Overall Firewall situation

I know this question has been brought up so many times, usually in this boring tone “…hello, I want to use firewall, what is the best one out there ?..”, but still I’ve decided to start this thread so we can try to have a nice discussion on what’s going on out there…

As we all know, firewall scene is pretty chaotic last few months, to be more precise, actually since Vista came out. Sad thing is, we still have this ugly situation where not so many products support this “new” OS. Our choices are limited to very few products which of some are so bad that sadly the only purpose of installing them is to add another system resources hog to your startup list. What is going on with these products lately ? Is it so hard to come up with some good and working firewall, light on system resources and to do what is supposed to do ? We are witnessing the era of bloated products full of some stupid features that normal ordinary person will never even use and not to mention to try to understand how it works and why is like that… what we need is a simple but effective inbound and outbound protection. The Little Snitch is the best possible example of a great product. True there is OS X only version, but if we could get something like that for PCs that would change everything, trust me. It is such a wonderful product, so light on resources, perfectly designed, with a load of returning information to the user (of course you can disable every single thing you don’t want to be bugged by…), I am sure PC users would be happy to have something like this on the menu.

Not sure how far Alwil firewall development is at this point, but I remember Vlk asked once in these forums what we like about Comodo… IMHO it would be a lot better thing to develop something that looks and acts more like The Little Snitch than like Comodo which became one of those bloated firewalls…

Any thoughts ? Remember, healthy discussion is what we are looking for… not trolling and fighting about which product is better than the rest of products out there… in this thread, simple end user should be the central point of this whole discussion. What is the best firewall solution out there, and when I say that I mean for simple computer user, for normal person, every day PC user.

Thanks to all who will contribute this way or another to this discussion.

Cheers!

Hello. I have recently used the new Webroot Desktop Firewall on my XP Machine and liked it. I believe it’s for Vista as well. I had it in Learning Mode and when I took it off I had very few pop ups. It comes with a HIPS program called Dynamic Security Agent that can be enabled if you want while in Learning Mode and offers pretty decent protection. You can check out what people are saying about it in the Wilders Security Forums under the section "Other Firewalls. Just google Wilders to find it. Also you can check out the Webroot Website and read about the FW. It installed easily and uninstalled better than any Firewall or other security program for that matter that I ever used. I am currently using the 1 year free Zone Alarm AntiSpyware with FW and it’s good, but I may go back to WDF with DSA soon. A lot of time was put into this product and it shows, however it does take a little time to get a feel for where some of the added features are.

I got rid of Zone alarm free last week and switched to Comodo Pro 2.14.8.184. Things are much better my lost connetivity problem is gone. Here is a link from the Comodo site for a video on how to configure http://forums.comodo.com/frequently_asked_questions_faq_for_comodo_firewall/noob_install_video_guide-t4766.0.html
Joe

Thanks to these two new forum members, I really do appreciate your input.

C’mon people… where are all those old avast! forum members ? I thought this could be nice thread to start a nice and healthy discussion… not a single reply from you guys. So it looks like starting this thread wasn’t that good idea in the first place… am I right when I say that?

As I mentioned in the beginning… I didn’t open it so we can start lining up all those firewalls we used to use… we all know pretty much everything about all of them. What I had in mind when I started this thread was to discuss what do we really need, what would we like to see inside some possible new firewall… things that are missing with all these well known firewalls out there, things that are there but not really useful…

Sorry Sasha but this is just another Firewall thread among many others.
To me, it’s simply re-hashing the same topic for the ???'s time. ;D

I would simply like to find one FW that’s easy to use, passes all the tests, uses very little system resources
and is compatible with all the operating systems.

I don’t think that’s to much to ask for. (is it ??? )

Yes almost true… except no one else mentioned The Little Snitch before, and I would really like to hear from Alwil what do they think of it and possibility to do something wonderful like that for PC. You should really see how it looks like and how it does what’s supposed to do, there is simply no better solution for Mac when it comes to protecting your outbound/inbound traffic. Is there any way we can have something similar on PCs ?

I’d like a simple free FW with very good inbound outbound defense but no HIPS, parental control,aplication behaviour,etc etc etc, please) with low resource usage and no slow down boot PC. If i need HIPS there a are lot of programs, even free. I think HIPS can be awsome, but if you are a power user, because if u aren’t, usually allow all.

I agree with that, broadly. I’ve never been a big fan of locking down the computer: it always causes problems. HIPS in Kerio used to cause a fair number of BSOD’s.

HIPS in CPF 3 was a nightmare, although that was the Beta.

CPF 2 does an excellent job of preventing Trojans phoning home without being too intrusive or resource hungry. I seen people posting here to say it has blocked malicious activity several times.

ZA seems to provide good inbound defence without noticeable slowdown: I’m not too bothered about ‘leak tests’ because I know enough to avoid Trojans.

At the moment I’m just behind a router firewall in Ubuntu. I used Firestarter before I got the router, but just to hide my ports: in Ubuntu they aren’t open anyway. The router hides my ports now, so no firewall to take up resources. </smug mode> 8)

I second this too.

Right now ZA, PcTools and Comodo. Later two have problems in my system.
http://forum.avast.com/index.php?topic=31193.msg263084#msg263084

The version 3 adds HIPS. This seems bloat to some users. Others like it.

Do you have the chance to test it on Vista?