havnt been using any firewalls on xp because i dont surf the net much often
and i didnt want to slow down my internet with it .

but am thinking about what to do in windows 7 . is the integrated firewall any good?
i can always use the zone alarm free edition which means disabling win7 firewall services .

do i really need firewalls at all ? and what do u recommend using if i do ?

i have one on my router also but its disabled by default and i couldnt figure out its
settings so i left it disabled

so far i have only AVG free edition installed and i disabled windows 7 defender

Image
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

Yes you need one and it doesnt slwo your net down.

Turn on the routers NAT feature and enable windows firewall, thats really all you need, but you do need it, no matter how little you are on the net.

EDIT: And don't disable windows defender, drop AVG and get Microsoft security essenials or Avira Antivir, either virus program is better than AVG and is lighter on the system.
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

yes but Microsoft security essentials refused to work along with defender
and had disabled it !!

can u teach me haw to set my router firewall please ? when i click on firewall i see this

IP Filtering

This page allows you to specify the IP packet filtering rules to prevent the services accessed from the Internet hosts or limit the Internet access for local hosts.

enable disable

and nat has nothing to do with it .
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

Dont worry about IP filtering as long as NAT is enabled.

Just noticed that my defender is disabled as well, ddint notice that at first when I installed MSE.
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

MSE disables Defender because it takes its place, it has a bit of Defender in it already, plus quite a bit more.
MORNING WOOD Lumber Company
Guinness for Strength!!!
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

Image

Image

Image

here is haw things looks . what do u mean by enable nat ? i dont see that
option .

and in fire wall when i click enabled it shows those 2 boxes out bound traffic
and inbound traffic . and IGMP proxy . haw should i set these things ? thanks
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

There's usually no "enable or disable NAT" function with home grade routers. That's how they work, in gateway mode..using NAT, it's what your basic hardware firewall protection is. You don't want to disable it, it's a good thing.

If you have do let services through NAT, you do it via port forwarding.
MORNING WOOD Lumber Company
Guinness for Strength!!!
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

ok i dont think i understand anything from all this .

can u just tell me what to do in those screen shots to enable my firewall thanks ?
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

u keep telling me wrong thinks . first about defender then u keep saying enable nat
and nat dosnt have enable option
what is gateway mod and so on . am new and u dont look like someone who
likes to help
am leaving this web site . :irate:
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

Maybe you should explain what you to accomplish with ip filtering?

A router with NAT makes for a basic or simple firewall, good enough for home users.

IP Filtering is just going to open ports to pass through the router, its not going to enable any firewall like feature.
User avatar
akbarri
Posts: 935
Joined: Tue Dec 30, 2008 4:21 pm
Location: Caterpillar Inc

Post by akbarri »

- do i really need firewalls?
- recommended firewall?
- how to set router firewall?
- how to set router firewall > IP Filtering?

how we can help if we dont understand ur main purpose?

ur scrshoot's too small!

# OS: Windows, Linux # Browser: Blink, Gecko, Presto, Webkit + Squid + Bind
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

these are thumbs if u click them and go to imgshake u can see full size
strange u donr know that already
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

well i just want to enable the router fire wall properly . i understand the rest of the
question u said
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

id1x wrote:well i just want to enable the router fire wall properly . i understand the rest of the
question u said
Well with no Disable/Enable option for NAT, the router is most likely functioning as a basic firewall now.

http://www.speedguide.net/scan.php

Click the Start button and let the page load. Does the scan come back with your ports being open closed, or filtered?
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

Total scanned ports: 309
Open ports: 1
Closed ports: 0
Filtered ports: 308

1863/tcp open unknown

http://www.speedguide.net/port.php?port=1863
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

So its already filtering your ports, the router is acting as a basic firewall for you. Not sure why 1863 is open with nothing listed in IP filtering, but if you are worried about the worm, run malwarebytes to clean up anything running on your system.

http://www.malwarebytes.org/
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

YeOldeStonecat wrote:There's usually no "enable or disable NAT" function with home grade routers. That's how they work, in gateway mode..using NAT, it's what your basic hardware firewall protection is. You don't want to disable it, it's a good thing.

