Announcement

Collapse
No announcement yet.

CCS Firewall, who uses it? And what is your experience?

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • #16
    Originally posted by Ed_Johnson View Post
    Hi Robin..

    I can confirm this works perfectly so far. The same procedure works for that pesky Containment. Although I really do not want to disable containment we have some clients where trusting applications simply does not work and I cant get them to work any other way than disabling containment.

    Specifically... Farmplan. Gatekeeper. Articad. Easyquote.. and anything with sentinal dongle.

    So I now have three clones of my standard Windows profile.. one with Firewall disabled.. one with Containment disabled and one with both disabled.. all report CCS running perfectly with no red warnings.


    You don't have to support farmplam do you, nasty program. We have that working through containment with no issues, but a pain to get right frost time.

    Also have sentinal as well working with no issues.

    Would be interestibg to see how your allowing them as something not right.
    Robin
    Director
    Strobe Technologies Ltd
    https://www.strobe-it.co.uk/

    Comment


    • #17
      We have quite a few clients with farmplan, fortunatelly only a couple of them on the Itarian platform and running ccs. But no.. still dont have any of those programs working with ccs properly.. It has been necesary to have Containment and Firewall tabs removed in all those endpoints. I will be visiting a client Monday to run the Unknown file utility to try and get farmplan working as this client owns a number of farms in the area and is expecting me to sort it or replace ccs.

      Comment


      • #18
        I wonder if it is worth trying to get a remote session with you to get this working 100%

        I know some apps and systems can be a pain but once you have the right paths and variables setup it should be a simple trust and done.

        If you want to talk please feel free to message me direct on robin@strobe-it.co.uk
        Robin
        Director
        Strobe Technologies Ltd
        https://www.strobe-it.co.uk/

        Comment


        • #19
          Had the dreaded firewall problem rear its head again today.. fortunately on one of our own endpoints.. running the latest EM(19060) with latest CCS(7495). A simple reboot on the machine resulted in no internet. Disabled the firewall driver in adapter settings and all sprung back to life. enabled and rebooted.. same again. No idea what triggered it but we have recently upgraded this endpoint to W10 1903. All our other endpoints are running the exact same setup with no issue so far.

          We have decided the only option is to take Robins suggestion of deleting the firewall tab as standard in all new endpoints via a new default profile. We already have this profile running on prob 20% of our clients endpoints successfully. I just hope that Comodo dont now do something crazy resulting in the removed tab causing some other problem. Hope you're taking note Comodo.
          Last edited by Ed_Johnson; 06-17-2019, 08:17 PM.

          Comment


          • #20
            Hi Ed_Johnson ,

            We have indeed raised your issue with engineering and we are awaiting their investigation on your report the soones time possible. Please give us some time to an answer to you on this. We will be in touch shortly.

            Comment


            • #21
              Originally posted by Ed_Johnson View Post
              Had the dreaded firewall problem rear its head again today.. fortunately on one of our own endpoints.. running the latest EM(19060) with latest CCS(7495). A simple reboot on the machine resulted in no internet. Disabled the firewall driver in adapter settings and all sprung back to life. enabled and rebooted.. same again. No idea what triggered it but we have recently upgraded this endpoint to W10 1903. All our other endpoints are running the exact same setup with no issue so far.

              We have decided the only option is to take Robins suggestion of deleting the firewall tab as standard in all new endpoints via a new default profile. We already have this profile running on prob 20% of our clients endpoints successfully. I just hope that Comodo dont now do something crazy resulting in the removed tab causing some other problem. Hope you're taking note Comodo.
              Hi Ed_Johnson

              We have had two endpoints where the network has been locked out after upgrading to Windows 10 Version 1903 Build 18362 (os_version=10.0.18362), both with CCS 11.1.0.7259. As you know, the firewall module relies on the "COMODO Internet Security Firewall Driver", and a full Windows 10 upgrade to 1903 implies some driver changes, so my guess is that on some endpoints the firewall driver gets stuck after the Windows upgrade. In our case, the issue has been resolved by just uninstalling and then reinstalling again Comodo CCS to repair the firewall driver.

              Hope this will help!

              -- Javier Llorente
              Devoteam - Endpoint Security

              P.S. Dear Support, we have no more cases so far, there is no need for us to create a ticket yet.

              Comment


              • #22
                Hi DevoteamEndpointSecurity

                The firewall issue is 100% a driver issue. The driver is used to add extra features like containment to your network functions, but as far as I'm aware this is the only AV that works like this and also the only AV that kills networking when MS updates drivers for NIC or the core code to the network layer.

                We found sound times just un-ticking and re-ticking the driver solved the issue and other times a reboot as well. On the majority of the cases a CCS reinstall was needed.

                All ways you look at it, this is a constant major flaw in the program design which means you need to travel miles and miles to solve every 2 weeks due to either an MS update or Comodo update.

                I know it sound bitter, but other than the firewall the product is amazing and so secure.

                Just need to rethink how the firewall works or integrate IPTables and WAF instead like all the competitors are doing.
                Robin
                Director
                Strobe Technologies Ltd
                https://www.strobe-it.co.uk/

                Comment


                • #23
                  I am also turning of the firewall on all my users. When installed, Comodo Security 11 stops the CSS from working on random computers. In addition, it will also entirely stop connections to the nternet. In fact it is happening on my OWN computer and haven't been able to resolve it. So very frustrating.

                  Comment


                  • #24
                    Hi davcomp,

                    May you please confirm if your are experiencing this issue with the current version of Client - Security 11.3.0.7495. Please check and update your CCS version if you are not running the latest version yet. If you are still experiencing the same issue after installing the latest version of CCS, please send us an email at support@itarian.com so we can further investigate and determine the root cause of the issue.

                    Thank you.
                    Gabriel
                    ITarian Technical Support

                    Comment


                    • #25
                      Hi,
                      at the moment I have 180 EPs with CCS firewall on and I have no particular problems.
                      The Containment is very finicky, but, in my experience, is manageable.

                      Comment


                      • #26
                        Originally posted by stefanoradam View Post
                        The Containment is very finicky, but, in my experience, is manageable.
                        That's undoubtedly the most accurate description of the Containment feature I've ever read. :-D

                        -- Javier Llorente

                        Comment


                        • #27
                          Originally posted by stefanoradam View Post
                          Hi,
                          The Containment is very finicky, but, in my experience, is manageable.
                          Please tell us all the "finicky" aspects so that we can fix them asap! thank you.

                          Comment


                          • #28
                            Containment works very well, just needs a bit of understanding and planning to get right.
                            Robin
                            Director
                            Strobe Technologies Ltd
                            https://www.strobe-it.co.uk/

                            Comment


                            • #29
                              Well, as I wrote is manageable...
                              For example I see some actions about files from Asus, Dell, HP that are a bit annoying

                              Dell servers
                              cont1-cont-dell.jpgcont1-dash-dell.jpg

                              Asus Desktops

                              cont2-dash-asus.jpg
                              ...

                              Comment


                              • #30
                                How odd to see the results like this.

                                Have you run a rating scan from Endpoint Manager portal on all devices?

                                We find the admin rating of trusted does not work until this is done.
                                Robin
                                Director
                                Strobe Technologies Ltd
                                https://www.strobe-it.co.uk/

                                Comment

                                Working...
                                X