Showing posts with label Firewall. Show all posts
Showing posts with label Firewall. Show all posts

How to enable TDI debugging

To enable TDI debugging in AVG 2012:

1. Update your AVG Program to the latest program and virus database versions (if possible).
2. Download the AVG Service Utility from this location to your Desktop:
http://www.avg.com/filedir/util/support/avgfwdiag2012_en.exe

3. Double-click the downloaded utility to run it.
4. Follow the instructions displayed on your screen.

How to disable AVG Network Redirector ( AVG TDI driver)

To disable the TDI driver:

1. On the Desktop, right-click My Computer, and then click Properties.
2. If the option is available, click the Hardware tab.
3. Click Device Manager.
4. On the View menu, click "Show hidden devices."
5. Expand the "Non-Plug and Play Drivers" option.
6. Right click "AVG TDI driver" (or "AVG Network Redirector") and then select "Disable."
7. Confirm disabling of the driver and restart of computer.

How to import modified CFE in AVG Firewall

To import the Firewall configuration file:

1. Open the AVG Program.
2. On the Tools menu, click "Firewall settings."
3. In the left pane, click General.
4. Under "Settings management" click Import.
5. In the opened dialog box, click Yes and then select the "modified_FW.cfe" file you downloaded to your Desktop.
6. Click Open.
7. Click Apply, and then click OK.
8. Restart the computer.

How to Disable AVG Firewall

To temporarily disable AVG Firewall:

1. Open AVG.
2. Click on Firewall component.
3. Select Firewall disabled, and then click Save changes. When prompted, confirm turning off the Firewall.

How to run AVG Firewall Diagnostics

Follow these steps to help us find the cause of the issue:

1.Update your AVG Program to the latest program and virus database versions (if possible).
2. Download the AVG Service Utility from this location to your Desktop:
http://www.avg.com/filedir/util/support/avgfwdiag2012_en.exe

3. Run the utility.
4. Follow the instructions displayed on your screen.

AVG Firewall Error

To rectify your issue, take the following steps:

A) Check whether any program on your computer might be in conflict with AVG Firewall (such as another firewall, network filtering/monitoring utility, or anti-virus), try to remove the conflicting program.

B) If no conflicting program is installed, try resetting the Firewall configuration, this will resolve issues caused by a corrupted configuration:

To reset the Firewall configuration:
1. Open the AVG Program.
2. Click the Firewall component.
3. Click Regenerate configuration.
4. Follow the displayed steps to reset your firewall configuration.
5. Restart the computer.

After restarting the computer, you may be presented with AVG Firewall dialogs related to applications you have previously allowed or blocked.

C) If the issue persists, perform a repair installation of AVG

To perform a repair installation of AVG:
1. Download the latest installation file from this webpage:

http://www.avg.com/download.prd-isc.line-2012
(AVG Internet Security 2012)

2. Click the "Download" button, and when asked, choose to save the file.
3. Choose the Desktop, and then click Save.
4. Double-click the AVG installation file.
5. Click Repair installation and follow the wizard.
6. When the installation is complete, restart the computer.

D) If the issue persists even after the repair installation, send AVG Support the diagnostic data from your computer.

To send AVG Support the diagnostic data:
1. Download runner.avgdx on this link:
http://www.avg.com/filedir/util/support/runner_en.exe

2. Double-click the file, the AVG Diagnostics tool will start automatically.
3. Type your e-mail address and a detailed issue description into the appropriate areas.
4. Click "Diagnose and send results.”

This will provide AVG Support with additional program data and log files, which will allow them to further analyze the issue and find the proper solution.

How to allow IGMP in AVG Firewall

To configure the AVG Firewall to allow the IGMP follow the steps below:

A) Connect your device to the computer.

B) Disable area detection and automatic profile switch:
1. Open the AVG Program.
2. On the Tools menu, click "Firewall settings."
3. In the left pane, click "Areas and Adapters profiles."
4. Select the "Disable area detection and automatic profile switch" check box, and then click Apply.

