Outpost Users Support Forum  
Outpost User Operated Support Forum
Agnitum Outpost Pro Release (OP, OSS, AV): 7.0.3.3392 [24-AUG-2010]
www.agnitum.com

Go Back   Outpost Users Support Forum > Agnitum Outpost Security Suite / Outpost Firewall/Outpost Antivirus > Outpost Firewall General Discussions, Support, and Troubleshooting

Closed Thread
 
Thread Tools
  #1  
Old 03-02-2003, 05:29 AM
justins justins is offline
Junior Member
 
Join Date: Mar 2003
Location: Scotland
Posts: 9
Angry Download manager blocked by Outpost

I'm using a download manager (Download accelerator plus) that works by opening up 4 simultaneous connections to ftp sites to download files quicker.

I've put the download manager in my trusted applications (allow all), but Outpost still seems to block it. When I try to use the dowload manager, it connects to the FTP site OK but then it doesn't start downloading. As soon as I close Outpost it starts up fine. I'v tried other download managers that work the same way and had the same problem. Strangely when I look in the Outpost blocked applications log, it doesn't show up there.

Any body any ideas?

Thanks!
  #2  
Old 03-02-2003, 07:51 AM
guitarhero's Avatar
guitarhero guitarhero is offline
Member
 
Join Date: Feb 2003
Location: UK
Posts: 32
I am succesfully using DAP with Outpost on a Win2K system.

I'm pretty sure that I just accepted the offered 'Download Manager' preset rules, but in any case there are 3 of them:

Rule 1: Download Manager

Where the protocol is TCP
and Where the direction is Outbound
and Where the remote port is 80-83, 443, 1080, 3128, 8080, 8088, 11523
Allow it


Rule 2: Download Manager FTP Connection

Where the protocol is TCP
and Where the direction is Outbound
and Where the remote port is 21
Allow it


Rule 3: Download Manager FTP DATA Connection

Where the protocol is TCP
and Where the direction is Inbound
and Where the remote port is 20
Allow it
  #3  
Old 03-02-2003, 08:43 AM
root's Avatar
root root is offline
Retired Administrator
 
Join Date: Aug 2001
Location: USA
Posts: 4,142
You may need to add extra ports sometimes, but will not know it unless you are in rules wizard mode.
So when you want to download, use rules wizard mode, and when it tries to download, you will get a popup box asking to allow to a certain IP and a certain port. When this happens, select other, and uncheck the box at the top for port, and then click allow for the IP only. That will allow for multiple downloads at the same time without asking for a different port each time.
Hope this gets it for you.
guitarhero's rules should work for most downloads.
  #4  
Old 03-02-2003, 09:48 AM
justins justins is offline
Junior Member
 
Join Date: Mar 2003
Location: Scotland
Posts: 9
Question still problems

thanks for the ideas, but I'm still having problems...

What I've now found is that DAP works fine with OP on some ftp sites but not on others....

For example, this file:

http://spamihilator.sourceforge.net/...ator_0_9_3.exe

will download no problem with DAP if I have OP running. But then I try:

ftp://ftp.hp.com/pub/softlib/softwar...a_w010_enu.exe

and DAP only makes one connection and won't start downloading UNLESS I close OP, then its all hunky dory. The fact that one's http and ones ftp seems irrelevant as ftp sites do work sometimes and http sites sometimes don't.

I'm running XP and the rules that I have for DAP are just as guitarhero has. Also, my OP *is* in rules wizard mode, but I don't get any popup when DAP is launched. Even if I remove DAP from my allowed applications and then start a download, I just get a popup giving me the options "Allow all....", "Stop all....." or "Create rules using...." The last option only gives me a choice of "Download manager" or "Browser", and not "Other"

root, it seems that what your saying is probably the cause, but I can't see a way 'round it...

I'm running OP free if that makes any difference......

J
  #5  
Old 03-02-2003, 10:07 AM
MegaHertz's Avatar
MegaHertz MegaHertz is offline
Beta Tester
 
Join Date: Jan 2002
Location: Idaho
Posts: 3,951
Some FTP sites require Inbound Authentication in order to work (Linux FTP Servers seem to be the worst). Try enabling the Global Rule Allow Inbound Identification. If that works just copy down the global rules settings and create a duplicate rule for your download manager.
__________________
My software never has bugs. It just develops random features.

Note: Past performance is no guarantee of future results. The value and accuracy of advice will fluctuate.

Do not Email/IM/PM forum staff for support, all support requests should be posted in the appropriate forum.
  #6  
Old 03-02-2003, 10:18 AM
justins justins is offline
Junior Member
 
Join Date: Mar 2003
Location: Scotland
Posts: 9
Thanks,

I had thought of this and tried changing that setting, no difference 'though.....
  #7  
Old 03-02-2003, 01:12 PM
root's Avatar
root root is offline
Retired Administrator
 
Join Date: Aug 2001
Location: USA
Posts: 4,142
If in rules wizard mode you are not getting a popup, then you must have a rule blocking it somewhere.
Take a look at all of your rules and see if you see something that is blocking that may cause the problem.
  #8  
Old 03-02-2003, 05:07 PM
chrisclu's Avatar
chrisclu chrisclu is offline
Administrator
 
Join Date: Aug 2001
Location: California
Posts: 5,824
Re: Download manager blocked by Outpost

Quote:
Originally posted by justins
Strangely when I look in the Outpost blocked applications log, it doesn't show up there.

Any body any ideas?

