Recommended Posts

Having used Sygate for years until it was bought over and killed by Symantec I then moved to Core Force. Sadly neither are in development or work with Windows 7.

If anyone could recommend a good alterative (Free or Feeware) it would be a great help?

It must have -

  • The ability to open inbound / outbound ports to specific applications and protocols

  • Have a secure setting that blocks everything and prompts for access via popup that can be selected to "remember" the setting

  • The ability to port forward i.e. 80 to 8080 inbound

  • Ideally not have any other junk installed with it, i.e. AV, Malware Scanner etc

  • Ideally not have a gui thats desiged for idiots that dont know what a firewall really can do.

So far the closest thing I've found in Zone Alarm Pro (Free does some of the above). I wasnt a fan of Tinywall or Comodo either.

Anyone got any tips please?

"The ability to port forward i.e. 80 to 8080 inbound"

So this software also has to do NAT? or are you using the built in internet sharing for this?

I would never in a million years connect my windows 7 box directly to the internet - it would be behind my border router/firewall, I currently run pfsense on VM. It provides all the firewall features you could need.

Host firewalls have there uses to be sure, for boxes that roam to different networks - but stationary computers, I see little need of host firewalls unless the network they are connected to is hostile.

Its much easier to manage your network at the border, use of IPS if so desired -- The built in firewall seems more than sufficient as a host based firewall if you ask me. You will find that most of these software/host firewalls cater to selling to the uneducated and use scare tactics to sell their product.

I am curious if your using your windows7 box as your border device or is it behind a nat router already? The use of the term port forward lends me to believe its your router/gateway to boxes behind it?

"The ability to port forward i.e. 80 to 8080 inbound"

So this software also has to do NAT? or are you using the built in internet sharing for this?

I would never in a million years connect my windows 7 box directly to the internet - it would be behind my border router/firewall, I currently run pfsense on VM. It provides all the firewall features you could need.

Host firewalls have there uses to be sure, for boxes that roam to different networks - but stationary computers, I see little need of host firewalls unless the network they are connected to is hostile.

Its much easier to manage your network at the border, use of IPS if so desired -- The built in firewall seems more than sufficient as a host based firewall if you ask me. You will find that most of these software/host firewalls cater to selling to the uneducated and use scare tactics to sell their product.

I am curious if your using your windows7 box as your border device or is it behind a nat router already? The use of the term port forward lends me to believe its your router/gateway to boxes behind it?

God no its not directly on the net, it sits behind a hardware fw in a different segment. Its just internally I dont like to open standard ports (when I can avoid it) sorry i guess I should have said 8080 to 80 on a one-to-one relationship rather than NAT one-to-many for example.

TBH the main reason I want a host FW is to be able to block specific applications from having internet access but still having local network access on my "lan". The moment someone writes an agent that can sit on a host and set the config on a dedicated FW to block src, dst, port and application (executable) I'd buy it straight away rather than have multiple host fws with different policies etc.

Currently im in the middle of trying to get an ESXi box built so I can do pretty much exactly what your doing with something better than the cr@p FW built into the router, but still doesnt get round my .exe requirement.

Hope this makes this a little clearer?

"8080 to 80"

What? That is still a forward on a nat.. If its just the host, then you would have the application listen on said port ;) Or you would have your border router forward 8080 to 80 to your box listening on 80, etc.. That statement still makes no sense.

As to blocking exe -- I fail to see a reason this is ever required other than circumvention of some phone home licensing scheme.

If you don't want something talking on the net, then you shouldn't be running said exe in the first place. Once a exe runs all is lost to be honest, what keeps said exe you ran from just turning off said firewall and or opening up the ports it needs on the local firewall. Sure a firewall can keep legit software from talking on the net, but its not a valid security method for preventing malware, etc. You don't run the malware in the first place is the idea ;)

So are there hostile boxes on your local network segment? If not - I still not seeing the need for host firewall. All of mine are off -- it makes management more difficult for no reason. My network is secure at the trust border (internet) All devices are trusted and managed/secured by me that are on my network - ports that would be used in transfer from one machine to another machine if a worm did get in are open anyway. Since I file share between machines. Services I do not use are not running in the first place. I only run software that I trust, and have a IDS running so that if for say any weird exe did slip through and started sending weird traffic I would be notified, etc.

Good luck in your search, but the firewall that came with your box is more than sufficient for a host firewall. Why should you trust or think that some 3rd party could hook into the OS better than the maker of the OS?? I never got that mentality. Funny how in the linux world there is no firewall prevents exe from talking on the net. They all just do what they should do an block protocol and ports, or you can block a specific userid - I don't know of one that works on say a hash of the exe that is trying to talk on the network. Now you could secure the box with SELinux or use Apparmor and lock down applications from doing things they should not do - but that is not a firewall. In windows you could use applocker, part of the OS to limit what exe can run in the first place. This seems like a better approach then letting the exe run - and then either blocking or allowing its network access. What I have seen with these sorts of firewalls is the user just allows everything that pops up, or they block stuff that they should be allowing ;) Have seen where they blocked box from being able to get dhcp address or even lookup up dns because they did not understand what some exe was doing.