C) Create a safe network (this would be the device IP).

Skip this procedure if you already have a safe network configured in your Firewall.

1. Open the AVG Program.
2. On the Tools menu, click "Firewall settings."
3. Select the firewall profile that you are using.
4. Click "Defined networks," and then click "Add network."
5. Type a short name for the network (for example Your_device).
6. Select the "Network is safe" check box.
7. Click "Add IP."
8. Fill in the needed values defining your local network (i.e. IP address of your device, or IP range of your local network).
9. Click OK.

D) Create a new system rule.
1. Open the AVG Program.
2. On the Tools menu, click "Firewall settings."
3. In the left pane under Profiles, expand your firewall profile.
4. Click "System services," and then click "Manage user system rules."
5.Click Add, and then set the following data:

Protocol: IGMP (this option is under "Other known protocols")
Direction: Both ways
Remote address(es): Your safe network
Rule detail name: "DeviceName"

E) If the issue persists, send the AVG diagnostic data for further analysis to AVG Support.
1. Download runner.avgdx on this link:
http://www.avg.com/filedir/util/support/runner_en.exe

2. Open the AVG Program.
3. On the Tools menu, click "Firewall settings."
4. In the left pane under Profiles, select your firewall profile, and then click "System services."
5. Select the “Log unknown incoming traffic” check box, and then click OK.
6. Induce the issue again.
7. Run the "runner.avgdx" file once again.
8. Type your e-mail address and a detailed issue description into the appropriate areas.
9. Click "Diagnose and send results."

AVG Support should receive the logs for further analysis and contact you with further information.

How to Blacklist an IP Address with AVG Firewall

To block incoming and outgoing traffic related to a particular IP address or range of IP addresses, follow these steps:
1. Open the AVG Program.
2. On the Tools menu, click "Firewall settings."
3. In the left tree menu, expand your current profile, and then click "Defined networks."
4. In the "Networks" column, double-click the "IP addresses blacklist" row, and then click "Add network."
5. Type a name into the "Network name" field, and then click "Add IP."
6. Click "One IP address," and then fill in the following value (for a single IP address):

<Blocked IP address>

You can also block a range of IP addresses by clicking "IP address range," and then filling in the needed values.

7. Save all changes by clicking OK.

How to allow blocked communication with AVG Firewall

To allow the blocked communication, proceed as follows:

1. Open the AVG Program.
2. On the Tools menu, click "Firewall settings."
3. Locate the profile you use in the left navigation tree, and then click "System services."
4. Click "Manage user system rules."
5. In the new window, click Add.
6. Under "Rule detail name," type a name for the service.
7. Specify the desired values for:

- Protocol ****, direction IN, local port(s) XXXX, remote port(s) XXXX, remote address(es) XXXX
- Protocol ****, direction OUT, local port(s) XXXX, remote port(s) XXXX, remote address(es) XXXX

8. In the "Allow for all" option, click "Allow for safe."
9. Confirm all changes by clicking OK.

How to open a specific port in AVG Firewall

Follow these steps to allow a specific port:

1. Open the AVG Program.
2. On the Tools menu, click "Firewall settings."
3. In the left tree menu under Profiles, expand the profile you are currently using.
4. Click "System services."
5. Click "Manage user system rules," and then click Add.
6. In the new window, for "protocol," select "TCP"
7. For "direction," select "Both ways," and then click OK.
8. For "local port(s)," click "User selected ports; check a port in the list or add your own to the edit box", type the port you need to open, and then click OK.
9. For "remote port(s)," select "All ports (0 - 65535)," and then click OK.
10. For "remote address(es)," select "All Networks," and then click OK.
11. Confirm all windows by clicking OK.