Thanks!
Have you looked in Active content? Many times I have not seen somthing in blocked, but when I looked in AC I find that 1 or more catagories were blocked, like cookies and java script. I than add the IP to AC properties and allow them. ( If it's a site I care to)
I have al, but referrers, disabled by default. Used to disable referrers too, but about 60% of the sites I go to need them and I got tired of toggling it on and off.
Check your AC log. Sometimes the obvious is what gets us messed up.
Chris
__________________
OS: Windows XP Pro SP2 OP ver. Latest Beta OSS
Firefox Beta 3.5.6, Thunderbird 3.0
AVG 8.0.237 Pro, SpyBot, BoClean, SuperAntispyware

Before you criticize someone, you should walk a mile in their shoes.That way, when you criticize them, you're a mile away and you have their
shoes.
  #9  
Old 03-02-2003, 09:40 PM
justins justins is offline
Junior Member
 
Join Date: Mar 2003
Location: Scotland
Posts: 9
No, nothing blocked in active content... and my settings are to enable everything

Quote:
I just get a popup giving me the options "Allow all....", "Stop all....." or "Create rules using...." The last option only gives me a choice of "Download manager" or "Browser", and not "Other"
I do get the popup after I've removed DAP from my trusted applications, just not an "other" option under create rules.

The Error message that DAP gives me after it times out is:
Quote:
server response 425: can't build data connection
What I've also found is that I get entries like this in my attack detection log each time I try a download:

Quote:
03/03/2003 10:32:32 Connection request 192.6.234.10 TCP(5003)
In my attack detection settings I don't have any boxes checked to block intruders / deny services 'though.

uuuummmmmmmmm
  #10  
Old 03-03-2003, 02:25 AM
root's Avatar
root root is offline
Retired Administrator
 
Join Date: Aug 2001
Location: USA
Posts: 4,142
Try this. SHut down all of the plugins. Shut down Outpost and reboot. Check and make sure the plugins are all disabled still.
Try to download from one of the problem sites and if you still can't download, check the blocked log.
Also copy all of the allowed log lines that have to do with the effort to download and post here. Select the top line, hold the shift key and select the appropriate line down the page. You will get a highlighted area you can copy and paste.
Do this after disabling the plugins and trying to download.
  #11  
Old 03-03-2003, 03:34 AM
MegaHertz's Avatar
MegaHertz MegaHertz is offline
Beta Tester
 
Join Date: Jan 2002
Location: Idaho
Posts: 3,951
justins,

Have you tried connecting to the offending sites using Passive mode? If not add a rule to your DL manager like the following:

FTP Passive Connection
Where protocol is: TCP
and Where the direction is: Outbound
and Where remote port is: 1024-65535
Allow it

Let us know if it works. I had to add this rule to my ruleset for Getright to get it to the point where it would work on virtually all FTP sites.
__________________
My software never has bugs. It just develops random features.

Note: Past performance is no guarantee of future results. The value and accuracy of advice will fluctuate.

Do not Email/IM/PM forum staff for support, all support requests should be posted in the appropriate forum.

Last edited by MegaHertz; 03-03-2003 at 03:37 AM.
  #12  
Old 03-03-2003, 06:19 AM
justins justins is offline
Junior Member
 
Join Date: Mar 2003
Location: Scotland
Posts: 9
you've cracked it!

Thanks Megahertz,

Passive mode was the problem. As DAP was in trusted applications, passive mode was allowed anyway, but then I looked at my settings for DAP and found there was an option to "use FTP in PASV mode" (required behind some firewalls), so it hadn't been using passive mode anyway - I allowed it, and......IT WORKED!

Thanks!

J
  #13  
Old 03-03-2003, 06:52 AM
MegaHertz's Avatar
MegaHertz MegaHertz is offline
Beta Tester
 
Join Date: Jan 2002
Location: Idaho
Posts: 3,951
Glad I could help.
__________________
My software never has bugs. It just develops random features.

Note: Past performance is no guarantee of future results. The value and accuracy of advice will fluctuate.

Do not Email/IM/PM forum staff for support, all support requests should be posted in the appropriate forum.
  #14  
Old 10-24-2004, 03:04 PM
Makc666's Avatar
Makc666 Makc666 is offline
Beta Tester
 
Join Date: Sep 2002
Location: MSK-RU
Posts: 45
Re: Download manager blocked by Outpost

The problem was in fact that "As DAP was in trusted applications" and not because passive mode was not allowed!!!
This is a bug of Outpost 2.5 and the staff knows about it!!
__________________
"А стукачков мы не любим!"
..................
How to fix FTP/port 21 connections with v2.5-v3.0 and ICS enabled !!!Press Here!!!
..................
  #15  
Old 10-24-2004, 03:09 PM
MegaHertz's Avatar
MegaHertz MegaHertz is offline
Beta Tester
 
Join Date: Jan 2002
Location: Idaho
Posts: 3,951
Angry Re: Download manager blocked by Outpost

Quote:
Originally Posted by Makc666
The problem was in fact that "As DAP was in trusted applications" and not because passive mode was not allowed!!!
This is a bug of Outpost 2.5 and the staff knows about it!!
Please look at the date of the original posts before you post replies, this thread is almost 18 Months old and has nothing to do with Oupost v 2.5.
__________________
My software never has bugs. It just develops random features.

Note: Past performance is no guarantee of future results. The value and accuracy of advice will fluctuate.

Do not Email/IM/PM forum staff for support, all support requests should be posted in the appropriate forum.
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
transit packets blocked (outpost v2) djvalle Outpost Firewall General Discussions, Support, and Troubleshooting 7 08-10-2003 02:38 AM
Blocked from LAN until Outpost reload apc Outpost Firewall General Discussions, Support, and Troubleshooting 8 11-26-2002 05:37 AM
Does your Outpost log the remote port and direction in Blocked field ? iwrite Retired Threads 5 04-14-2002 07:38 PM
Not updating IP + W2K service issue tekno Retired Threads 6 03-21-2002 03:27 PM


All times are GMT -12. The time now is 01:38 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.