I have been asking for years and years around here for an example of why you need to block exe from talking to the network, when said exe is something you choose to run in the first place. If not something you choose to ran, blocking it from talking to the network is pointless and a defeatist attitude in security. Now if you want to lock your box down to NOT run applications you have not ok'd, I get that - and that is good policy. But trying to just block network access and allow anything that you click on to run or that tries to run on its own is looking at it the wrong way if you ask me.

edit: Here is something that might help, you seem interested in something that tells you what is trying to go outbound, and then allowing you to block or allow said application. Take a look at this - this uses just the built in firewall to accomplish what your after

http://www.howtogeek.com/113641/how-to-extend-the-windows-firewall-and-easily-block-outgoing-connections/

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • ImgDrive 2.2.7 by Razvan Serea ImgDrive is a CD/DVD/BD emulator - a tool that allows you to mount optical disc images by simply clicking on them in Windows Explorer. If you have downloaded an ISO image and want to use it without burning it to a blank disc, ImgDrive is the easiest way to do it. ImgDrive features: One-click mounting of iso, cue, nrg, mds/mdf, ccd, isz images Runs on 32-bit and 64-bit Windows versions Mount ape, flac, m4a, wav, wavpack, tta file as AUDIO CD (16-bit/44.1kHz) Mount a folder as DVD/BD Mount images in command line Does not require rebooting after installation Support up to 7 virtual drives at the same time Support multi session disc image (ccd/mds/nrg) A special portable version is available Translated to more than 10 languages Support File Type: .ccd - CloneCD image files .cue - Cue sheets files of ape/flac/m4a/tta/wav/wv/bin .iso - Standard ISO image files .isz - Compressed ISO image files .nrg - Nero image files .mds - Media descriptor image files ImgDrive 2.2.7 changelog: Added command line parameter to set number of drives Added AACS-Auth support for HD DVD Bumped kernel driver version to 2.2.7 Download: ImgDrive 2.2.7 | 692 KB (Freeware, paid upgrade available) Download: ImgDrive Portable 535 KB View: ImgDrive Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • AnyDesk 9.7.7 by Razvan Serea AnyDesk is a fast remote desktop system and enables users to access their data, images, videos and applications from anywhere and at any time, and also to share it with others. AnyDesk is the first remote desktop software that doesn't require you to think about what you can do. CAD, video editing or simply working comfortably with an office suite for hours are just a few examples. AnyDesk is designed for modern multi-core CPUs. Most of AnyDesk's image processing is done con­currently. This way, AnyDesk can utilize up to 90% of modern CPUs. AnyDesk works across multiple platforms and operating systems: Windows, Linux, Free BSD, Mac OS, iOS and Android. Just 7 megabytes - downloaded in a glimpse, sent via email, or fired up from your USB drive, AnyDesk will turn any desktop into your desktop in se­conds. No administrative privileges or installation needed. AnyDesk 9.7.7 fixes: Fixed an issue that prevented users from creating meetings without an active license Download: AnyDesk 9.7.7 | 8.0 MB (Free for private use, paid upgrade available) Links: AnyDesk Home Page | Other platforms | Release History | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • I used a Pixel 10 Pro XL when it first came out for about 8 months. When I first got it, it was using Google assistant and that was fast, when asking it to call somone etc. Then it automatically switched with some update to Gemini. Doing even the simplist of things like asking it to call someone in my contacts was soooooo slow compared to Google assistant. I guess it had to go out to the cloud to do that? Back on iPhone and while Siri is dumb right now, it does do those simple things, like call someone, set a timer, star the stop watch etc, really fast. That an while I like Google Material Design 3 over iOS 26, they Pixel 10 Pro XL was so slow in comparison to the iPhone 17 Pro I am using.
    • I use Gemini in my rotation of AI clients...that work pays for. It is good at most things, better than copilot for imgage searching and making images, worse at writing vs Claude and way worse at hadling technical issues when it comes to Azure stuff. I also use YT premium and maps. Anything else Google is a pass for me. I have now seen multiple people locked out of their Google accounts for reasons that are just very vauge.
    • Microsoft is building an AI datacenter that "uses less water than a fast food restaurant" by Ivan Jenic Image: Microsoft Microsoft has announced plans to build a new datacenter campus in Pecos, Texas, as the company continues to invest billions in AI infrastructure. The new facility, called project Kilby, will reportedly have a capacity of 2 gigawatts and will be one of the largest single capacity additions in the company’s history. To power the campus, Microsoft signed a 20-year deal with Chevron to supply natural gas from the Permian Basin, America's largest oil field. This deal is set to become the largest collaboration to date between a U.S. oil and gas giant and Big Tech. It’s no secret that Big Tech has often been criticized for exploiting natural resources for its AI developments. Microsoft is trying to mitigate some of that negative consensus by promising to build its own power supply for the new datacenter, independent of the public grid. The Pecos datacenter will be powered by a power plant hub, built by Chevron, with up to 2.5 gigawatts of gas-fired capacity, with potential to scale to up to 5 gigawatts. The facility will include at least seven GE Vernova turbines, with first power potentially coming online as early as late 2027 or early 2028. The power plant hub is part of an approximately $7 billion investment by Chevron, making it one of the largest dedicated energy projects tied to a single datacenter campus in the U.S. Microsoft hasn’t publicly disclosed the amount it’s investing in the new datacenter. Microsoft has also committed to implementing a closed-loop cooling system that will only require an initial water charge to operate. The company said that “the total lifecycle water use of this datacenter is only a fraction of that consumed annually by a typical fast-food restaurant.” What the press release doesn’t mention, however, is how much water the natural gas plant itself will consume, or how a 20-year fossil fuel commitment squares with the company's pledge to be carbon negative by 2030. The construction of the new datacenter should provide over 6,000 construction jobs at peak build-out, and create hundreds of operational job roles once the facility is built. Via: Reuters
  • Recent Achievements

    • Dedicated
      tuben earned a badge
      Dedicated
    • Week One Done
      mnsgroup earned a badge
      Week One Done
    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      525
    2. 2
      +Edouard
      199
    3. 3
      PsYcHoKiLLa
      94
    4. 4
      Michael Scrip
      82
    5. 5
      Steven P.
      67
  • Tell a friend

    Love Neowin? Tell a friend!