Recommended Posts

Having used Sygate for years until it was bought over and killed by Symantec I then moved to Core Force. Sadly neither are in development or work with Windows 7.

If anyone could recommend a good alterative (Free or Feeware) it would be a great help?

It must have -

  • The ability to open inbound / outbound ports to specific applications and protocols

  • Have a secure setting that blocks everything and prompts for access via popup that can be selected to "remember" the setting

  • The ability to port forward i.e. 80 to 8080 inbound

  • Ideally not have any other junk installed with it, i.e. AV, Malware Scanner etc

  • Ideally not have a gui thats desiged for idiots that dont know what a firewall really can do.

So far the closest thing I've found in Zone Alarm Pro (Free does some of the above). I wasnt a fan of Tinywall or Comodo either.

Anyone got any tips please?

"The ability to port forward i.e. 80 to 8080 inbound"

So this software also has to do NAT? or are you using the built in internet sharing for this?

I would never in a million years connect my windows 7 box directly to the internet - it would be behind my border router/firewall, I currently run pfsense on VM. It provides all the firewall features you could need.

Host firewalls have there uses to be sure, for boxes that roam to different networks - but stationary computers, I see little need of host firewalls unless the network they are connected to is hostile.

Its much easier to manage your network at the border, use of IPS if so desired -- The built in firewall seems more than sufficient as a host based firewall if you ask me. You will find that most of these software/host firewalls cater to selling to the uneducated and use scare tactics to sell their product.

I am curious if your using your windows7 box as your border device or is it behind a nat router already? The use of the term port forward lends me to believe its your router/gateway to boxes behind it?

"The ability to port forward i.e. 80 to 8080 inbound"

So this software also has to do NAT? or are you using the built in internet sharing for this?

I would never in a million years connect my windows 7 box directly to the internet - it would be behind my border router/firewall, I currently run pfsense on VM. It provides all the firewall features you could need.

Host firewalls have there uses to be sure, for boxes that roam to different networks - but stationary computers, I see little need of host firewalls unless the network they are connected to is hostile.

Its much easier to manage your network at the border, use of IPS if so desired -- The built in firewall seems more than sufficient as a host based firewall if you ask me. You will find that most of these software/host firewalls cater to selling to the uneducated and use scare tactics to sell their product.

I am curious if your using your windows7 box as your border device or is it behind a nat router already? The use of the term port forward lends me to believe its your router/gateway to boxes behind it?

God no its not directly on the net, it sits behind a hardware fw in a different segment. Its just internally I dont like to open standard ports (when I can avoid it) sorry i guess I should have said 8080 to 80 on a one-to-one relationship rather than NAT one-to-many for example.

TBH the main reason I want a host FW is to be able to block specific applications from having internet access but still having local network access on my "lan". The moment someone writes an agent that can sit on a host and set the config on a dedicated FW to block src, dst, port and application (executable) I'd buy it straight away rather than have multiple host fws with different policies etc.

Currently im in the middle of trying to get an ESXi box built so I can do pretty much exactly what your doing with something better than the cr@p FW built into the router, but still doesnt get round my .exe requirement.

Hope this makes this a little clearer?

"8080 to 80"

What? That is still a forward on a nat.. If its just the host, then you would have the application listen on said port ;) Or you would have your border router forward 8080 to 80 to your box listening on 80, etc.. That statement still makes no sense.

As to blocking exe -- I fail to see a reason this is ever required other than circumvention of some phone home licensing scheme.

If you don't want something talking on the net, then you shouldn't be running said exe in the first place. Once a exe runs all is lost to be honest, what keeps said exe you ran from just turning off said firewall and or opening up the ports it needs on the local firewall. Sure a firewall can keep legit software from talking on the net, but its not a valid security method for preventing malware, etc. You don't run the malware in the first place is the idea ;)

So are there hostile boxes on your local network segment? If not - I still not seeing the need for host firewall. All of mine are off -- it makes management more difficult for no reason. My network is secure at the trust border (internet) All devices are trusted and managed/secured by me that are on my network - ports that would be used in transfer from one machine to another machine if a worm did get in are open anyway. Since I file share between machines. Services I do not use are not running in the first place. I only run software that I trust, and have a IDS running so that if for say any weird exe did slip through and started sending weird traffic I would be notified, etc.

