Serious Discussion What is your firewall security setup?

Azazel

Level 5
Thread author
Jun 15, 2023
226
Do you deny all inbound security traffic, or allow only core networking or default inbound rules.
Do you block lolbins outside network traffic?
Personally I use Windows Firewall Control, allowing only core networking inbound traffic and andy ful's Firewall Hardening tools for outbound traffic.

How would you rate my setup?
 

Jonny Quest

Level 16
Verified
Top Poster
Well-known
Mar 2, 2023
794
Windows Firewall Control for now, but I'm thinking of switching to NetLimiter or GlassWire... (which are not free)



Firewall Hardening by @Andy Ful does it without a hitch with Windows Firewall ! ;)
What I do like about GlassWire is the Network Monitor, the ability to see the first outgoing connections, and the Traffic Monitor where I can review the connections made and to what countries. I'm just using the free version.
 

simmerskool

Level 31
Verified
Top Poster
Well-known
Apr 16, 2017
2,094
What I do like about GlassWire is the Network Monitor, the ability to see the first outgoing connections, and the Traffic Monitor where I can review the connections made and to what countries. I'm just using the free version.
my ubiquity router shows all network activity. I do have free ZoneAlarm firewall running with MS Defender on one VM. Seems solid, sort of Checkpoint Harmony experience for free. :whistle::)
 

Trident

Level 28
Verified
Top Poster
Well-known
Feb 7, 2023
1,737
My home devices are behind Virgin Media’s new IPS functionality (on-router) and Check Point firewall (on-device), where possible.

I don’t block LOLBins from connecting, I block them from execution as much as possible.

I would always prefer security solution that blocks malicious traffic for all processes, not just in-browser and I would add secure DNS with NRD blocking to the mix. These features are more important than firewall.
 

monkeylove

Level 11
Verified
Top Poster
Well-known
Mar 9, 2014
545
I've been using Firewall App Blocker on Windows firewall.

I tried Malwarebytes Firewall Control with Kaspersky free, and it works fine. I think its main feature is a learning mode, but I felt that if no more additional software's installed then I might as well stick to the app blocker.

The only annoying this is that when I have to update a game using a mod pack, I have to disable the firewall temporarily or add the file as a temporary rule.

I thought of something more advanced, so I tried Comodo free firewall, and for some reason it worked fine with Kaspersky free. I think I uninstalled it because I felt it slowed down the system, which I think is the case when any security program with more features is running.

I had difficulty with Portmaster, though: for some reason Firefox and Edge could no longer browse online. I'm certain it's something in the settings of either the browser or some other app that just needed changing, but I got impatient and decided to just remove the firewall.

I also tried Avast free with the firewall turned on, but the latter looked basic.
 

Jonny Quest

Level 16
Verified
Top Poster
Well-known
Mar 2, 2023
794
I had difficulty with Portmaster, though: for some reason Firefox and Edge could no longer browse online. I'm certain it's something in the settings of either the browser or some other app that just needed changing, but I got impatient and decided to just remove the firewall.
Portmaster was a bit to advanced for me, I really couldn't figure it out as confidently as I would have liked. GlassWire just makes more sense to me, easier to follow and understand. I think in some of my research, there was some controversy that if you buy the Pro version (register with them) of GlassWire, there was a privacy concern that they denied (of course) regarding any tracking on their end of your use.
 

Trident

Level 28
Verified
Top Poster
Well-known
Feb 7, 2023
1,737
suggestion: take a look at ZoneAlarm free firewall app. (Might slow you down...)
I do not recommend the free firewall app for the following reason:
It includes Anti-Bot functionality which does the following:
-Blocks malicious communications based on domain and IP reputation, and communication patterns, such as protocols used.
-Blocks malicious communications based on program behaviour (machine learning).
-Automatically removes programs as soon as they attempt to perform malicious communication, rolls actions back and generates a forensic report (just sitting in a folder with no easy option to access it).

Anti-bot requires the forensic recorder engine to be running, which also powers Anti-Ransomware and Behavioural Guard. However, Anti-Ransomware and Behavioural Guard are not available for free, so the engine records all the data just for anti-bot. Waste of resources in my opinion. It would make much more sense to get Extreme Security with the threat emulation and everything, or to just find a lightweight firewall from someone else.
 
Last edited:

LennyFox

Level 7
Jan 18, 2024
307
I am running WHHL wtth Microsoft Defender with Avast Free Firewall.

Just install the Avast Free firewall as only part of the Avast Free security suite.The Avast FW uses the Windows internal FW framework, so it is only an application blacklist layer. It is like Glaswire paid for free. I manually added blockrules for LolBins (not all because some of the LoLbins blocked by Andy Ful in Firewall Hardening did not exist on my Windows 11 config).

I can't find the info on MT anymore by a member posting that Avast has a new "limited" notifications option where it only shows popups which are security related (and not commercial upsell popups tryig to convince you to switch to the paid version). It really seems to work (no go premium popups or you are at risk because you don;t use paid)
 
Last edited:

Trident

Level 28
Verified
Top Poster
Well-known
Feb 7, 2023
1,737
I can't find the info on MT anymore by a member posting that Avast has a new "limited" notifications option where it only shows popups which are security related (and not commercial upsell popups tryig to convince you to switch to the paid version). It really seems to work (no go premium popups or you are at risk because you don;t use paid)
v1_win_av_notifications.webp

They are starting to come across as a serious cyber-security vendor and not as an annoying infomercial platform. Good on them. Silent mode + threat alerts seems like a sensible one.
 

Neno

Level 6
Verified
Well-known
Jan 4, 2012
280
Windows Firewall Control for now, but I'm thinking of switching to NetLimiter or GlassWire... (which are not free)



Firewall Hardening by @Andy Ful does it without a hitch with Windows Firewall ! ;)
I have them both. But I would recommend you the NetLimiter. I don't like the GlassWire firewall rules management, and in my case applications blocked via GlassWire seem to bypass the block after you switch to VPN connection (Adguard in particular).
 

simmerskool

Level 31
Verified
Top Poster
Well-known
Apr 16, 2017
2,094
Windows Firewall Control for now, but I'm thinking of switching to NetLimiter or GlassWire... (which are not free)
@Shadowra, Quick question, ie, short answer (please)(or anyone here...): I first looked at NetLimiter then Glasswire. I do not see any info on Glasswire site that talked about Glasswire "integration" with AV apps. So far I have only used WFC on machines running MD & of course windows firewall. Is an app like Glasswire "safe" running with AV using their firewalls. Or can you use Glasswire without firewall but only use it to monitor to avoid conflicts, OR non-issue Glasswire does not create any conflicts??? :unsure:
 

monkeylove

Level 11
Verified
Top Poster
Well-known
Mar 9, 2014
545
I just tried Glasswire, but the free version only allows users to block two apps. However, the reporting was clear, and I could see things like connections by country. I think it can be used with the firewall featured turned off and as a monitoring tool, but I'm not sure.

If you install Avast with firewall, and even try to disable the latter, the Glasswire firewall won't be activated. The Avast firewall has to be uninstalled for it to work.

I decided to go back to Malwarebytes, and for some reason it reported that Comodo firewall is registered even though I tried to completely uninstall it using HiBit, although it pushed through with the installation.
 

simmerskool

Level 31
Verified
Top Poster
Well-known
Apr 16, 2017
2,094
I just logged-in to my UniFi router and it has so much info it is overwhelming -- drilling down, down... I should spend more time with it, but it's always working so don't bother. Also see how secure it is, or appears to be, a comfort. Log shows it blocked an incoming suspicious ICMP from Netherlands 10 days ago and provided oodles of info.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top