How to Whitelist an IP address in AVG Firewall

To allow incoming and outgoing traffic related to a particular IP address or range of IP addresses, follow these steps:

1. Open the AVG Program.
2. On the Tools menu, click "Firewall settings."
3. In the left tree menu, expand your current profile, and then click "Defined networks."
4. In the "Networks" column, double-click the "IP addresses whitelist" row, and then click "Add network."
5. Type a name into the "Network name" field, and then click "Add IP."
6. Click "One IP address," and then fill in the following value (for a single IP address):

<Allowed IP address>

You can also allow a range of IP addresses by clicking "IP address range," and then filling in the needed values.

7. Save all changes by clicking OK.

AOL Problem with AVG Firewall

According to the information provided on the AOL web site, you need to allow specific communication in AVG Firewall.

To configure AVG Firewall:
1. Open the AVG Program.
2. On the Tools menu, click "Firewall settings."
3. Locate the profile you use in the left navigation tree, and then click "System services."
4.Click "Manage user system rules."
5. In the new window, click Add.
6. Under "Rule detail name," type AOL1.
7. Set the following data:

Protocol: TCP
Direction: In
Local Ports: 5190-5193
Remote Ports: All ports (0 - 65535)
Remote address - select All Networks
Allow for all

8. Click OK.

- Please follow the same steps and name the other rules AOL2, AOL3, etc.
- Create rules for the following communication:

Protocol: UDP
Direction: Out
Remote Ports: 5190-5193
Local Ports: All ports (0 - 65535)
Remote address - select All Networks
Allow for all

Protocol: TCP
Direction: Out
Remote Ports: 443
Local Ports: All ports (0 - 65535)
Remote address - select All Networks
Allow for all

Protocol: ICMP
Direction: Out
ICMP protocol port number: 3
Remote address - select All Networks
Allow for all

Protocol: ICMP
Direction: Out
ICMP protocol port number: 4
Remote address - select All Networks
Allow for all

9. Confirm all by clicking OK.

Try to connect to AOL now. Please let us know if these procedures solved the issue.

B) If the issue persists, we would like to request AVG configuration and log files for analysis.
To provide these files:
1. Open the AVG Program.
2. On the Tools menu, click "Firewall settings."
3. In the left pane, click Profiles, and then select your firewall profile.
4. Click System services, and then select the "Log unknown incoming traffic" check box.
5. Induce the issue again.
6. Click OK.
7. Download runner.avgdx on this link:
http://www.avg.com/filedir/util/support/runner_en.exe

8. Double-click the file, the AVG Diagnostics tool will start automatically.
9. Type your e-mail address and a detailed issue description into the appropriate areas.
10. Click "Diagnose and send results."

AVG Support should receive the data and contact you with further information.

How to enable Allow All profile in AVG Firewall


Change the AVG Firewall profile to Allow all:

1. Open AVG.
2. Click the Firewall component.
3. In the drop-down menu, select Allow all.
4. Click Save changes.

AVG Firewall Profiles, Area Detection and Automatic Profile Switch

The Profiles, Area Detection and Automatic Profile Switch are closely related features of AVG Firewall. This FAQ topic describes what they are and how they work, allowing you to configure AVG Firewall exactly according to your needs.

1. What is the Profile?

Profile in AVG Firewall is a complete set of Firewall configuration. AVG Firewall has a default set of profiles that contains specific settings for these areas:
  •     adapters
  •     networks
  •     safe networks/adapters
  •     application rules
  •     system rules
  •     services
  •     logging options
The result of this is the possibility to set up multiple AVG Firewall configurations and use them in the networks you connect to, based on your security requirements.

2. What is Area Detection?

Area Detection is the ability of AVG Firewall to distinguish which network is the computer currently connected to. The detection is independent of the used adapter, network configuration and network type. If you connect a laptop with AVG Firewall installed to one Wi-Fi network, you will receive an Area Detection dialogue where you can assign the profile you want to use. When connecting to another Wi-Fi network, the Area Detection dialogue will be displayed again, even if the network configuration is exactly the same and the only difference is in the Wi-Fi router/hotspot.

