by VistaFirewallControl » Wed Jun 30, 2010 12:47 pm
>Just to keep things simple, for every app that I'm allowing access, I'm basically giving the app EnableAll authority. Is this a bad thing?
The question is practically equal “I completely trust the application, confirm the application network activity as safe and wanted. Am I wrong?”
Evidently the answer is application dependent. On the other part permanently settings EnableAll for all the applications makes any firewall senseless.
The entity to block blocking nothing is a subject for collecting only.
>I'm doing this partly because 1) I trust the applications I'm okay-ing, and 2) In some cases I'm not sure which are the right zones to apply (although I could guess and go the trial-and-error route, I suppose).
Regarding (2). The zone adviser on the application detection should give a decent zone to start with. The common sense may be applied also as the default zones (which can be easily customized by the way) are reasonably named. So could you can use the following logics
- ABC is asking for connection, I do not know what ABC is, I did not launch it. So ABC is a candidate for DisableAll evidently.
- ABC is asking for connection, I do know what ABC is, I know it can be launched even automatically, I just do not know why ABC needs the internet. LANonly would be reasonable with checking of ABC operability after the LAN is enabled only.
- ABC is for ABC-ing; An ABC zone would be reasonable for the app.
“trial-and-error route” is the longest but the most comprehensive anyway. We are nearly sure you will discover a lot of network activities you did not even expect before.
1 Set DisableAll at application detection (and DisableAll as Settings/DefaultZone).
2 Check the IP/port the application is asking, Check the IP, think (and once more), make a conclusion about the activity safety, choose a proper zone or start creating a new zone from scratch enabling/disabling the activity only accordingly.
3. Check blocked notifications of the application
4 Loop from (2)
We believe the above should not take too much time, for experienced users 1-2 minutes for the first application.