If you have do let services through NAT, you do it via port forwarding.
A router can be basically set into one of 2 modes: NAT routing or Bridge mode.

In NAT routing mode, your router receive the WAN IP address from your ISP and creates a Local Area Network (LAN) and assign an internal LAN IP address to your computer, usually in the format 192.168.xx.xx

In Bridge mode, the routing function is turned off and your computer receive the direct WAN IP address issued by your ISP. Thus, your computer is exposed directly to the internet.

If you want to learn more about how NAT routing acts like a firewall, try reading through this link:

http://www.grc.com/nat/nat.htm
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

maybe windows MSNP (Microsoft Notification Protocol), used by the .NET Messenger Service and a number of Instant Messaging clients (official)

is using it ? it cant be a malware i have done 3 clean installed yesterday on different
partition and they gave same result .

anyway u recommend keeping this setting ? and using ip filtering for Outbound traffic

thanks
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

trogers wrote:
If you want to learn more about how NAT routing acts like a firewall, try reading through this link:

http://www.grc.com/nat/nat.htm

thanks but u are talking to a total nob here . i just want to see haw to
enable my router firewall if its any good .
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

i made this test and tested all common and services ports and all were stealth i dunno
why ure test showed that port opened

https://www.grc.com/x/ne.dll?bh0bkyd2

GRC Port Authority Report created on UTC: 2010-03-19 at 18:23:58

Results from scan of ports: 0-1055

0 Ports Open
0 Ports Closed
1056 Ports Stealth
---------------------
1056 Ports Tested

ALL PORTS tested were found to be: STEALTH.

TruStealth: PASSED - ALL tested ports were STEALTH,
- NO unsolicited packets were received,
- NO Ping reply (ICMP Echo) was received.

GRC Port Authority Report created on UTC: 2010-03-19 at 18:27:36

Results from scan of ports: 0, 21-23, 25, 79, 80, 110, 113,
119, 135, 139, 143, 389, 443, 445,
1002, 1024-1030, 1720, 5000

0 Ports Open
0 Ports Closed
26 Ports Stealth
---------------------
26 Ports Tested

ALL PORTS tested were found to be: STEALTH.

TruStealth: PASSED - ALL tested ports were STEALTH,
- NO unsolicited packets were received,
- NO Ping reply (ICMP Echo) was received.
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

Hmmmm, thats a good question. I shall ask the man with the answers to share this thoughts here.
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

u mean the first most evil ? :rtfm:
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

id1x wrote:u mean the first most evil ? :rtfm:
Nope, :p

The man that runs the site, Philip. I sent him a pm and linked this thread to see if he can shed some light on it.
User avatar
Philip
SG VIP
Posts: 11699
Joined: Sat May 08, 1999 5:00 am
Location: Jacksonville, Florida

Post by Philip »

Seems that the GRC scan simply does not scan port 1863, that's why it showed no open ports. There are 65535 tcp and 65535 UDP possible ports, different sites choose to scan a different subset of all those (common vulnerabilities, most often open ports, etc.), since a full scan takes too much time and resourses.

Port 1863 is most commonly used by MSN Messenger, there are also a couple of worms/trojans that use it: http://www.speedguide.net/port.php?port=1863
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

i did that scan after a clean install . maybe its a flow in windows messenger .

anyway so if my ports are stealth dose that means i am protected ?
do i still need a software firewall ?
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

GRC Port Authority Report created on UTC: 2010-03-20 at 16:42:30
Port
Status Protocol and Application

1863
OPEN! msnp
MSNP




Results from probe of port: 1863

1 Ports Open
0 Ports Closed
0 Ports Stealth
---------------------
1 Ports Tested

THE PORT tested was found to be: OPEN.

TruStealth: FAILED - NOT all tested ports were STEALTH,
- NO unsolicited packets were received,
- NO Ping reply (ICMP Echo) was received.


yes ure right msn protocol that means am not the only one with that port
open . so what do u recommend for me as a final solution
i dont want outbound protection just inbound so am i ok with that
nat and that port open ?
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

id1x wrote: anyway so if my ports are stealth dose that means i am protected ?
do i still need a software firewall ?
Yes, you are protected.
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

ok great thanks . now i will turn windows 7 firewall and those services
off . would that be ok ?

