ZoneAlarm and 0.4 (Instructions to configure)

Dimes users are invited to bring comments, suggestions and all other happy thought about DIMES.

Moderators: BoazH, UDi, shavitt, idob

ZoneAlarm and 0.4 (Instructions to configure)

Postby andrewsullivan » Fri May 20, 2005 2:48 am

ZoneAlarm Pro 5.5.094.000

These instructions were written and tested by me, but based on upon some original investigative work by HelzBelz, so all credit to him or her for figuring out how to get it working with ZA.

1. Select Firewall from the menu on the left
2. Set Internet Security Zone to High (the default)
3. Click the Custom button within Internet Security Zone
4. Ensure that the following items within "High security settings for Internet zone" are checked:
Allow broadcast/multicast is checked (default)
Allow outgoing ping (ICMP Echo)
Allow other outgoing ICMP
5. Ensure that other items within that category are NOT checked unless you need them for something unrelated to DIMES.
6. Run DIMES, it will now work!!!

You do not need to enable "Allow incoming ping (ICMP Echo)" or "Allow other incoming ICMP", nor do you need to let javaw.exe act as a server (meaning listen for or accept connections).

I have not attempted to apply these settings to the free version of ZoneAlarm.

Regards,
Andrew.
andrewsullivan
 
Posts: 3
Joined: Thu May 19, 2005 12:54 am

Postby mfpotter » Fri May 20, 2005 3:33 am

Hi Andrew,

Thanks for your post, and for figuring out how to get DIMES to work with ZoneAlarm. Unfortunately (at least for me), the settings/options that you described are only available in the paid version of ZoneAlarm (ZoneAlarm Pro), not in the free version (which is the version that I have :-( ).

Best regards,
Mike
mfpotter
 
Posts: 9
Joined: Sun May 08, 2005 5:49 am

Re: ZoneAlarm and 0.4 (Instructions to configure)

Postby HelzBelz » Fri May 20, 2005 4:25 am

andrewsullivan wrote: ... based on upon some original investigative work by HelzBelz, so all credit to him or her for figuring out how to get it working with ZA.


FYI, it's "him" :lol:

Glad I could be of some help !

I'll probably try and fiddle around with the Free version of Zone Alarm next time I've got a fresh Windows install to play with (unless someone beats me to the punch, that is).

Regards,

HelzBelz
If at first you don't succeed, then skydiving is not for you.
HelzBelz
 
Posts: 37
Joined: Wed May 18, 2005 8:47 pm

Postby 7im » Sat May 21, 2005 9:22 pm

Would a moderator please fix the title of this thread? It only applies to the Pro version of ZoneAlarm. I guess that us free ZoneAlarm FireWall users are out of luck for now. My DSL router blocks ICMP, and I can't turn that off. And the free ZoneAlarm is blocking UDP. I supposed I won't be participating in this project an further until you can find a work around. Thanks.
7im
 
Posts: 5
Joined: Sat May 21, 2005 9:14 pm

Postby danny » Sun May 22, 2005 12:01 pm

I'll do that. thanx for the notice.
I know where my towel is.
danny
Site Admin
 
Posts: 177
Joined: Sun Sep 05, 2004 1:03 pm
Location: Israel

Free Zone Alarm and DIMESAgent 0.4

Postby Jammy » Tue May 24, 2005 1:13 pm

I have been running DIMES on two AXP's (XP 2600 and XP 3000) both use W2K and the free version of Zone Alarm. I was never even aware that others were having problems with ZA until one of my team mates from Ars Technica Team Strawberry Jello mentioned it yesterday.

The sliders in ZA for the firewall on both the Trusted Zone and the Internet Zone are set at Medium. I have my DIMES client set for UDP only and Zone Alarm does not block the UDP packets, in fact, both Tracert and Ping works fine with ZA. My graph window gets so congesteted that I have to dump the graphs at least hourly for I have found DIMES to really be a memory hog and it actually slows down my 3 GHz Dell Dimension (I run DIMES with Seventeen or Bust on all four of my boxes) which has 512 megs of PC3200 DDR2 DC.

Jammy
Jammy
 
Posts: 10
Joined: Mon May 23, 2005 7:33 pm
Location: San Diego, CA

Re: Free Zone Alarm and DIMESAgent 0.4

Postby HelzBelz » Wed May 25, 2005 6:25 am

Jammy wrote: ... The sliders in ZA for the firewall on both the Trusted Zone and the Internet Zone are set at Medium ...


Yep, verified here.

With Zone Alarm "Free", most of the control you have is by selecting "presets"; here with DIMES, this means using "Medium" in both the Trusted and Internet zones. The "Medium" settings allows UDP transfers, hence DIMES can be used in UDP mode, by specifiying "UDP" in Properties --> Network --> Protocol.

This is NOT a problem with DIMES: it's the way your firewall software is designed. For Zone Alarm, the "Pro" version does have a much more complete set of user settings (as described in previous posts above), so do other software firewalls.

Now, it's up to the user to decide if "Medium" (in Zone Alarm Free) provides good enough protection on the Internet side (and, for most users, Medium is indeed sufficient).

Regards,

HelzBelz
Last edited by HelzBelz on Wed Jun 18, 2008 9:43 am, edited 1 time in total.
If at first you don't succeed, then skydiving is not for you.
HelzBelz
 
Posts: 37
Joined: Wed May 18, 2005 8:47 pm

Re: Free Zone Alarm and DIMESAgent 0.4

Postby mfpotter » Wed May 25, 2005 12:05 pm

Thanks Jammy for the info regarding the free version of ZoneAlarm - I may give the sliders a try...

