I am experimenting on blocking all outbound traffic by default using Windows Firewall. I then wish to explicitly allow ICMPv4 outbound by the PING.EXE program. Hence, I explicitly create custom rules that say if the file is %systemroot%system32PING.EXE and the protocol is ICMPv4, it is allowed.
However, when I run PING.EXE 8.8.8.8, it says "General Failure" and my firewall log shows that the traffic is dropped. I then use dir ping.exe /s to find all the instances of PING.EXE (there are 4 of them, one in System32, one in SysWOW64, two under WinSxS) and explicitly allow all 4 of them. I am still met with "General Failure".
I used ProcMon to see if C:WindowsSystem32PING.EXE is being called. It looks like it is.
However, if I says ICMPv4 is allowed for "ALl programs that meet the specified conditions", then PING.EXE 8.8.8.8 will succeed.
Can anyone help to explain why is this the case?
Recent Questions...
ما را در سایت Recent Questions دنبال میکنید
برچسب:
نویسنده: استخدام کار
بازدید: 186
تاريخ: يکشنبه
16 خرداد
1395 ساعت: 9:07