Good luck in your search, but the firewall that came with your box is more than sufficient for a host firewall. Why should you trust or think that some 3rd party could hook into the OS better than the maker of the OS?? I never got that mentality. Funny how in the linux world there is no firewall prevents exe from talking on the net. They all just do what they should do an block protocol and ports, or you can block a specific userid - I don't know of one that works on say a hash of the exe that is trying to talk on the network. Now you could secure the box with SELinux or use Apparmor and lock down applications from doing things they should not do - but that is not a firewall. In windows you could use applocker, part of the OS to limit what exe can run in the first place. This seems like a better approach then letting the exe run - and then either blocking or allowing its network access. What I have seen with these sorts of firewalls is the user just allows everything that pops up, or they block stuff that they should be allowing ;) Have seen where they blocked box from being able to get dhcp address or even lookup up dns because they did not understand what some exe was doing.

I have been asking for years and years around here for an example of why you need to block exe from talking to the network, when said exe is something you choose to run in the first place. If not something you choose to ran, blocking it from talking to the network is pointless and a defeatist attitude in security. Now if you want to lock your box down to NOT run applications you have not ok'd, I get that - and that is good policy. But trying to just block network access and allow anything that you click on to run or that tries to run on its own is looking at it the wrong way if you ask me.

edit: Here is something that might help, you seem interested in something that tells you what is trying to go outbound, and then allowing you to block or allow said application. Take a look at this - this uses just the built in firewall to accomplish what your after

http://www.howtogeek.com/113641/how-to-extend-the-windows-firewall-and-easily-block-outgoing-connections/

