Re: networking with zonealarm

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Chuck (none_at_example.net)
Date: 04/10/04


Date: 10 Apr 2004 15:47:10 -0500

On Sat, 10 Apr 2004 13:24:48 -0700, "Bob" <anonymous@discussions.microsoft.com>
wrote:

>Chuck,
>thanks for the reply. I am running the free version of
>zonealarm and it does not appear to have the ability to
>allow file sharing. I definitely notice that the only
>time I can share files is when I disable Zonealarm. It
>will not allow sharing no matter what security settings I
>use.
>Bob

Bob,

Is this the most current version of ZAF?

What is the paranoia level in ZAF set at right now? Can you drop a level?

If you can't get ZAF to work for you, there are other solutions. I have heard
good things about Kerio and Sygate personal (free) firewalls. Discussion groups
comp.security.firewalls and microsoft.public.security are good places to
research this.

Or upgrade to ZA Pro.

Other security considerations for a wireless LAN:
Enable WEP / WPA. Use non-trivial (non-guessable) values for each. (No "My dog
has fleas").
Enable MAC filtering.
Disable DHCP, and assign an address to each computer manually.
Change the subnet of your LAN - don't use the default.
Change the router management password, and disable remote (WAN) management.
Don't disable SSID broadcast - some configurations require the SSID broadcast.
But change the SSID itself - to something that doesn't identify you, or the
equipment.
Enable the router activity log. Examine it regularly. Know what each
connection listed represents - you? a neighbor?.
Use non-trivial accounts and passwords on every computer connected to a wireless
LAN. Disable or delete Guest userid. Rename Administrator, to a non-trivial
value, and give it a non-trivial password. Never use the Administrator renamed
account for day to day activities, only when intentionally doing administrative
tasks.
Stay educated - know what the threats are. Newsgroups alt.internet.wireless and
microsoft.public.windows.networking,wireless are good places to start.

Cheers,
Chuck
Paranoia comes from experience - and is not necessarily a bad thing.



Relevant Pages

  • Re: Unable to access the remote computers...
    ... If so make sure that simple file sharing is ... that is a local administrator on the computer you want to manage and making ... After that i have click the local users and groups.. ... remote machines and login as an admin and did the work for reset the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Admin users can see other users My Documents folders in Explorer
    ... Turn off simple file sharing and use the 'Security' tab under properties to ... admin account can see everything (preferably the default 'Administrator' ... Any local administrator can access all files, ... Calling an illegal alien an "undocumented worker" is like calling a ...
    (microsoft.public.windowsxp.general)
  • Re: Change a service - access denied???
    ... After looking at a couple other posts I think that it might be helpful to give you a little background on the machine. ... When I look in control panel at users it only lists my name [with administrator privileges] and guest. ... In the KB article referenced in the previous post it says "Windows XP Home Edition-based computers always have Simple File Sharing enabled" so I don't know how this is gonna help either Shannon or myself. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: What have I done???
    ... scroll to the bottom and look for "Use simple file sharing ". ... Click on properties, then click on the security tab, now click advanced. ... If you want to see what state your user account is in, ... you what permissions you do have, if you compare yours to the administrator ...
    (microsoft.public.windowsxp.general)
  • Re: Video Problems
    ... Are you using any software firewall, such as ICF or ZoneAlarm? ... Did you log in as an Administrator, ... Let me know if you use ZoneAlarm, since ZA has a particular issue/solution. ... Does any one have a working system and would be willing ...
    (microsoft.public.windowsxp.messenger)