HelzBelz wrote:This is NOT a problem with DIMES: it's the way your firewall software is designed. For Zone Alarm, the "Pro" version does have a much more complete set of user settings (as described in previous posts above), so do other software firewalls.
HelzBelz


However, not meaning to be argumentative with HelzBelz, but there IS an issue with the 0.4 version of DIMES. With the 0.3 version, and with the free version of ZoneAlarm, and with the sliders set to High, DIMES worked. Same computer, same version of ZoneAlarm, same slider position, but now with DIMES 0.4, DIMES DOES NOT work. So, something was changed in DIMES that is preventing it from working with a firewall configuration that worked with DIMES 0.3.

Best regards,
Mike
mfpotter
 
Posts: 9
Joined: Sun May 08, 2005 5:49 am

Re: Free Zone Alarm and DIMESAgent 0.4

Postby HelzBelz » Wed May 25, 2005 4:13 pm

mfpotter wrote: ... With the 0.3 version, and with the free version of ZoneAlarm, and with the sliders set to High, DIMES worked. Same computer, same version of ZoneAlarm, same slider position, but now with DIMES 0.4, DIMES DOES NOT work ...


I'm sure you're right, mfpotter, sorry for the misunderstanding : I should have mentionned that I've joined DIMES at version 0.4 (hence have never witnessed the behaviour of previous agents).

Note to developpers --> I can only confirm the "problem" and solutions (i.e. my posts above, and the original post in this thread) with this configuration:

DIMES Agent 0.4 on a Win2k w/SP4 install, running with either
ZoneAlarm Pro version: 5.5.094.000, or
ZoneAlarm Free version: 5.5.094.000

(People with a different setup: don't hesitate to add a comment, i.e. Win XP, or older Zone Alarm, etc.)

Anyhow, both versions of Zone Alarm do have a solution (described previously); but yet, I sure agree with mfpotter that if previous versions of your Agent (0.3 and earlier) were working without fiddling around with Zone Alarm's default settings, then only you (the developpers) are in a position to figure out what has since changed in 0.4 which triggered the problems related in thread...

Please, let us know what you find out ! (I'm quite fascinated by the DIMES project)

Later,

HelzBelz


P.S. 5.5.094.000 is the latest (as of this moment) Zone Alarm version (either Free or Pro). I haven't tried DIMES with older versions of ZA, since this latest release does address security concerns, and the (free) update is strongly recommended.
If at first you don't succeed, then skydiving is not for you.
HelzBelz
 
Posts: 37
Joined: Wed May 18, 2005 8:47 pm

Postby 7im » Thu May 26, 2005 5:11 am

Windows XP SP2 and ZoneAlarm Free v5.5.094.000. Doesn't work with Internet Zone slider on the FireWall set to High. And I am not really comfortable compromising my firewall settings to run this project, especially when I read that dimes worked in v.03 and stopped working in v.04 with Zone Alarm. Obviously, something in the dimes agent changed! It would be nice if some of the project people would comment on this concern.

Oh, ya, and it would be nice if the servers didn't go offline so much either.
7im
 
Posts: 5
Joined: Sat May 21, 2005 9:14 pm

Postby Jammy » Thu May 26, 2005 6:18 am

7im wrote:
Oh, ya, and it would be nice if the servers didn't go offline so much either.


Amen to that!
Ars Technica Team Strawberry Jello
Ars Technica Team Prime Rib:SOB
lagh lucharghlu'bogh HuH ghopDu'lIj lungaSjaj
Jammy
 
Posts: 10
Joined: Mon May 23, 2005 7:33 pm
Location: San Diego, CA

What UDP Ports ?

Postby HelzBelz » Tue Jun 28, 2005 9:46 pm

O.K. I'ld like to switch my Agents to run in UDP mode. However, my firewall (ZA Pro) requests a list of which specific "UDP ports" to be opened...

So, what UDP ports are being used / monitored by the Agent ?

Regards,

HelzBelz
If at first you don't succeed, then skydiving is not for you.
HelzBelz
 
Posts: 37
Joined: Wed May 18, 2005 8:47 pm

Postby Lupine1647 » Tue Jun 28, 2005 9:56 pm

According to Netpeeker, it would look like UDP port 53 is the port NetDimes uses for UDP.


[EDIT]Nevermind, was reading the wrong column, on the local side, it would apear to be just random ports ranging from anywhere between 1000-4000.[/EDIT]
Lupine1647
Junior member
 
Posts: 76
Joined: Sat Sep 18, 2004 5:48 am
Location: Kansas City, Missouri

Re: What UDP Ports ?

Postby HelzBelz » Thu Aug 04, 2005 5:22 am

HelzBelz wrote:O.K. I'ld like to switch my Agents to run in UDP mode. However, my firewall (ZA Pro) requests a list of which specific "UDP ports" to be opened...

So, what UDP ports are being used / monitored by the Agent ?

Regards,

HelzBelz


Thanks Lupus1647; however, perhaps an "admin" could help us here (being more specific)...

So, I reiterate my question: Which specific UDP ports does DIMES use ?

Best regards,

HelzBelz
If at first you don't succeed, then skydiving is not for you.
HelzBelz
 
Posts: 37
Joined: Wed May 18, 2005 8:47 pm

Agreed

Postby chunming » Thu Aug 11, 2005 3:26 am

I am running Zonealarm 5.5.094.000 and at high internet security, DIMES is blocked by Zonealarm.

At medium setting, only ICMP can get through. UDP cannot get through as well................

I have used the older version before and it works at high security, so don't know what happened here..........
chunming
 
Posts: 1
Joined: Thu Aug 11, 2005 3:20 am
Location: New Zealand

Next

Return to Dimes users forum

Who is online

Users browsing this forum: No registered users and 1 guest

cron