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Oh man, but what if I have the PS3 version?
    • Floorp 12.15.0 by Razvan Serea Floorp is a cutting-edge web browser that combines the trusted foundation of Mozilla's Firefox with a unique Japanese perspective, offering users an exceptional online experience. This open-source browser prioritizes privacy, customization, and security. Floorp is transparent, with no user tracking or data sharing, and it's completely open source. With a strict no-tracking policy and full transparency, your personal information remains private. As an open-source project, Floorp not only shares its source code but also its build environment, inviting users to contribute and build their unique versions. The regular updates, based on Firefox ESR, ensure that you always have the latest features and security enhancements. Floorp key features: Strong Tracking Protection: Floorp offers robust tracking protection, safeguarding users from malicious tracking and fingerprinting on the web. Flexible Layout: Customize Floorp's layout to your heart's content, including moving the tab bar, hiding the title bar, and more for a personalized browsing experience. Switchable Design: Choose from five distinct designs for the Floorp interface, and even switch between OS-specific designs for a unique look Regular Updates: Based on Firefox ESR, Floorp receives updates every four weeks, ensuring up-to-date security even before Firefox's releases. No User Tracking: Floorp prioritizes user privacy by abstaining from collecting personal information, tracking users, or selling user data, with no affiliations with advertising companies. Completely Open Source: The full source code for Floorp is open to the public, allowing transparency and enabling anyone to explore and build their own version. Dual Sidebar: Floorp features a versatile built-in sidebar for webpanels and browsing tools, making it perfect for multitasking and quick access to bookmarks, history, and websites. Flexible Toolbar & Tab Bar: Customize your browser with Tree Style Tabs, vertical tabs, and bookmark bar modifications, catering to both beginners and experts in customization. User-Centric Web Experience: Floorp prioritizes user privacy and collaboratively blocks harmful trackers. Floorp 12.15.0 changelog: Refine appearance of Start top sites and Hub sidebar by @CutterKnife in #2435 Improvement command pallete by @Walkmana-25 in #2429 Fix gesture command by @Walkmana-25 in #2425 Add Mac OS formatting for modifier keys in shortcut editor by @Walkmana-25 in #2424 refactor: bridge as little by @nyanrus in #2416 fix(pwa): follow Firefox 150 ShellService API changes (Bug 1985098) by @Ryosuke-Asano in #2409 feat(notes): Desktop向けThree-Way Merge Sync実装 by @Ryosuke-Asano in #2402 fix(pages-settings): resolve Invalid Hook Call error in SortableContext by @Ryosuke-Asano in #2350 README: fix signpath avatar url by @CutterKnife in #2453 Enhance command palette with new actions by @Walkmana-25 in #2449 feat(split-view): implement tab drop functionality with overlay and new window zone by @Ryosuke-Asano in #2445 fix: restore 'Hide Interface', 'Toggle Navigation Panel', and 'Rest Mode' keyboard shortcuts by @Ryosuke-Asano in #2458 fix: prevent unified extensions panel from closing on bottom navbar (#2079) by @Ryosuke-Asano in #2462 fix: prevent workspace system from overriding SessionStore tab selection on startup by @Ryosuke-Asano in #2461 fix: prevent multi-row tabs from disappearing when sidebar opens website by @Ryosuke-Asano in #2460 fix: prevent private container tab from saving first page to history by @Ryosuke-Asano in #2459 fix: prevent browser close when container tab is the only tab open by @Ryosuke-Asano in #2465 Resolve conflicts for #2467: Add split-view mouse gesture commands by @Ryosuke-Asano in #2472 fix(os-server): auto-generate auth token on enable by @Ryosuke-Asano in #2471 fix(settings): change broken link to Floorp Docs by @regularentropy in #2477 Enhanced search functionality in the command palette — now supports English keywords, Japanese morphological analysis, and hiragana search by @Walkmana-25 in #2470 fix(patches): align Gecko patches with Linux CI runtime by @Ryosuke-Asano in #2482 feat(pwa): add Firefox Container support for PWA apps by @Ryosuke-Asano in #2443 fix(statusbar): add event listener for buttons in status bar by @greeeen-dev in #2484 Download: Floorp 64-bit | 95.0 MB (Open Source) Links: Floorp Website | Github Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Google Gemini co-lead Noam Shazeer is leaving for OpenAI by Pradeep Viswanathan Noam Shazeer is best known as one of the co-authors of the 2017 “Attention Is All You Need” paper, which introduced the Transformer architecture that now powers most large language models. He also worked on several major Google AI projects, including LaMDA, before leaving the company in 2021 to co-found Character.AI. He also authored the Sparsely-gated Mixture of Experts (2016) paper, which is popular among the AI community. After falling behind OpenAI and Anthropic a couple of years ago, Google brought Shazeer back in 2024 as part of a major deal with Character.AI. Through this deal, along with Noam, several other researchers returned to Google DeepMind. More recently, he was a vice president of engineering at Google and a technical co-lead for Gemini. Today, Noam Shazeer announced on X that he is leaving Google and joining OpenAI. In his post, Shazeer said it was a difficult decision to move on, adding that he was proud of the Google team and what it had built together. OpenAI CEO Sam Altman welcomed the move with a post of his own, saying Shazeer was one of the people he had most wanted to work with since OpenAI’s early days. Google has made strong progress with Gemini over the past year, closing the gap with OpenAI in several areas. But losing Noam Shazeer is a major talent setback for them, especially after bringing him back less than two years ago by spending a fortune. For OpenAI, the hire adds one of the industry’s most experienced language model researchers to a team that is already pushing ahead with ChatGPT, Codex, and its next generation of frontier models.
    • I'm lost too... what did you mean by your first comment then?
  • Recent Achievements

    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
    • Week One Done
      Harris Gilbert earned a badge
      Week One Done
    • One Month Later
      Vincian earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      541
    2. 2
      +Edouard
      171
    3. 3
      PsYcHoKiLLa
      85
    4. 4
      ATLien_0
      64
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!