This is a read-only archive. No new posts or registrations. Privacy Page
Software

Win firewall

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello I don't know much about firewalls even after reading about them. I currently have the Windows firewall behind a router which I feel is secure as it is set to WPA - 2 with good passwords and keys. I recently got a Trojan which Windows Defender was able to remove from quarantine. I got it while reading about firewalls. Comodo is hard and difficult to remove, private firewall is hard too. I can't seem to find a relatively easy to use one which is good. Zone Alarm has no HIPS but monitors both ways however I don't know if it is worth using. My question is, although there is no outbound monitoring, would it be a sound idea to reset the firewall to default occasionally so that it would ask me if I want to allow programs rather than trying to set them when I don't know what I am doing? Thank you Peter

My question is, although there is no outbound monitoring, would it be a sound idea to reset the firewall to default occasionally so that it would ask me if I want to allow programs rather than trying to set them when I don't know what I am doing?

I don't know what you mean by no outbound monitoring. Windows Firewall is a two-way firewall, and an excellent firewall at that. Should you reset it if you don't know what you are doing? I think that would be a good idea regardless, then let Windows Firewall manage itself - it knows how, and is fully capable. All my Windows 7 systems here have been using Windows Firewall since first built over 3 years ago - with no problems. Windows Firewall is a good, solid, basic firewall. And that's all you need.

If you otherwise "practice safe computing", you will be fine. That is, if you, the user and always the weakest link in security:

Keep Windows updated and patched,
Use a decent, real-time and updated anti-malware solution and firewall,
AND
You don't invite the badguys in by participating in illegal filesharing via torrents or P2P,
You are not "click happy" with unsolicited downloads, attachments, links and popups.

I currently have the Windows firewall behind a router which I feel is secure as it is set to WPA - 2 with good passwords and keys.
I recently got a Trojan which Windows Defender was able to remove from quarantine.

Note WPA-2 only involves computers connected via wireless. Computers connected via Ethernet don't use wireless encryption. If you got a real Trojan, your anti-malware solution let it through. Firewalls block ports, they don't scan for malware.

I used ZoneAlarm for years with XP (never went to Vista) but it became too bloated, bogged down my system, and they kept trying to get me to into their whole security suite. So I went to Comodo when it started to make a name for itself. It had a high learning curve, and was heavy on resources. And they too tried to get me to into their whole security suite. :( In Oct 2009, W7 came out with a vastly improved firewall that is pretty much set and forget - assuming you practice safe computing - and I have been using that (and MSE) since, with no problems.

got a Trojan which Windows Defender was able to remove from quarantine

Remove from quarantine? What do you mean? The suspect file was already in quarantine? Or did you mean WD quarantined it?
Comodo is very good but very Techy, annoying to use and difficult to remove. The removal process has apparently improved since I last used it. By how much I don't know. I'd stick with the W7 firewall and not worry too much about the tech stuff. just let it do it's thing set on default. It was the XP firewall that only monitored inbound traffic and that is all I use when on XP. No problems, it works fine for my conservative web habits.

It was the XP firewall that only monitored inbound traffic and that is all I use when on XP.

I agree. All the hoops and hollers about the Windows Firewall in XP was blown way out of proportion by the anti-Microsoft crowd - fueled by the very aggressive ZoneAlarm marketeers.

The fears something might "call home" with your personal information totally ignored the fact the bad code first had to get to your machine on your network, past the incoming Firewall, past the anti-malware program on the way in, then become active and unnoticed by your anti-malware solution on the way out. :( Not an easy task if you kept your computer updated and stayed away from risky activities.

I too thought Comodo was too annoying and difficult. It worked, but way too much user involvement required.

The problem with XP's firewall is that it was not enabled by default. A decision made because when XP first came out, most home computers were not connected to a network/Internet (except maybe by dial-up modem). And most business computers were connected to a LAN, with IT support and a firewall through the "gateway server" or business class router.