This function allows you to create a custom configuration for each single network you connect to.

3. What is the Automatic Profile Switch?

By combining the Profiles with the Area Detection, it is possible to automatically assign any profile to any network. Each profile contains its own configuration, each network is recognized as a new area.

Example:

When you connect your computer to a company network, the Area Detection dialogue is displayed. You decide to use the profile "Computer within domain," because the network is protected by gateway and other internal security measures. Then you decide to connect to the company network using Wi-Fi. Again, Area Detection is displayed and "Computer within domain" is the best choice.

Then, you take your laptop and go to a café with a public Wi-Fi hotspot. A new area is detected again, and you select profile "Directly connected to the Internet" to block all unwanted traffic (e.g. file sharing). This area is recognized, even though you are using the same Wi-Fi adapter, and the network configuration (IP, Gateway, etc.) is identical to that at work.

Finally, you connect at home using cable. Once again is the area detected, and you select profile "Small home or office network".

Once you connect to these networks for the second time, the desired profile will be selected automatically based on your previous choice.

Each of the profiles used in this example has different settings for applications (e.g. Skype, FTP Server, ICQ, Internet browser), system rules (file sharing, RDP, RPC, etc.) and all other options, so for each network you connect to, the required security level is always maintained.

AVG Firewall Safe Networks

In AVG Firewall, it is possible to set some networks (IP ranges) as Safe. At the same time, rules for applications or system services can be allowed only for Safe networks. The combination of the two allows you to configure your Firewall to protect your computer from unwanted network connections, while allowing all required communication from and to known sources.

Note:
The configuration of Safe networks can be combined with Automatic Profile Switch functionality.

Safe networks
configurable in the AVG program - menu Tools - Firewall settings - Profiles - your profile - Defined networks


To be able to set some network as Safe, it is necessary to create it first using the button "Add network". Once you create the network (in other words custom list of IP addresses), you can specify that this network will be safe. "Allow for all" rules are applied to all networks including the safe ones, and "Allow for safe" is applied only to the safe network. For example:

  •     create a new network (e.g. 192.168.0.1 - 192.168.0.100) and mark it as Safe
  •     set Microsoft File Sharing and Printing as Allow for safe
  •     if the other computer is in the IP range specified when creating the network, it will be able to   connect and browse your shared files
  •     connections from different IP addresses will be blocked

This way, you can allow sharing of your files or network resources (or allow any other communication) only to strictly specified list of IP addresses/computers.

"Allow for safe" rules are stored individually for each profile. This allows you to create fully customized sets of configuration for any network you are connecting to.

If you have the profile "Small home or office network" in your AVG, some rules which are typically required in this scenario (MS File Sharing and Printing, Replies to ICMP diagnostics) are already marked as Allow for safe. It is therefore only necessary to set some adapter or network as safe to gain full advantage of this profile.

There is also an option to use IP addresses whitelist/blacklist. When some IP address is entered into these two dialogs, all outgoing and incoming communication will be allowed (whitelist) or blocked (blacklist). IP addresses whitelist/blacklist can be found in the Firewall settings -> <used profile> -> Defined networks.

Allow Microsoft Sharing - Safe Networks in AVG Firewall

The default AVG Firewall configurations for the "Directly connected to the Internet" and "Small home or office network" profiles do not allow "Microsoft file sharing and printing" protocol. This must be enabled manually.

A) To enable the “Microsoft sharing and printing” protocol:
1. Open the AVG Program.
2. On the Tools menu, click "Firewall settings."
3. In the left tree menu, under Profiles, select your firewall profile.
4. Click "Defined networks," and then click "Add network."
5. Type a brief network name (for example Local network).
6. Select the "Network is safe" check box, and then click "Add IP."
7. Fill in the needed values defining your local network, and then click OK.
8. In the left tree menu, under Profiles, select your firewall profile.
9. Click "System services."
10. In the "MS Printer and File Sharing" line, click the Action field, and then click "Allow for safe."
11. Click OK.

