Wednesday, October 24, 2007

The Vista Firewall disaster

Well, this is not a Delphi related post, but it is something I need to say. All Vista compatible firewall I have tested suck. Have I been rude ?.. Ok... sorry.. All Vista compatible firewalls really suck.

You may think that I say that easilly, but not... that is not the case. I have been testing following trial versions of Vista compatible Firewalls:

Comodo, Agnitum Outpost Firewall 2008, Jetico Personal Firewall, Lock'n'Stop, ZoneAlarm, Norton Internet Security 2008.

In all cases except with Jetico and Lock'n'Stop the resources and speed penalties are really high, or they simply don't work, or worst, they hang the system. Agnitum Firewall once installed doesn't lets the system to be rebooted, Jetico Simply freezes the whole system, Lock'n'stop just blocks the system randomly, Zonealarm.. oh.. zonealarm... it decreases my system speed in about 25%. Disaster.. really disaster. But do you know what really annoys me ? That no firewall except Zonealarm and Jetico lets you disable the hashing of an application. I am connected permanently to the internet during my coding. My applications usually access SQL Servers around my LAN. Each time I compile my application and execute it , its SHA checksum changes so all firewalls bug me that the application has changed and ask me what to do... How can the coders of the firewalls not add this easy feature to implement to disable this checsum check on certain applications. Incredible.

4 comments:

Anonymous said...

Just use the builtin Windows Firewall. It is much improved compared with the one in XP/2003. You can now set rules to control both the inbound and outbound connections :)

Albert Research said...

I am using it also... but it is far less intuitive and far les secure as the others as it leaks by all the serious tests. If I activate the blocking mode (the one that is that it blocks all outgoing connections that are not explicity allowed) it does not show any dialog to allow the communications if an application wants to access de internet... it just blocks it (good) but to allow it you have to access all the time the firewall snap in to allow this program, and this snap is is really a pain from my point of view...
Once I had a really good firewall.. tiny personal firewall.. this was really good... many customizations could be made... and it worked like a charm... but where is tiny now ??? CA bought the company and made a terrible firewall of it...

Anonymous said...

Yup Tiny firewall was good but I think I didn't work well for me back to the XP days.... FYI

http://www.oldversion.com/program.php?n=tpfirewall

I turned into Kerio Personal Firewall then and later Sunbelt; but stopped using it since I found that the service STOPPED several times without notice on my dual CPU machine at work... Here come the builtin Windows Firewalls era :P

One advantage to the Windows Firewall is that: I, also worked as an admin, could deploy the firewall rules via Active Directory :)

Albert Research said...

Could be... I had some problems with tiny but they where acceptable compared to the other firewall's on those times.. for example Norton wich was really a pain.
I see that I am not the only one who had problems with firewalls before ;-)..
At this very moment I am using the Windows firewall... just because all others failed... but that does not mean that for me this firewall does its job well...