Does the Windows FIrewall provide outbound monitoring?

Link19

Senior member
Apr 22, 2003
971
0
0
Is there anyway that the Windows firewall can provide outbound monitoring? Everyone seems to say it lacks this ability inclduing Microsoft. However, I read on Microsoft;s website that it is possible to use IPSec with the Windows firewall to provide Outbound monitoring.

Read Using Windows XP SP2 Windows Firewall and IPSec at the bottom of the page:

http://www.microsoft.com/technet/prodte.../winxppro/deploy/depfwset/default.mspx


It says it's possible to block outbound connections using IPSec to provide this extra layer of protection. Is there any value to this and can it allow the Windows firewall to rpovide Outbound monitoring capabilities, or doe sit only work for IPSec supported applications? Reading that got my hopes up that the Windows firewall may have the ability to monitor and block outbound traffic, but I don't quite understand what they mean and want to make sure it actual does monitor outbound traffic?
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
You can probbaly use it to block traffic to certain outbound ports, but it won't let you do it per-process or anything.
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
The very paragraph you quoted sayd "Windows Firewall blocks unsolicited incoming traffic. However, you cannot configure Windows Firewall to block outgoing traffic". The point is, if your using IPSEC you can configure what traffic is allowed, but on a machine level (not process) and their isn't a just in time UI (like with incoming traffic) that will allow you to do this.

Did you really think it was possible and MS just wasn't telling you?

Bill
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
The last time I mentioned these alerts, I got a rather disbelieving response from the OP, so I posted one. As a tripwire that indicates that his software is trying to do stuff he wants to know about, it might be somewhat useful.