Sophos Anti Virus and Firewall

Mar 07, 2015 5 Replies

Anyone here use the Sophos firewall? I really liked it when I had it on a Vista machine. But somehow it doesn't work as well under Win8. When an app was run and would try to access the Internet and it was blocked you would get a popup that gave you the option of adding it to the "approved" list or if it was already there and the checksum changed, you could update the checksum. Very useful for browsers and other Internet apps that update often.



But with Win8 the popup doesn't happen. So every time you restart a browser and it has installed an update... which is about every time I restart a browser... I have to manually go into the checksum dialog and reselect the executable. Once in a while this is a real chore. Did you know that IE has *two* executables, one in the 32 bit program files dir and one in the 64 bit program files dir? You have to include them both in the checksum dialog or they can't get out.



A couple days ago I ran update on Sophos and the browsers quit working, all of them. This is usually some sort of confusion in the TCP stack (or some networking stack) that has to be reset in a command box with admin privilege. But this time that doesn't work. There is a report that shows you what is blocked by the firewall or allowed, but it doesn't seem to report accurately all the time. I added a couple of ports that have to do with talking to the router and now nothing is reported as being blocked by Firefox, but FF still won't work unless I disable the firewall (just like the other browsers).



Contacted Sophos support and they are now telling me to change the port and mode specific filters that the previous Sophos tool had recommended to being a "trusted" app. I thought the point of a firewall was to limit an app to the specific modes it needed to do it's job. Besides, the browsers didn't quit when they were updated, they quit when Sophos was updated!



This may be the final problem for me. Sophos has been a much bigger PITA for me since I got a Win8 PC and Win8 has been out for two years! You'd think they would have figured it out by now.



Any recommendations on a good firewall program? Is the Windows firewall any good?


Rick

The windows built-in firewall is better (for most uses) than any third-party firewall, because it is relatively simple. Third-party firewalls and "security suites" for windows tend to be so complicated that they have been known to have their own security holes that attackers can use. The also have a tendency to have so many pop-ups to confirm or deny things that users end up clicking "Yes" to everything automatically - or find that their everyday programs no longer work.

No firewall on windows will do the job of a proper external firewall, but assuming you at least have a cheapo NAT router between you and the bad guys, then the Windows built-in firewall is as good as it gets on Windows.

I think the problem for *any* firewall is simply how to set it up. Over the years I have found it easy to set up the Sophos firewall... until now. How would an external firewall be any better and how would it be set up?

Rick

The usual setup for an external firewall is that anything inside can go out, anything outside is blocked from getting in. Dead simple, and covers the great majority of what is needed. If you need to let something in, such as to run a server with external access, you open that particular port and direct it to the particular server machine.

An external firewall device does not limit traffic from any particular program - that requires a firewall on the Windows machine itself (the built-in firewall is sufficient, even if the interface is not particularly pretty). But usually you only want to do that if you are running suspicious software (or running legitimate software in a suspicious way, such as to avoid licence checks) - and you would then be better sandboxing the program inside a virtual machine where you have full control and can block all network traffic.

Isn't a browser by definition a "suspect" program? You can't know what a web site is going to do until you visit it.

Rick

Use Linux and a browser with no plug-ins and everything turned off.

Then, YOU decide what to "send" to them.

Essentially, you won't be visiting many sites as most will get culled by you once you see what they are scraping.

iPad and Android "apps" are worse criminals in this regard, btw.

And yes, I do feel it should be banned and deemed criminal.

The machine USER should be the ONE person deciding what EXACTLY goes OUT on his pipe(s).

Just like the stupid "fashion industry", smart phones and the web on PCs as well, have made the world utter idiots as we allowed this cookie s*it and java and all the other invasive horseshit IN, and our personal info OUT.

Besides... with the huge amount of data bandwidth we would get back, the NSA would have less to sift through, and what they did look at would be far more pertinent to their cause. Right? (evil grin)

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required