B) If the issue persists, please proceed as follows to find the cause of the issue:
Change the Firewall profile to "Allow all":
1. Open the AVG Program.
2. Click the Firewall component.
3. In the drop-down menu, click "Allow all."
4. Click "Save changes."

C) Temporarily disable AVG Firewall:
1. Open the AVG Program.
2. Click the Firewall component.
3. Click "Firewall disabled," and then click "Save changes."

D) If the connection is OK after the changes in procedures B or C, we would like to request .log and configuration files for detailed analysis. If the issue is not solved even after performing procedures B and C, the issue is likely not caused by AVG Firewall:

1. Open the AVG Program.
2. Click the Firewall component.
3. Click "Firewall enabled."
4. Select your default firewall profile, and then click "Save changes."

To provide the requested files for analysis:
5. Download runner.avgdx on this link:
http://www.avg.com/filedir/util/support/runner_en.exe

6. Double-click the file, the AVG Diagnostics tool will start automatically.
7. Type your e-mail address and a detailed issue description into the appropriate areas.
8. Click "Diagnose and send results."

AVG Support should contact you with further information.

Allow Microsoft Sharing - All Networks in AVG Firewall

The default AVG Firewall configurations for the "Directly connected to the Internet" and "Small home or office network" profiles do not allow "Microsoft file sharing and printing" protocol. This must be enabled manually.

A) To enable the “Microsoft sharing and printing” protocol:
1. Open the AVG Program.
2. On the Tools menu, click "Firewall settings."
3. In the left tree menu, under Profiles, select your firewall profile.
4. Click "System services."
5. In the "MS Printer and File Sharing" line, click the "Action" field.
6. Click "Allow for all," and then click OK.

B) If the issue persists, proceed as follows to find the cause of the issue:

Change the Firewall profile to "Allow all":
1. Open the AVG Program.
2. Click the Firewall component.
3. In the drop-down menu, click "Allow all."
4. Click "Save changes."

C) Temporarily disable AVG Firewall:
1. Open the AVG Program.
2. Click the Firewall component.
3. Click "Firewall disabled," and then click "Save changes."

D) If the connection is OK after the changes in procedures B or C, send AVG Support the .log and configuration files for detailed analysis. If the issue is not solved even after performing procedure B and C, the issue is likely not caused by AVG Firewall:

To provide AVG Support the files required for analysis:
1. Open the AVG Program.
2. Click the Firewall component.
3. Click "Firewall enabled."
4. Select your default firewall profile, and then click "Save changes."
5. Download runner.avgdx on this link:
http://www.avg.com/filedir/util/support/runner_en.exe

6. Double-click the file, the AVG Diagnostics tool will start automatically.
7. Type your e-mail address and a detailed issue description into the appropriate areas.
8. Click "Diagnose and send results."

AVG Support should contact you with further information.

What to do when AVG Firewall is blocking your application or connection

A) Check whether any application on your computer might be in conflict with AVG Firewall (such as another firewall, network filtering/monitoring utility, or anti-virus), try to remove the conflicting program.

B) Try resetting the Firewall configuration; this will overwrite the current configuration:
To reset the Firewall configuration:
1. Open the AVG Program.
2. Click the Firewall component.
3. In the Firewall Component window, click Regenerate configuration.
4. Follow the displayed steps to reset your firewall configuration.
5. Restart the computer.

C) Disable area detection:
1. Open the AVG Program.
2. On the Tools menu, click Firewall settings.
3. In the left tree menu, click Areas and Adapters profiles.
4. Select the “Disable area detection and automatic profile switch” check box.
5. Click OK.

D) Change the Firewall profile to Allow all:
1. In the Firewall Component window, on the Select Firewall profile drop-down menu, click Allow all.
2. Click Save changes.

E) Disable the Firewall component:
1. In the Firewall Component window, click Firewall disabled.
2. Click Save changes.