Nvidia hardware firewall

moosey

Golden Member
Apr 18, 2001
1,331
0
76
With the firewall built into the nforce4 boards, is it still necessary, or better, to use a software firewall like kerio? Or does it work best when one or the other is used?
Also, is the nforce firewall worth using?
 

fORM

Member
Feb 12, 2005
29
0
0
The firewall works fine. I dumped XP firewall and turned on the NV one.
It pops up with permission tabs from time to time and keeps any mystery programs from connecting.

Great for blocking silly programs like Quicktime, Real player and other useless media players.

 

davvv

Junior Member
Feb 1, 2005
8
0
0
Don't use it in tandem with any other firewall (dual firewalls can cause very weird connection problems).
 

PascalT

Golden Member
Nov 20, 2004
1,515
0
0
ihad big issues when i installed it. First when I booted up it asked for some kind of network login thingie, so i had to boot fromCD (ForceWare). then since I had sp2/windows firewall, my internet wouldn't work anymore, and the only way to fix it was to uninstall sp2.

 

Glpster

Banned
Jan 14, 2005
221
0
0

So far, I've been fairly impressed with the nVidia Firewall, despite a few minor problems, that will hopefully be fixed soon in future revisions.

The fact that it (along with ActiveArmor) is hardware based, and is protecting your PC essentially from the moment the power is turned on is, in a word, awesome!

And knowing all those bad and unwanted packets flying up against its brute hardware power and being pounded down before they can ever bother your CPU is SWEET!

Yes, it does have some room for improvment, but I suspect they are working on it, because it's an absolutely great idea.

 

Glpster

Banned
Jan 14, 2005
221
0
0

:Q :brokenheart:

I'm sorry to have to take back my previous "praise".

As much as I appreciate those other aspects of the nVidia Firewall, I JUST discovered a SERIOUS flaw!

I had the Firewall set to "High" protection mode (which is just below LOCKDOWN). I downloaded LeakTest from grc.com and ran it. The nvFirewall notification came up and I was able to deny access to Leaktest (thereby passing the test). Yay!!!!

HOWEVER, I then closed down Leaktest, and renamed it to iexplore.exe (The executable name for Internet Explorer). I re-ran Leaktest, and IMMEDIATELY the test failed, as an nvFirewall notification came up and said *ding* 'Hello, I recognize this program iexplore.exe and am therefore automatically creating a rule to allow it to access the internet whenever it darn well pleases. No action is required by you. Have a good day.' (in not so many words). And then promptly disappeared.

:Q :Q :Q

I could not believe it would allow that (something I know Zone Alarm alerts you to). What if a malicious program (renamed as an allowable program) launched when I wasn't around to see the notification. I'd have no idea it was accessing the internet at will.

Oh well, I guess I'll have to switch to Zone Alarm, and lose all that hardware offloading goodness.

Of course, I have no idea how to E-mail nVidia to alert them to problems, or suggest improvements for any of their products. I could not find any E-mail address for them on their web site. I looked in all the standard places you'd find one. Unless I missed it. Anyone know their E-mail address?

Grrrrrr..... :|

 

Glpster

Banned
Jan 14, 2005
221
0
0

Well, I just finished reading the ICSA Labs Certification Report for the Nvidia Firewall. After some requirec fixes, the Nvidia Firewall was given a passing grade by them.

Unfortunately this ICSA Lab certification is pretty crappy, if they could allow a glaring vulnerability like the one mentioned above get past them.

In fact, the stupid report they created is more concerned with and has more to say about the Logging ability of the firewall software than it is with the Firewall's enforcement of security policy without being circumvented.

Oye! I think I'm going to contact this ICSA Labs and see just what they have to say about certification of products that have serious vulnerabilities like simple renaming of a malicious program to an allowed program, or Leaktest's mysterious Stealth mode, to get past the firewall.

 

Heinrich

Golden Member
Jul 28, 2001
1,341
1
81
Interesting finds...most of the other posts around here say "it sucks" and "it's great" - thanks for your thorough contribution!
 

TheNiceGuy

Golden Member
Dec 23, 2004
1,569
3
81
I had all kinds of issues which seemed to be either NVF or driver related.
1) I tried to install ZoneAlarm initialy (with NVF disabled), but my PC locked up really badly.
2) I kept getting errors trying to install Kaspersky AV, and later even the bundled Norton AV.
3) None of my bittorrent programs would work properly, despite clearing ports, etc. I ended up switching to Windows FW.

Everyone I talked to said these were NVFW or driver related . I really like the idea of it, but can't use it.
 

T3mplar

Junior Member
Mar 15, 2005
12
0
0
The NV Firewall will access the CPU like every second and this is supposed to offload the CPU. My CPU got like spikes every second to about 15-20%, uninstall the Firewall and BINGO, no more spikes. Great offloading eh.

Both the NV RAID and Firewall functions on this board are VERY bugged and after a whole month of agony trying to get my NON OCed system to be stable under all circumstances I ended up using the Silicon Image RAID contrller and the Marvel LAN LOL.. all the hyped NForce4 features just wont give you that stability.. bummer!

Simon
 

bradley

Diamond Member
Jan 9, 2000
3,671
2
81
On paper, it sounds like a great feature, just not so sure about the actual implementation. Biggest problem with Nvidia's firewall seems to be a lack of adequate documentation, and an unreceptive, almost cavalier attitude to questions or suggestions.

Firewalls are a serious matter, and I'm not about to trust my security to just anyone. Although, I wonder if ATI already has a hardware firewall in the works.
 

Metaphis

Junior Member
Apr 1, 2005
19
0
0
also the nvfirewall can cause many BSOD.... Seems like this was just a marketing spree and it can't really be used.
 

BuckNaked

Diamond Member
Oct 9, 1999
4,211
0
76
I was running the firewall on a newly built system, and was playing some steam based games... I had a lot of hestiations and play was jerky and couldn't figure out was was going on... Finally uninstalled the Nvidia Firewall, and the now plays smooth as butter. I couldn't believe the firewall was having that serious an impact on the game, but it sure appears that it did.

Dave
 

GadgetBuilder

Member
Dec 28, 2004
148
0
0
The nVidia driver set (6.53 presently) works well for many NF4 owners. A minority of NF3/NF4 owners experience a variety of problems/symptoms, as reported in the nVidia mobo forum. So concentrate on threads with over 100 views:
http://forums.nvidia.com/index.php?s=f3...ead353326152f9b12af806c46&showforum=34

Below I have briefly categorized the NAM symptoms reported in the nVidia mobo forum; hard to say how good individual owners are at properly determining the underlying cause but in most cases there seems to be a consensus. ( Buck_Naked and Metaphis should note that their problems are also experienced by other NAM users.)

-----------------------------------------------------------------
NAM (firewall) complaints: BSOD; P2P (bittorrent, emule) crash/ disconnect/slow; can't connect to certain sites (each user reports different problem sites); ftp blocked (sometimes works for a while); IE favicons don't work (recover if NAM disabled); excessive disk access

The frustrating thing is that the problems seem random, both in what happens and who is affected. Sometimes a system will work perfectly with NAM but after some event (like reloading XP and the drivers) will experience serious problems.

This leads to wildly conflicting opinions on the nVidia firewall's capability, functionality, and usefulness.

For example, many owners like the reduction in processor load when the co-processor in the NF4 handles firewall processing.
Then, you read this (follow the link at the bottom of the page; note the date on the review and on the problem description):
http://www.neoseeker.com/Articles/Hardware/Reviews/vnf4ultra/8.html

And you wonder if the firewall load reduction is real or just a marketing theory...

Given the number of issues raised in the nVidia mobo forum, I find it surprising that more reviewers of NF3 and NF4 boards don't encounter problems, especially with NAM. NAM draws the most complaints in the nVidia forum but each of the other drivers in the set has a similar laundry list of complaints.

nVidia ignores their forums and never responds or participates. Nor is there any way to contact nVidia concerning problems with their drivers -- "contact your mobo vendor". Updates to the mobo driver set are becoming less frequent - 6.53 was released March 17 and the fix for the problem noted in the neoseeker review (discovered in early February) was not included.

 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |