It is currently Fri May 02, 2025 8:57 am

All times are UTC - 8 hours [ DST ]




Post new topic Reply to topic  [ 12 posts ] 
Author Message
Offline
 Post subject: Firewall issue with CGoban, KGS, Zonealarm
Post #1 Posted: Thu Sep 20, 2012 2:54 pm 
Beginner

Posts: 5
Liked others: 0
Was liked: 2
Rank: KGS 10k
KGS: JeetKunGo
Since updating to Java 7, I have been unable to log on to KGS.

CGoban works fine, but when attempting to log on to KGS, I get a message saying "can't connect to the server - the server may be down, please try again later"

I switched off my firewall (Zonealarm free firewall) to see whether this was a firewall issue, and it is, to some extent.

I had to set up an exception on windows firewall to allow the port (I think it's 2379). This solved the problem.

Obviously I am not going to wander round the internet with no firewall on, so this isn't a reasonable solution for me.

I suppose I need a new firewall, but would like to stick with what I have if possible...

Any input welcome.

_________________
In the land of the blind, the one-eyed man got bullied for being a freak, but went on a voyage of self-discovery and realised that it was okay to be different, then came back in disguise and became a highly successful private investigator.

Top
 Profile  
 
Offline
 Post subject: Re: Firewall issue with CGoban, KGS, Zonealarm
Post #2 Posted: Thu Sep 20, 2012 9:50 pm 
Judan

Posts: 6269
Liked others: 0
Was liked: 796
1) Which operating system?

2) When you switched off your firewall for testing, did you revert your system to the state prior to doing so?

3) Yes, a [software] firewall is needed. Zonealarm? It is known to not protect well. If you use Windows, use its firewall!

4) Exception for Java / CGoban? It is indeed possible that you need some. Use your firewall's log to find out what you need.

5) Java 7 is known to have problems with CGoban. Both Java 6 and Java 7 are known to have - different - security issues. Java always has some. Therefore, simply using a firewall is insufficient precaution. If you use Windows, here are more ideas:
http://home.snafu.de/jasiek/windows_sec ... ncept.html
viewtopic.php?p=36505#p36505
Do not forget to deactivate Java in your browser and email client and check again after any program update for each user account.

Top
 Profile  
 
Offline
 Post subject: Re: Firewall issue with CGoban, KGS, Zonealarm
Post #3 Posted: Fri Sep 21, 2012 8:52 pm 
Gosei
User avatar

Posts: 1449
Liked others: 1562
Was liked: 140
Rank: KGS 6k
GD Posts: 892
JeetKuneGo wrote:
Since updating to Java 7, I have been unable to log on to KGS.

CGoban works fine, but when attempting to log on to KGS, I get a message saying "can't connect to the server - the server may be down, please try again later"

I switched off my firewall (Zonealarm free firewall) to see whether this was a firewall issue, and it is, to some extent.

I had to set up an exception on windows firewall to allow the port (I think it's 2379). This solved the problem.

Obviously I am not going to wander round the internet with no firewall on, so this isn't a reasonable solution for me.

I suppose I need a new firewall, but would like to stick with what I have if possible...

Any input welcome.


From http://senseis.xmp.net/?KGSIssueFirewall:
wms wrote:
All you need is outbound traffic from your host to goserver.gokgs.com port 2379. The other ports are standard web server ports (if your firewall blocks them, then you're in trouble anyway).

Actually, port 80 *is* a problem: a browser will happily use a proxy, but CGoban doesn't have an option to.

_________________
a1h1 [1d]: You just need to curse the gods and defend.
Good Go = Shape.
Associação Portuguesa de Go

Top
 Profile  
 
Offline
 Post subject: Re: Firewall issue with CGoban, KGS, Zonealarm
Post #4 Posted: Fri Sep 21, 2012 10:13 pm 
Judan

Posts: 6269
Liked others: 0
Was liked: 796
Calling ports standard webserver ports misses the point. It depends on how strictly one's firewall rules are. If one has configured port 53 to communicate only with one's local provider's DNS server, then another port 53 rule can be necessary for KGS (and its site hosting the start screen ads). If one has allowed port 80 only for one's browser, email client and newsreader, then another rule can be necessary for KGS.

Top
 Profile  
 
Offline
 Post subject: Re: Firewall issue with CGoban, KGS, Zonealarm
Post #5 Posted: Mon Oct 15, 2012 11:17 am 
Beginner

Posts: 5
Liked others: 0
Was liked: 2
Rank: KGS 10k
KGS: JeetKunGo
Thank you for the replies guys. Sorry it took me a while to get back to you.
I did manage to resolve my problem by downloading a historic version of Java - 6.31 - which has avoided the issue.
Link is here: http://www.oracle.com/technetwork/java/ ... 01637.html
As far as I am aware, there is no other way to run CGoban other than with Java (Web Start) - is this correct?

Robert - I appreciate the help in the first post. If you wouldn't mind going through one or two of the points raised, that would be totes spiff. My answers in red:

1) Which operating system?
Windows 7

2) When you switched off your firewall for testing, did you revert your system to the state prior to doing so?
No. I simply closed the firewall program. This solved the problem

3) Yes, a [software] firewall is needed. Zonealarm? It is known to not protect well. If you use Windows, use its firewall!
I am disinclined to pay for a firewall, stupid as this may be. Do you have any reasons why Windows Firewall is preferable to ZA?

4) Exception for Java / CGoban? It is indeed possible that you need some. Use your firewall's log to find out what you need.
ZA is pretty lame, as you outlined above - can't create exceptions for specific ports or programs.

5) Java 7 is known to have problems with CGoban. Both Java 6 and Java 7 are known to have - different - security issues. Java always has some. Therefore, simply using a firewall is insufficient precaution. If you use Windows, here are more ideas:
http://home.snafu.de/jasiek/windows_sec ... ncept.html
Excellent - that's some homework for me!
viewtopic.php?p=36505#p36505
Too opaque for moi. But thanks :)
Do not forget to deactivate Java in your browser and email client and check again after any program update for each user account.
a) done b) don't use one at home - webmail only.
Thanks for the help

_________________
In the land of the blind, the one-eyed man got bullied for being a freak, but went on a voyage of self-discovery and realised that it was okay to be different, then came back in disguise and became a highly successful private investigator.

Top
 Profile  
 
Offline
 Post subject: Re: Firewall issue with CGoban, KGS, Zonealarm
Post #6 Posted: Mon Oct 15, 2012 12:32 pm 
Dies in gote

Posts: 34
Liked others: 3
Was liked: 10
Rank: DGS 18
KGS: Coyote
DGS: Coyote
Years ago when I worked at a cable internet support call center I spoke with a gentleman who couldn't connect to his vpn suddenly. He didn't have a firewall but he could contact everything but his vpn.

Turns out he had uninstalled Zone Alarm a week ago. Reinstalled Zone Alarm, completely disabled it, uninstalled. Now he can connect to his VPN. Since then I've always suggested people avoid ZA.

Windows Firewall is good enough. I've also been using the free windows AV, Windows Security Essentials for over a year now with good success.

Top
 Profile  
 
Offline
 Post subject: Re: Firewall issue with CGoban, KGS, Zonealarm
Post #7 Posted: Mon Oct 15, 2012 2:58 pm 
Judan

Posts: 6269
Liked others: 0
Was liked: 796
JeetKuneGo wrote:
2) When you switched off your firewall for testing, did you revert your system to the state prior to doing so?
No. I simply closed the firewall program. This solved the problem


But... you know that you are running a great risk?! Inbound firewall should always be active, even during tests. Therefore, the proper way was to revert your system together with applying a solution, i.e., activate the Windows firewall before again connecting to the internet.

Quote:
Do you have any reasons why Windows Firewall is preferable to ZA?


Every security expert I have read during the last years has said a) the Windows Firewall is good and b) ZA is bad. (I have not bothered to collect citations for various evidence.)

Top
 Profile  
 
Offline
 Post subject: Re: Firewall issue with CGoban, KGS, Zonealarm
Post #8 Posted: Mon Oct 15, 2012 9:01 pm 
Oza

Posts: 2264
Liked others: 1180
Was liked: 553
JeetKuneGo wrote:
As far as I am aware, there is no other way to run CGoban other than with Java (Web Start) - is this correct?

No that's not correct. You can download and run the jar directly, but unless you already know how to run Java programs on the commandline, its probably easier to just stick with JWS

Top
 Profile  
 
Offline
 Post subject: Re: Firewall issue with CGoban, KGS, Zonealarm
Post #9 Posted: Mon Oct 15, 2012 11:08 pm 
Judan

Posts: 6269
Liked others: 0
Was liked: 796
xed_over wrote:
run the jar directly


But JRE must still be installed?

Top
 Profile  
 
Offline
 Post subject: Re: Firewall issue with CGoban, KGS, Zonealarm
Post #10 Posted: Mon Oct 15, 2012 11:35 pm 
Lives in sente
User avatar

Posts: 844
Liked others: 180
Was liked: 151
Rank: 3d
GD Posts: 422
KGS: komi
RobertJasiek wrote:
xed_over wrote:
run the jar directly


But JRE must still be installed?


Indeed

Top
 Profile  
 
Offline
 Post subject: Re: Firewall issue with CGoban, KGS, Zonealarm
Post #11 Posted: Mon Oct 15, 2012 11:42 pm 
Lives in sente
User avatar

Posts: 844
Liked others: 180
Was liked: 151
Rank: 3d
GD Posts: 422
KGS: komi
Note also that your ADSL router (assuming you have one) will usually be running at least a NAT style firewall, which is a very effective first line of defense.

Top
 Profile  
 
Offline
 Post subject: Re: Firewall issue with CGoban, KGS, Zonealarm
Post #12 Posted: Wed Jan 09, 2013 12:16 pm 
Beginner

Posts: 5
Liked others: 0
Was liked: 2
Rank: KGS 10k
KGS: JeetKunGo
Well, in the end the solution I went with was to go back to Java update 6.31, which worked fine, and inspired me to restrict Java's running in my web browser - which is positive in a way, as my browsing should be more secure, but still...

Not ideal, and I am looking in to which solution I should use with a new laptop, so thanks very much for the help, folks.

Toodles!

_________________
In the land of the blind, the one-eyed man got bullied for being a freak, but went on a voyage of self-discovery and realised that it was okay to be different, then came back in disguise and became a highly successful private investigator.

Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 12 posts ] 

All times are UTC - 8 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group