![]() |
Outpost User Operated Support Forum
Agnitum Outpost Pro Release (OP, OSS, AV): 7.0.2.3377 [23-JUL-2010]
www.agnitum.com |
|
#1
|
||||
|
||||
|
SVCHOST.EXE.936 in/out summary only
Here is a log entry from W7 64 bit with OP FW Pro 2009 6.7.3.3058.
Before asking our vendor I would appreciate it if any body else sees a similar entry. ie in/out bytes at summary level but none at detail level. Comments as always welcome!
__________________
Best Regards! ![]() .... there is always time to do it over, but never enough to do it right the first time.... |
|
#2
|
||||
|
||||
|
Re: SVCHOST.EXE.936 in/out summary only
Yep. I have more entries with 0 traffic in detail.
__________________
If it ain't broke... fix it until it is. |
|
#3
|
||||
|
||||
|
Re: SVCHOST.EXE.936 in/out summary only
The used ports section means that an application has opened a port and is listening for traffic. There's no connection since the bytes are at zero.
The PID of 936 is not relevant since it's an assigned ID number and as you see other sessions of svchost have different PIDs. Svchost hosts quite a few processes so looking at the port number is the way to try and determine what process has that port [49153] open. Process Explorer may be of help trying to determine what port that is but Win 7 is a little more difficult to figure these things out. Port 49153 belong to the private/ephemeral ports that get randomaly assigned. Try turning off software that you may have running and see if that port gets closed. It's not a real problem as OP will warn you if a new connection is attempted if your svchost rules are properly made. |
|
#4
|
||||
|
||||
|
Re: SVCHOST.EXE.936 in/out summary only
Quote:
Hi Manny: My question is poorly phrased I guess. I'm unconcerned about pid numbers. I simply wanted to know how I have data in and out at summary level but looking at the detail level all I see is zeros. Normal summary/ detail reports balance. IE the sum of the detail lines equals the summary. SVCHOST rules do concern me and have alway confused me. I set rules up on a completely different new application using learning mode for 5 minutes only to find all sorts of new SVCHOST rules showing up via the presets. I must be doing something wrong or suffering rule burn out. But it is very frustrating to keep having to go back and see what damage learning mode did to rules I thought I was done with. Never mind...
__________________
Best Regards! ![]() .... there is always time to do it over, but never enough to do it right the first time.... |
|
#5
|
||||
|
||||
|
Re: SVCHOST.EXE.936 in/out summary only
Quote:
Quote:
Last edited by Manny Carvalho; 02-09-2010 at 09:53 AM. |
|
#6
|
||||
|
||||
|
Re: SVCHOST.EXE.936 in/out summary only
Quote:
Hi Manny: on the in/out summary I will ask the vendor and report back on the rules I will follow the guide you gave in the post, from this point forward I'll just drive the car with manual transmission. Maybe some day some nice person will provide a tight rule starter set for OP. Users could download it as a saved configuration file.
__________________
Best Regards! ![]() .... there is always time to do it over, but never enough to do it right the first time.... |
|
#7
|
||||
|
||||
|
Re: SVCHOST.EXE.936 in/out summary only
Quote:
I did hear back from the vendor. All they said was take and send the usual zip log files so they can see what is going on in my PC. Assumption is that I have done something wrong. I have not done that, since all they have to do is look at their own versions. I'm done with this one. They will either fix it or they won't.
__________________
Best Regards! ![]() .... there is always time to do it over, but never enough to do it right the first time.... Last edited by Escalader; 02-17-2010 at 12:58 AM. Reason: spelling |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Blocking in/out with 1 rule, same as 2 rules? | DebP | Outpost Firewall General Discussions, Support, and Troubleshooting | 3 | 12-13-2007 10:57 AM |