Two Plus Two Newer Archives  

Go Back   Two Plus Two Newer Archives > Other Topics > Computer Technical Help
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 12-01-2006, 05:01 PM
BiPolar_Nut BiPolar_Nut is offline
Senior Member
 
Join Date: Aug 2006
Location: Slightly over the edge
Posts: 1,590
Default Need firewall recomendation - special requirements

I need a software firewall meeting the following requirements:

Must run on Windows Server 2k3
Must be configurable to allow inbound Terminal Services traffic immediately upon installation.

The second criteria is causing me headaches. I will be installing via a remote desktop session and I do not have physical access to the machine. Both Sygate and Comodo will install fine on 2k3, but neither seem to allow any configuration until after the system is rebooted (Sygate won't run until rebooted, and Comodo won't allow rules to be added, and even setting Comodo to "allow all" doesn't work because that setting is not saved, apparently...at least not after the installer runs and before rebooting)...at which point it's too late because inbound connections are blocked at that point.

Although it's trivial to open the necessary ports while sitting in front of the machine after the reboot that completes the install process, I need to be able to do it from a Terminal Services session (which obv must be unblocked prior to rebooting).

Using 2k3's built-in firewall is not an option.

Thanks!

(Other firewall programs I've looked at do not run on 2ks so pls verify your suggestion is 2k3-computable before posting)
Reply With Quote
  #2  
Old 12-01-2006, 05:25 PM
Dementia Dementia is offline
Senior Member
 
Join Date: Sep 2006
Location: new york
Posts: 1,585
Default Re: Need firewall recomendation - special requirements

Sygate firewall pro is the only thing I use bro. [img]/images/graemlins/frown.gif[/img]
Reply With Quote
  #3  
Old 12-01-2006, 05:42 PM
Freakin Freakin is offline
Senior Member
 
Join Date: Sep 2004
Posts: 6,022
Default Re: Need firewall recomendation - special requirements

i don't suppose you have remote access to the console through VGA over IP available to you? That would kinda make it easy.

What about finding out where sygate or comodo save config settings and putting the file in place immediately after installing them?
Reply With Quote
  #4  
Old 12-01-2006, 05:55 PM
BiPolar_Nut BiPolar_Nut is offline
Senior Member
 
Join Date: Aug 2006
Location: Slightly over the edge
Posts: 1,590
Default Re: Need firewall recomendation - special requirements

[ QUOTE ]
i don't suppose you have remote access to the console through VGA over IP available to you? That would kinda make it easy.

What about finding out where sygate or comodo save config settings and putting the file in place immediately after installing them?

[/ QUOTE ]

I've checked for config files in both and registry entries for sygate...as best I can tell the config is stored in .dat files but aren't clear text (and may even be encrypted)...guess I'll fire up the hex editor and see if that yields any clues.

Will also try a default config, save it, add a rule, then run a diff. I was just hoping someone knew a pre-configurable product instead of going through all that trouble.

Thanks for trying! Will post the trip report if I get it working.
Reply With Quote
  #5  
Old 12-01-2006, 06:20 PM
BiPolar_Nut BiPolar_Nut is offline
Senior Member
 
Join Date: Aug 2006
Location: Slightly over the edge
Posts: 1,590
Default Re: Need firewall recomendation - special requirements

.dat files seem to be encrypted [img]/images/graemlins/frown.gif[/img] (in sygate...haven't re-tried Comodo yet)
Reply With Quote
  #6  
Old 12-01-2006, 06:50 PM
BiPolar_Nut BiPolar_Nut is offline
Senior Member
 
Join Date: Aug 2006
Location: Slightly over the edge
Posts: 1,590
Default Re: Need firewall recomendation - special requirements

Apparently, two files are used for storing each "advanced rule" in Sygate, but I found another problem that's a deal-breaker.

Sygate won't display the popups on a terminal service session, nor can you bring up the configuration.

Off to trying comodo again.
Reply With Quote
  #7  
Old 12-01-2006, 07:32 PM
Freakin Freakin is offline
Senior Member
 
Join Date: Sep 2004
Posts: 6,022
Default Re: Need firewall recomendation - special requirements

[ QUOTE ]
Apparently, two files are used for storing each "advanced rule" in Sygate, but I found another problem that's a deal-breaker.

Sygate won't display the popups on a terminal service session, nor can you bring up the configuration.


[/ QUOTE ]

configure RDP to connect to console. that may get around it
Reply With Quote
  #8  
Old 12-01-2006, 07:59 PM
BiPolar_Nut BiPolar_Nut is offline
Senior Member
 
Join Date: Aug 2006
Location: Slightly over the edge
Posts: 1,590
Default Re: Need firewall recomendation - special requirements

[ QUOTE ]
configure RDP to connect to console. that may get around it

[/ QUOTE ]

That would prolly work...currently back on comodo on the test server at the moment tho...looking like it stores configuration in one large file as opposed to sygate's multiple files. I like the multi-file setup better.
Reply With Quote
  #9  
Old 12-03-2006, 09:40 PM
'Chair 'Chair is offline
Senior Member
 
Join Date: Jun 2006
Posts: 833
Default Re: Need firewall recomendation - special requirements

[ QUOTE ]
[ QUOTE ]
configure RDP to connect to console. that may get around it

[/ QUOTE ]

That would prolly work...currently back on comodo on the test server at the moment tho...looking like it stores configuration in one large file as opposed to sygate's multiple files. I like the multi-file setup better.

[/ QUOTE ]

bingo...make your own msi installation file.
Reply With Quote
  #10  
Old 12-03-2006, 09:48 PM
BiPolar_Nut BiPolar_Nut is offline
Senior Member
 
Join Date: Aug 2006
Location: Slightly over the edge
Posts: 1,590
Default Re: Need firewall recomendation - special requirements

[ QUOTE ]
bingo...make your own msi installation file.

[/ QUOTE ]

This is something I have never considered. I've never made .msi's before so I'm not sure what I'd be getting in to but without a doubt it could come in handy in many situations (like pushing out software via AD that hasn't been msi-packaged). I'll check into that. Thanks!
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 12:27 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.