e/ Yale Software Library http://www.yale.edu/software/ For assistance contact the ITS Help Desk 785-3200, 432-9000, helpdesk@yale.edu Windows XP Firewall Windows XP SP2 includes the new Windows Firewall, which replaces the Internet Connection Firewall (ICF) provided with Windows XP with Service Pack 1 (SP1) and Windows XP with no service packs installed. Windows Firewall is a stateful firewall that drops unsolicited incoming traffic that does not correspond to either traffic sent in response to a request of the computer (solicited traffic) or unsolicited traffic that has been specified as allowed (excepted traffic). Windows Firewall provides a level of protection from malicious users and programs that rely on unsolicited incoming traffic to attack computers. In Windows XP with SP1 and Windows XP with no service packs installed, ICF is disabled by default for all connections, unless changed by the Network Setup Wizard or Internet Connection Wizard. Manually enabling ICF is done per connection through a single checkbox on the Advanced tab of the properties of a connection, from which you can also configure the set of excepted traffic by specifying Transmission Control Protocol (TCP) or User Datagram Protocol (UDP) ports. Click on Start Settings Control Panel Double-Click on Windows Firewall The General tab with its default settings are shown. Last modified 21-Apr-06 (LAC) Page 1 of 8
Note: The excepted traffic is not allowed when the Don t allow exceptions option is selected on the General tab. Click on the Exceptions tab From the Exceptions tab, you can enable or disable an existing program (an application or service) or port. Last modified 21-Apr-06 (LAC) Page 2 of 8
Check the box of the program you want to allow If the program that you want to allow is not listed: Click Add Program. Last modified 21-Apr-06 (LAC) Page 3 of 8
In the Add a Program dialog box, click the program that you want to add, and then click OK. If the program that you want to allow is not listed in the Add a Program dialog box click Browse, locate the program that you want to add, and then double-click it. Last modified 21-Apr-06 (LAC) Page 4 of 8
If the program will appear under Programs, in the Add a Program dialog box. Click OK. The program will appear, selected, on the Exceptions tab, under Programs and Services. Last modified 21-Apr-06 (LAC) Page 5 of 8
If you still do not find the program, you can open a port instead. A port is like a small door in the firewall that allows communications to pass through. To specify which port to open, on the Exceptions tab, click Add Port. Adding an exception is preferable to opening a port because: It is easier to do. You do not need to know which port number to use. Adding an exception helps provide security, because the firewall is only open while the program is waiting to receive the connection. When you click AddPort, the Add a Port dialog box is displayed. Here you can configure a TCP or UDP port to open for a specific port number. Last modified 21-Apr-06 (LAC) Page 6 of 8
When you are finished click OK Then click OK again at the Exception List. The Exception has been successfully created. Windows Firewall Notifications At times applications can prompt the user to automatically add exceptions to the Windows Firewall. When an application runs and attempts to listen on TCP or UDP ports, Windows Firewall prompts with a Windows Security Alert dialog box. Keep Blocking Adds the application to the exceptions list but in a Disabled state so that the ports are not opened. Last modified 21-Apr-06 (LAC) Page 7 of 8
Unsolicited incoming traffic for the application is blocked unless the application is specifically enabled on the Exceptions tab. By adding the application to the exceptions list, Windows Firewall does not prompt the user every time the application is run. Unblock Adds the application to the exceptions list but in an Enabled state so that the ports are opened. Ask Me Later Block unsolicited incoming traffic for the application and do not add it to the exceptions list. The local administrator will be prompted again the next time the application is run. Last modified 21-Apr-06 (LAC) Page 8 of 8