Author Topic: Configuring Vista firewall outbound rules  (Read 6819 times)

0 Members and 1 Guest are viewing this topic.

jellaby

  • Guest
Configuring Vista firewall outbound rules
« on: March 05, 2008, 09:25:54 AM »
I have blocked all outbound connections on my Vista firewall, and I am making outbound rules to allow Avast to update and run normally.  I have made an outbound rule for every .exe file in the Avast folder, but when I update Avast, it says that the file that is not allowed to connect to the internet is something called, "avast.setup" and "avastXX.setup" (where XX is a number). 

This is true, because I have not been able to locate the file within Vista Firewall's Outbound rule making wizard.  From what I can gather from some other forums, Avast creates avast.setup when it updates and then deletes it when the update is completed.  So, the question is, how can I make a rule for an .exe file (I think it is an .exe file) that Avast creates and deletes when updating?

Please help...I need to update Avast.

btw-except for this problem, although I've found Vista's firewall to be somewhat tiresome in forcing me to create a rule for every program that wants to make an outbound connection, I am finding it easy to use as an amateur.  The challenge is finding all the little .exe files that you need for all your programs to function.  It is frustrating when you can't seem to find the program that you need to allow your software to function normally.  I wish there was a list somewhere.  Note to Avast: you need to post a primer on how to config Vista Firewall Outbound rules to allow Avast to connect seamlessly.   

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89611
  • No support PMs thanks
Re: Configuring Vista firewall outbound rules
« Reply #1 on: March 05, 2008, 02:33:09 PM »
There should only be one occurrence of avast.setup so it would appear that there were multiple occurrences which shouldn't happen. Perhaps if you initiated a manual update whilst the auto update is running (or had stalled) that might happen, but I can't say for sure.

The avast.setup file isn't a permanent file and is only created at the time of update (and is removed when the update is complete), so I don't know if that might also be a factor in the windows vista firewall.

Two other files/providers that require internet connections, ashMaiSv.exe (the Internet Mail Provider, email scanner) and ashWebSv.exe (the Web Shield provider, scans http content).

I don't know if you might find this helpfull - Vista Firewall Control, check out this topic for some user friendly help for the Vista Firewall, Outbound protection, http://forum.avast.com/index.php?topic=30234.0
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free  24.8.6127 (build 24.8.9372.862) UI 1.0.814/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Configuring Vista firewall outbound rules
« Reply #2 on: March 05, 2008, 02:48:10 PM »
What I've done with other firewalls to catch this elusive little guy. I waited for an auto update to occur, then answered yes and remember answer. This put the file name in the firewall's allowed list. from there it can be configured. Maybe this will also work with Vista's firewall?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67185
Re: Configuring Vista firewall outbound rules
« Reply #3 on: March 05, 2008, 03:04:31 PM »
Into the firewall settings, the following programs should be allowed to connect:

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (avast! Web Scanner)
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (avast! e-Mail Scanner Service)
C:\Program Files\Alwil Software\Avast4\Setup\avast.setup (avast! Update executable). This is a temporary file that just appears when an update (check) is about to launch, and disappears again afterwards.

Don't need rights to connect:
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (avast! Update Service)
C:\Program Files\Alwil Software\Avast4\ashServ.exe (avast! antivirus service). Although, ashServ.exe sends ping packets to find out if the Internet connection is alive. You can turn this off by checking the "My computer is permanently connected to the Internet" box in the avast Program Settings > Update (Connections) page.
The best things in life are free.

jellaby

  • Guest
Re: Configuring Vista firewall outbound rules
« Reply #4 on: March 05, 2008, 07:29:40 PM »
You are telling me stuff I already know.   :-\ I know that avast.setup is created and goes away when there is an update.  It's in my original post.  Apparently this file needs to get through Vista's firewall to run the updates for Avast, and I need to create an outbound rule to allow it to do so.  I'm not sure how to do that.  I've made rules for all the other files mentioned in the other replies (and more), so I know it is not those. 

Vista's firewall does not alert when an outbound program tries to connect to the internet, so I have no way of knowing when Avast is updating, and more importantly, I have no option to make the exception.

Do you see the problem?   

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67185
Re: Configuring Vista firewall outbound rules
« Reply #5 on: March 05, 2008, 07:41:13 PM »
Yes, I can only tell you that setup.ovr file from <avast>\setup folder is 'transformed' into avast.setup. This file, and not an executable, connects the Internet to update. This transformation, as far I know, is done by VisthUpd.exe at system account.
More, only the programmers could say. Sorry if I'm not being useful.
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89611
  • No support PMs thanks
Re: Configuring Vista firewall outbound rules
« Reply #6 on: March 05, 2008, 07:50:05 PM »
If Vista firewall allows you to just enter the full path to the file (rather than navigate to it) then copy and paste this path, C:\Program Files\Alwil Software\Avast4\Setup\avast.setup, avast.setup isn't an exe file. This assumes you installed avast in the default location.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free  24.8.6127 (build 24.8.9372.862) UI 1.0.814/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

jellaby

  • Guest
Re: Configuring Vista firewall outbound rules
« Reply #7 on: March 05, 2008, 09:52:00 PM »
Thanks, guys.  I will try it this evening.  I apologize if I sounded snippy.  I do appreciate your help.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89611
  • No support PMs thanks
Re: Configuring Vista firewall outbound rules
« Reply #8 on: March 05, 2008, 11:45:13 PM »
No problem, welcome to the forums.

Good luck.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free  24.8.6127 (build 24.8.9372.862) UI 1.0.814/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67185
Re: Configuring Vista firewall outbound rules
« Reply #9 on: March 06, 2008, 12:15:47 AM »
I apologize if I sounded snippy.
Don't worry ;)
The best things in life are free.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Configuring Vista firewall outbound rules
« Reply #10 on: March 06, 2008, 04:57:31 AM »
Yes, let us know if that will work. Hmm, just learned something about vista firewall.  :D

jellaby

  • Guest
Re: Configuring Vista firewall outbound rules
« Reply #11 on: March 06, 2008, 06:14:42 AM »
I got it working!  ;D  For anyone who may stumble on this post in the future:

I followed the directions found at this link to block all outbound connections through windows firewall.
http://www.komando.com/tips/index.aspx?id=2973
The document tells you in a very clear way how to create rules to allow outbound programs to go through the firewall.  I created a rule for every .exe file that was in the Avast folder in my Program files.  I probably didn't need to do it for every one, but it was easier than trying to figure out which ones didn't need it. 

Then, I couldn't update.  Avast tried to connect to the server, but was being blocked by the firewall.  I only knew it was the firewall because it updated fine before I followed the directions to block all outbound connections, as Vista's firewall does not alert when a program attempts to connect and is blocked. 

The problem is, that when Avast updates, it needs a specific file called avast.setup to connect to the server.  It is located in the "Setup" folder.  To create a rule for it, in the rule making wizard, I could not browse to choose the program, because avast.setup is not an .exe file.  So, I did what DavidR said to do above: type in the path to the file, instead of navigating to it.  That did the trick.  I feel somewhat silly for not trying that, but oh well.  Live and learn. 

Now if only I could figure out how to allow a Windows Update without creating an outbound rule for svchost.exe, which I am told creates a vulnerability. 

Many thanks, gents.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Configuring Vista firewall outbound rules
« Reply #12 on: March 06, 2008, 07:32:46 AM »
Glad you got it going. I have a question.

Since vista firewall doesn't ask/notify when something is trying to access the internet, what happens when that particular exe is modified? Is there a provision in the firewall to notify you something has changed?

For example, when the avast program is updated, webshield for example, is a different version. Most firewalls will notify you that it has changed since you last used it. It will not be allowed access until you allow it. Question is, does vista firewall allow for this, or does it block/allow according to name and path?

Just trying to learn a bit about this firewall.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67185
Re: Configuring Vista firewall outbound rules
« Reply #13 on: March 06, 2008, 01:25:42 PM »
Since vista firewall doesn't ask/notify when something is trying to access the internet, what happens when that particular exe is modified? Is there a provision in the firewall to notify you something has changed?
No there isn't... the check is done only by the path basis.
The best things in life are free.