Friday, May 17, 2013

How to setup Comodo Firewall - IP Binding through MAC address

These rules will work with or without a router.This is a good way to make sure any application(s) you choose,will only run through your vpn connection.

This will configure Comodo Firewall to allow specific applications, to access to the internet,only when HMA VPN is active.

With Comodo firewall (100% free version), you can set a network zone based on an adapters MAC, make a pre-defined rule for that zone, and apply that rule to certain applications.

A. Create a network zone, Get the MAC for the TAP-Win adapter
1. (XP) Start / Run and type CMD, press enter.
(Win7) Start and type CMD, press enter.
2. You should see a black box called a DOS box with a blinking cursor.
3. Type IPCONFIG /ALL
4. Look in the mess of junk for the section that says TAP-Win32.
5. You need the part that says Physical Address . . . . . . 00-??-??-??-??-??
6. Leave this window open for now.
Alternative way to find out the TAP-adapters MAC address:

Go to -> Control Panel\Network and Internet\Network Connections
1) Right Click the Tap-win adapter
2) Click Status
3) Click Details
The MAC address is the physical address, which you can't select on its on so you can either just write it down or
4) Ctr+C to copy and paste entire window into Notepad


B. Create network zone, Add in Comodo
1. In Comodo, go to Firewall / Advanced / Network Security Policy / My Network Zones
2. Add / New Network Zone
3. Name it HMA MAC (press apply)
4. Select HMA MAC
5. Add / New Address
6. Choose "A MAC Address" and enter the Physical Address from earlier.
7. You should see your new Zone with the New rule.
8. Press OK.

C. Make a Pre-Defined Rule
1. Open Firewall / Advanced / Predefined Firewall Policies
2. Click ADD
3. Enter a Name, HMA Only
4. Add...
Action: Allow
Protocol: IP
Direction: In
Source Address: Any
Destination Address: Zone / HMA MAC
Apply

5. Add...
Action: Allow
Protocol: IP
Direction: Out
Source Address: Zone / HMA MAC
Destination Address: Any
Apply

6. Add...
Action: Block
Protocol: IP
Direction: In/Out
Source Address: Any
Destination Address: Any
Apply
Apply
Apply

7. You should now have 2 green rules and then a Red one.


D: Apply rule to Applications
1. Open Firewall / Advanced / Network Security Policy / Application Rules
2. Choose the application that should only work with HMA active, or add an new one.
3. It will open to "Application Network Access Control"
4. Here choose the Predefined Policy "HMA Only"
5. If there are other rules already, they will be removed.To keep any existing settings, you'll have to improvise here.
6. Apply
7. OK.

Do this to all apps that should only access through the HMA VPN Connection

E. Testing...
1. In the above example, I made a rule for Google Chrome.
2. Disconnect from HMA
3. Open Chrome - it is unable to load the home page.
4. Enable HMA
5. Refresh Chrome - it worksBig Grin

I added a few more applications.
Open Firewall / Advanced / Network Security Policy / Application Rules *Make sure your applications refer to "HMA Only" and your covered.


Here's the download link for Comodo Firewall Free Edition:
http://www.comodo.com/home/download/down...d=firewall /
http://downloads.comodo.com/cis/download...taller.exe
(32/64bit installer)

No comments:

Post a Comment