Internet Connection Firewall (ICF)

* Application Layer Gateway Service
* Internet Connection Sharing (ICS)
# Base Filtering Engine
# IKE and AuthIPsec Keying Modules

# IPsec Policy Agent
# Routing and Remote Access
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

Base Filtering Engine Cand be disabled.

Application Layer Gateway Service
IKE and AuthIPsec Keying Modules
IPsec Policy Agent

Those should be left on or set to manual.

And Internet connection Firewall I would leave on.
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

YARDofSTUF wrote:Base Filtering Engine Cand be disabled.
.

u mean can or cant ? sorry but that would be my final question and thanks
a lot for setting my system .
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

id1x wrote:u mean can or cant ? sorry but that would be my final question and thanks
a lot for setting my system .
Ya, I meant cant, or shouldn't, guess I combined those. lol


A good guide to services:

http://www.blackviper.com/Windows_7/servicecfg.htm
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

but it was that web that recommended disabling win firewall and those
services if i have a router firewall



http://www.blackviper.com/Windows_7/Ser ... rewall.htm

so u got me confused again :confused:
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
User avatar
akbarri
Posts: 935
Joined: Tue Dec 30, 2008 4:21 pm
Location: Caterpillar Inc

Post by akbarri »

id1x wrote:but it was that web that recommended disabling win firewall and those
services if i have a router firewall

http://www.blackviper.com/Windows_7/Ser ... rewall.htm

so u got me confused again :confused:
Win Firewall vs Router Firewall => Software Firewall vs Hardware Firewall

Just make ur Firewall 2 Layers :
1st Defence, Hardware Firewall (Router Firewall)
2nd Defence, Software Firewall (Win Firewall / 3rd Party Software)

http://www.speedguide.net/faq_in_q.php? ... 102&qid=64

# OS: Windows, Linux # Browser: Blink, Gecko, Presto, Webkit + Squid + Bind
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

yes i got what u mean from the start its just at that web they said something difrent than u said :

If you use an external hardware firewall/gateway/router between your computer and the internet, do not use IPsec (VPN tunneling, etc) and Internet Connection Sharing (ICS), then this service and the following group of services can be disabled:

* Base Filtering Engine
* IKE and AuthIPsec Keying Modules
* Internet Connection Sharing (ICS)
* IPsec Policy Agent
* Routing and Remote Access
* Windows Firewall


i have read that web before i asked u but when advised me to use it , i got confused
but i will keep those services on like u said . wont be using 3rd part s/w


i got another problem now :

i got my isp dns numbers working fine with xp but in windows 7
it says dns servers are not responding . when i used
a public dns server it worked . what should i do ?
i asked the isp company they said its better that i ask you .
maybe i can give them feed back . thanks



Image
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

On that same article you link it says it recommends not disabling the windows firewall.

As for the DNS, what type of connection do you have DSL/Cable? Have you tried leaving it on obtain ip/dns automatically?
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

aha i didnt see the recomended . ok then

i have adsl and am used to set it at xp cause it dosnt work on auto
but no i didnt try to leave it at auto with win7 ill try and see if it works
it works .

should i uninstall anything in the connection properties such as clients
or so ? or just leave it as it is? :rolleyes:
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
id1x
Member
Posts: 27
Joined: Tue May 19, 2009 8:22 am

Post by id1x »

YARDofSTUF wrote: As for the DNS, what type of connection do you have DSL/Cable? Have you tried leaving it on obtain ip/dns automatically?
that didnt work . i put down my DNS anyway and it worked despite
the error message . when i use that new public dns it works normally
maybe they are behind all that . i would use them but they kinda take
over my browser some times and i dont like that .
E8500/9800 GTX+/4 gb kingston ddr2 800/ P5Q Pro/WD caviar Black 750GB/Corsair tx 750W/ SUMO 5115/SAMSUNG 2333SW lcd/win7 64bit home premium.
Post Reply