No one, I mean really no one predicted how rapidly broadband to the home would spread resulting in an explosion of Internet use. And no one predicted how prolific the Internet would be for the badguys, or how easy it would be to exploits its gullible users. :(

In SP2, it was enabled by default - but remained one-way. Vista's Windows Firewall was two-way.
I read a tutorial in Win Tech that said to block all incoming traffic on private and public so I set the firewalls to default and followed that advice. We have been using the pcs most of the day without issue. ***I did not know the Win 8 native firewall was a two way firewall but that is great to hear! One person asked about quarantine - the Trojan was in Defender's quarantine so I removed it from there. I appreciate all the tips; to be honest, I thought I was doing the right thing. I followed all the rules and while reading up on firewalls, a Trojan hit out of nowhere. It shook my defensive ability that is why I wrote to you.

***I did not know the Win 8 native firewall was a two way firewall but that is great to hear!

And so does Windows 7 and Windows Vista. And Vista came out 8 years ago.

That's why Bing Google is a good friend to have.



>>True, I have worn them out. I also watch the videos in both as to how something works.

When I got a Trojan, it must have been the poorly set firewall and weak router as Defender did its job and caught it. It also allowed me to remove it. My router has strong passwords and keys and uses AES . It is set as WPA2-PTSK.
They say to broadcast the SSID. Do you agree?

When I got a Trojan, it must have been the poorly set firewall and weak router

No. As I noted earlier, firewalls block ports, they don't scan for malware. Neither do routers. And on the wireless side, AES and WPA encryption have NOTHING to do with you getting a Trojan. They help block users from hacking into and using your network.

Also, just to be sure, note that Windows Defender is an anti-spyware program. It is not a full anti-malware program, which you should be using. If you are using MSE, it will disable WD as it is no longer needed.

They say to broadcast the SSID. Do you agree?

Well I don't know who "they" are so I don't know what they were referring to. However, broadcasting or not broadcasting does not make you safer, one way or the other.
With Win 8 I have MBAM which I run regularly but real protection is enabled on Defender as MBAM is free and won't allow real protection to be enabled.

Win 8 does not have MSE; it is called Defender in this latest OS [Win 8 Pro].

I broadcast SSID as it makes no difference except harder for me to find when I need to with another pc.

So, Defender(old MSE) is the weak link. I need to figure a way to beef up the a/v protection.

Would it be prudent to buy MBAM, enable its real time protection and let Defender run without Real Time Protection.

I have the entire Norton security Suite available at no cost through Comcast but really do not want it, free or not.
Hi Peter,

I'm sure that Digerati will be able to advise in greater detail but the standard installation of Win 8 includes the new Defender (based on MSE anti virus and anti spyware engine)

Operating via the hardware firewall (in your Router) and with the Windows Firewall set to "on" and with the Microsoft Defender/MSE as standard the protection you have is quite reasonable as it is (in any event this is what I use on my own personal Win 8 machine……. :) )

You did mention the following in your last post

So, Defender(old MSE) is the weak link. I need to figure a way to beef up the
a/v protection

.

I don't agree that the Defender/MSE is the weakest link….. at least I'm happy with the level of protection it provides….. the weakest link is often to be found sitting at the keyboard…. (I don't mean you Peter) but it's generally the operator of the computer that can be the weakest link.

However if you feel that you would be safer using Norton or McAfee or any of the other well known anti virus products that are available, then don't let me persuade you otherwise….. its your computer and you need to feel comfortable that you have made the correct choices….

Regards

paws
Hi Paws I'm glad you wrote. Yes, Defender is the new a/v in Win 8. I agree with what you have said. I wonder if my grandchildren who use their IPods on my network have to do with any virus problem; I doubt it. My surfing habit as well as my wife's are never anything but pc work, research or emailing. I guess it can happen regardless of what you have. I do have the Norton Suite available for free but I think I am better of with what I have. I was splitting a fine hair wondering if the real protection offered by MBAM was better than Defender, I think my set up is adequate and if we continue using the machines smartly we should be ok. I am glad I got some tips about the firewall which was perplexing me. I clicked default on both then blocked all four squares to block incoming with both private and public. We have had no issues since that change. Default was from Digerati and blcking ws from Win Tech. Can you imagine I was going to blame my grandchildren. :smack: Peter
I also use MBAM Pro. and have done so for years. The best combo you can have is when it's paired with Defender or any other good firewall, if for some reason you don't like Defender. SuperAntiSpyware (free version) makes a good backup scanner to have on-board as well. Never had a problem surfing the net with MBAM Pro. active Melware protection and a regular scan with SAS cleans up the inevitable spyware one collects.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI