XP Pro x64 compatible firewall?

hypn0tik

Diamond Member
Jul 5, 2005
5,867
2
0
I just installed XP Pro x64 on my brand new computer that I built last night and it wouldn't let me install Zone Alarm. Are there any firewalls that are compatible with this OS?

My apologizes if this question has been asked previously. I searched for it and could not find anything.
 

ProviaFan

Lifer
Mar 17, 2001
14,993
1
0
Originally posted by: STaSh
Windows Firewall.
Which doesn't have any big problems, except that it won't stop programs from getting out, only from receiving incoming requests. Potential feature request for next version?
 

stash

Diamond Member
Jun 22, 2000
5,468
0
0
Which doesn't have any big problems, except that it won't stop programs from getting out, only from receiving incoming requests. Potential feature request for next version?

I doubt it. Not doing outbound filtering was a conscious decision by the product team, which I have discussed many times. I don't want to derail this thread, but essentially it comes down to the first Immutable Law of Security: If a bad guy can persuade you to run his program on your computer, it's not your computer anymore.
 

dawks

Diamond Member
Oct 9, 1999
5,071
2
81
Originally posted by: STaSh
Which doesn't have any big problems, except that it won't stop programs from getting out, only from receiving incoming requests. Potential feature request for next version?

I doubt it. Not doing outbound filtering was a conscious decision by the product team, which I have discussed many times. I don't want to derail this thread, but essentially it comes down to the first Immutable Law of Security: If a bad guy can persuade you to run his program on your computer, it's not your computer anymore.

Pretty much.. If you have to worry about blocking a program from sending outgoing requests, you have to worry about that same program being able to simply shutdown the firewall.


The Windows Firewall is more then enough for 90% of home users.
 

TGS

Golden Member
May 3, 2005
1,849
0
0
Originally posted by: STaSh

I doubt it. Not doing outbound filtering was a conscious decision by the product team, which I have discussed many times. I don't want to derail this thread, but essentially it comes down to the first Immutable Law of Security: If a bad guy can persuade you to run his program on your computer, it's not your computer anymore.

Is this what Bill Gates is thinking when people install Longhorn?
 

sourceninja

Diamond Member
Mar 8, 2005
8,805
65
91
If your really worried about outbound requires, it needs to be done off pc. On PC firewalls are a joke in terms of outbound security. They may do good for blocking inbound, but any program with admin access in windows can and will do whatever it wants. It could hook into the tcp stack in front of the firewall, it could shutdown the firewall, it could simply hide itself inside a svchost so you just ok it thinking its part of windows. Or it could plugin to IE and hide tha tway. If you want security, get a router/firewall with some IDS on it, and audit the logs now and then. Plus you wont have to worry about constant annoyances of pop ups asking you to approve this app.

Plus, if you have to worry about getting malware on your pc, perhaps you should look into your pc usage habbits and how you could improve them to prevent the installation in the first place. My wife's pc has never gotten a virus, or a peice of spwyare. This is because every program she uses is approved, trusted, and researched. And if it is suspect, it will be installed inside a virtual pc and checked to make sure it doesn't do any harm. I'm not saying you have to be that extreme, but you could just not run mail attachments, scan everything with a virus scanner, and use good spyware protection. Plus when going to websites, use firefox coupled with noscript and adblock and only allow javascript on a site by site basis. Proactive solutions are much better then reactive.
 

ProviaFan

Lifer
Mar 17, 2001
14,993
1
0
I'm just anal about wanting to know what programs are doing, and when... A seemingly trustworthy app (no, not kazaa) was caught trying to "phone home" one time. Sounds like an IDS is about as good as it gets for feeding this kind of habit, then.
 

sourceninja

Diamond Member
Mar 8, 2005
8,805
65
91
I suggest if you have a spare box doing nothing to try out ipcop. Its got a great web based gui. Supports snort rules for ids, and can show you every connection on your network. Stick that up and use ethereal on the network and you can see anything and everything that happens on your network. And for minimal amount of work at that. Plus you get bandwith shaping, firewall, dns cache, proxy cache and a whole bunch of other stuff if you want it.
 

stash

Diamond Member
Jun 22, 2000
5,468
0
0
Agreed. If you want to find out if an app is phoning home, a host-based firewall is not the way to do it.
 

dwcal

Senior member
Jul 21, 2004
765
0
0
Do you have an Nforce4? The NVIDIA firewall installed fine on x64, but I haven't tested it out very much.
 

sourceninja

Diamond Member
Mar 8, 2005
8,805
65
91
When I tested win64 i found the nforce4 firewall to give me weird issues I couldn't track down. I would for example open 6881 for bittorrent and 1 torrent would start fine, but then I would get errors with sockets on any new torrents i tried to open. (so I could only run one torrent at a time). Plus other weird networking issues. I dont think the nforce drivers for x64 have matured yet.
 

hypn0tik

Diamond Member
Jul 5, 2005
5,867
2
0
Yes. I have nForce4. In fact, I have nForce4 Ultra so would that make much of a difference? I doubt it but I thought I might as well ask.

So you guys suggest sticking with the Windows Firewall or should I just say screw it and go back to using the 32-bit version of XP Pro for the time being till the x64 version becomes more mainstream?
 

dwcal

Senior member
Jul 21, 2004
765
0
0
Never mind about Nvidia firewall. What a POS. I formatted x64 to install 32 bit XP SP2. On a fresh install of Forceware 6.66 with Nvidia firewall enabled, it slowed my network to 150KB/s and downloaded files were corrupt (getting updates from Microsoft). After disabling the firewall, transfer rates went back up and downloads were fine.
 

ModemMix

Senior member
Dec 21, 1999
347
0
0
i know this is an old thread, but i just started using bitdefender 9 prefesional plus, it has antivirus and firewall in one package, and im as happy with it if not happier then i was with zone alarm.

Ill be even happier when Kaspersky gets a working beta if KIS 2006 out.
 

REMF

Member
Dec 6, 2002
141
0
0
Originally posted by: dwcal
Never mind about Nvidia firewall. What a POS. I formatted x64 to install 32 bit XP SP2. On a fresh install of Forceware 6.66 with Nvidia firewall enabled, it slowed my network to 150KB/s and downloaded files were corrupt (getting updates from Microsoft). After disabling the firewall, transfer rates went back up and downloads were fine.

disconcurs.

works fantastically for me.
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
Originally posted by: REMF
Originally posted by: dwcal
Never mind about Nvidia firewall. What a POS. I formatted x64 to install 32 bit XP SP2. On a fresh install of Forceware 6.66 with Nvidia firewall enabled, it slowed my network to 150KB/s and downloaded files were corrupt (getting updates from Microsoft). After disabling the firewall, transfer rates went back up and downloads were fine.

disconcurs.

works fantastically for me.

same here
 

SUOrangeman

Diamond Member
Oct 12, 1999
8,361
0
0
FYI, Schadenfroh, the link in your post (two or three up) is bad, but it is good in your sig.

Before my Shuttle's PSU bit the dust last week, I had dumped nVidia's firewall (ActiveArmor and such) in favor of Tiny Firewall Pro 64. I had been using Kerio's firewall for the longest time with 32-bit Windows and had grown quite accustomed to its way of doing things. I just couldn't comfortably adjust to nVidia's solution to the same level.
 

13Gigatons

Diamond Member
Apr 19, 2005
7,461
500
126

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Originally posted by: STaSh
Which doesn't have any big problems, except that it won't stop programs from getting out, only from receiving incoming requests. Potential feature request for next version?

I doubt it. Not doing outbound filtering was a conscious decision by the product team, which I have discussed many times. I don't want to derail this thread, but essentially it comes down to the first Immutable Law of Security: If a bad guy can persuade you to run his program on your computer, it's not your computer anymore.

Stash, the LongHorn firewall is to block outgoing traffic as well....
 

stash

Diamond Member
Jun 22, 2000
5,468
0
0
I know. We had a rather...lively debate about it on some internal email aliases. The net is that is it is not designed as a spyware, virus, etc deterrent, but rather as a way for network administrators to further control what services clients use. Again, it is not intended to be protection against malware, and I hope to hell they don't market it as such. It would be a huge disservice to our customers.

The original documentation in Beta1 touted it as a malware prevention device, but I think I managed to show them the light on that.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |