PiTBoSs and Zone Alarm

ColonelSanders

Chieftain
Joined
Jan 6, 2006
Messages
31
Location
UK
Hi all,

Has anyone had any experiences with ZoneAlarm Pro (fully up to date, latest version) and the PiTBoSs beta?

Using program control I have provided PiTBoSs with client and server rights to trusted and internet zones. However, I can see in the logs that ZA is blocking in-coming PiTBoSs requests (port 2056).

Am I missing something or is ZoneAlarm misbehaving?

I was under the impression that ZoneAlarm's program control made it un-necessary to manually configure individual ports.

Cheers

Andy

PS. I am running the PiTBoSs server on my only machine (Win2K). I myself am not logged in to the game when these external connection attempts come in.
 
do you have security for the Internet zone set to high? I think my wife had to reduce it to medium to make it work.

I don't use ZoneAlarm on my own machine so I'm not particularly familiar with how it works, but I'm surmising that "high" overrides program-specific settings while "medium" allow those settings to take effect.

-ken
 
Hi kgober,

Thanks for the suggestion.

I've just had a quick look at the settings of medium vs high, but it doesn't look like this should be the cause of the problem. However, it is good to have verification that someone else has also had ZoneAlarm/PiTBoSs problems.

If you go to Firewall -> Main -> Custom -> Internet Zone, you will find the following statement:
"High security blocks all network traffic except authorized program traffic and traffic indicated by a check mark"

This suggests to me that ZoneAlarm should be letting the connection in. I have specifically told ZoneAlarm that the pitboss progam is authorized to accept in-coming connections :(

By the way, I recommend your wife resets her internet protection to high when not playing Civ IV. Her machine will be much more vulnerable to attack with the medium setting. Looking at the options for "medium", it seems like it would be better called "minimal".

Cheers

Andy
 
Hi kgober, I have had another look at the custom settings for medium/high security. In the end, I settled for simply opening up port 2056 for incoming and outgoing UDP connections. This allows me to leave the internet on High Security.

I know this sounds like a sensible solution, but it means that ZoneAlarm is not working as advertised. ZoneAlarm should be opening port(s) as and when required by an application (in this case, pitboss). The ports should remain closed at all other times.

Oh well, ZoneAlarm is proving to be a bit of a pain. Scree's pitboss emailer script is also being tripped over by it. I may have to look for an alternative firewall solution.

Regards,

Andy
 
Top Bottom