Microsoft-vista firewall is blocking uploads to seti.

Questions and Answers : Windows : Microsoft-vista firewall is blocking uploads to seti.
Message board moderation

To post messages, you must log in.

AuthorMessage
Profile jay_e

Send message
Joined: 6 Apr 03
Posts: 62
Credit: 1,072,112
RAC: 0
United States
Message 1585970 - Posted: 12 Oct 2014, 21:54:36 UTC

Greetings!!

My anti-virus (Avira) stopped supplying firewall protection - and now I am *trying* to figure out Microsoft (Vista) firewall settings.

Please help.

If I turn the firewall off, I can upload SETI results.
If the firewall is on, no can do.
So, its not a network load or seti server problem.

Mainly, I fail to comprehend the Microsoft instruction.....
http://technet.microsoft.com/library/cc732283%28WS.10%29.aspx
says
Home users should use the Windows Firewall program in Control Panel instead. To start the Windows Firewall program, click Start, click Control Panel, click Security, and then click Windows Firewall. Help for using the Windows Firewall program can be found either by pressing the F1 key while viewing the main Windows Firewall page or by clicking the links on the Windows Firewall dialog boxes.


The simple Firewall control doesn't have anything for outgoing, it just allows Incoming addresses and ports to be enabled for a program..

a sarcastic note: The help mentioned above takes you to the
"Windows Firewall with Advanced Security".

In controlPanel-> Admin tools -> windows firewall with advanced security
I Look in the center pane and select windows firewall properties.
I verify that all outbound connections are allowed for
- Domain profile
- Private Profile
- Public Profile
I didn't think the IPsec Setting would be involved,
but it had an option to "Exempt ICMP from IPsec", by default the setting was off.
?? should I try changing it??

In the left pane, selecting Inbound rules, and looking at boinc and boinc manager,
both are wide open, any address, any port -for both local and remote - all protocols - all users

In the left pane, selecting Outbound rules, I get a blank.
The trick is to hit refresh and wait 3 minutes... (sarcasm...)
about 40 items in Outbound rules - but nothing specifically for boinc or
boinc-manager
?? should I add a rule here for the two??

In the left pane, selecting connection security rules - no rules.

The only suspicious item was that there is an entry for ICMPv6 - Out (wide open)
but no corresponding rule for ICMPv4
I hope I'm overlooking something obvious...

T H A N K Y O U!!
Jay
ID: 1585970 · Report as offensive
rob smith Crowdfunding Project Donor*Special Project $75 donorSpecial Project $250 donor
Volunteer moderator
Volunteer tester

Send message
Joined: 7 Mar 03
Posts: 22204
Credit: 416,307,556
RAC: 380
United Kingdom
Message 1586100 - Posted: 13 Oct 2014, 5:17:30 UTC

Yes, you need to allow an exception for BOINC, go to:

Control Panel\System and Security\Windows Firewall\Allowed Programs

and select the "change settings" tab, followed by "add a program" tab, the brose to find the running version of the BOINC executable.
Bob Smith
Member of Seti PIPPS (Pluto is a Planet Protest Society)
Somewhere in the (un)known Universe?
ID: 1586100 · Report as offensive
John McLeod VII
Volunteer developer
Volunteer tester
Avatar

Send message
Joined: 15 Jul 99
Posts: 24806
Credit: 790,712
RAC: 0
United States
Message 1588111 - Posted: 17 Oct 2014, 3:37:04 UTC

Yes, the Windows Firewall can block outgoing connections. Here's what you need to enable.

1) BOINC.exe needs outbound access on ports 80 (http) and 443 (https). Some projects require one or the other, some allow either.
2) The daemon (BOINC.exe) needs to accept inbound connections on port 31416 from the local host and the LAN only. It does not need to accept connections from outside the LAN. This is to allow the UI to actually control the daemon.
3) The manager (BOINCMgr.exe) needs to have outbound access on port 31416 to the LAN and local host only. This is to allow the manager to control the daemon.
4) OPTIONAL. BOINCcli (the command line interface) needs the same access as the manager if you are going to use it.

NOTE: Some malware uses port 31416 to phone home. So, you may need to prevent that malware from running if it is - to free up the port.


BOINC WIKI
ID: 1588111 · Report as offensive
Profile jay_e

Send message
Joined: 6 Apr 03
Posts: 62
Credit: 1,072,112
RAC: 0
United States
Message 1591638 - Posted: 24 Oct 2014, 23:43:29 UTC - in response to Message 1588111.  

T H A N K Y O U !!!!

Jay E.
ID: 1591638 · Report as offensive

Questions and Answers : Windows : Microsoft-vista firewall is blocking uploads to seti.


 
©2024 University of California
 
SETI@home and Astropulse are funded by grants from the National Science Foundation, NASA, and donations from SETI@home volunteers. AstroPulse is funded in part by the NSF through grant AST-0307956.