Help - Search - Members - Calendar
Full Version: ~ AGNITUM OUTPOST PRO FIREWALL ~
B.I.S.S. Forums > Internet Security Forum > B.I.S.S. Security Guides
Moore
##################################################################

AGNITUM OUTPOST FIREWALL PRO V2.1

##################################################################


Outpost V2.1 has been publicly released and is available for download from agnitum.com.

http://agnitum.com/products/outpost/


OUTPOST 2.1 announcement page

New features include:

QUOTE
Log file control - set limits to the size or age of log entries retained;
Rewritten Active Content plugin giving control over Flash plugins, animated GIFs and external content;
Pop-up alerts now appear for Reported connections - and can be enabled for detected attacks;
Ad-Filter - individual web sites can now be excluded from ad blocking.
Existing third-party plugins for Outpost 2.0 - [HTTPLog] will also work with version 2.1. Configurations can be carried across from 2.0 except for the Active Content plugin - this will need to be reconfigured from scratch due to the changes made in 2.1.

The Blockpost Plugin has been updated to be compatible with Outpost 2.1 only , please check the outpost forum here !

Auto-configuration sets up 95% of your applications, system and local network settings during installation;
Wizard mode simplifies automatic rule creation;
Predefined system and application settings cover all common tasks such as browsing the web, allowing ICQ, allowing DNS or DHCP, etc;
Individual configurations for multiple users.
Stealth mode Support makes your computer invisible to attackers;
MD5 authentication offers added protection for encrypted messages;
E-mail protection guards against dangerous attachments and worms;
Firewall engine resides on the lowest possible level of the operating system, allowing Outpost filter RAW_SOCKET and direct packet sending into drivers, thus bypassing the TCP/IP stack.



The Outpost Firewall complete online guide:
http://www.outpostfirewall.com/guide/index.htm


Outpost 2.1 Pro / @OUTPOST FORUM - - what to expect
http://www.outpostfirewall.com/forum/showt...=&threadid=9474

Check out some screenshots here of the active content blocking plugins:
http://www.agnitum.com/products/outpost/be...version_21.html

Bluetack forum Firewall Guide :
http://www.bluetack.co.uk/forums/index.php?showtopic=770


####################

MY OUTPOST SCREENSHOTS:

####################
Moore
############################

OUTPOST ATTACK DETECTION PLUGIN :

############################

Internet attack blocking (nuke, nestea ,iceping , opentear ,teardrop , syn attacks , Dos , fragments etc.)
averts attacks that can cause system crashes;
Port scan detection denies access to intruders;

Outpost Firewall Guide to Attack detection :
http://www.outpostfirewall.com/guide/the_o...k_detection.htm
Moore
##################
SYSTEM SETTINGS:
##################

System and application level filtering define broad and precise restrictions;
TCP, UDP and ICMP level filtering define access for data packet transmissions;
Stealth mode Support makes your computer invisible to attackers;
Moore
###################
OUTPOST Security Features

New:Improved Web Active Content Filtering feature provides for easier,
more flexible and effective way to control Web pages active elements (ActiveX, scripts, etc.) behavior;

Privacy Features
New:Improved banner blocking allows to replace banners with transparent images;
New:Trusted Sites list allows to personalize banner treatment for specific Web sites;
Banner ad blocking (including Flash ads) and pop-up window blocking keep frustrating ads off your screen;
Cookies blocking maintains Web privacy and protects personal information;
Web history (referrers) blocking conceals surfing habits;
Active elements blocking for ActiveX, Java, Visual Basic scripts, and Java applets protects your system from malicious programs.
Moore
Outpost has 5 policies to choose from , [depending on your circumstances]
once application rules have been set up using rules wizard or entered manually ,
the normal mode for online activities should always be block most
One click to block all traffic or disable the firewall;
Moore
#######################

APPLICATION RULES SETTINGS

#######################

Extremely flexible application rules let you control applications right down to the ports and protocol to be allowed or denied.
Moore
##################

COMPONENT CONTROL

##################

Components Control (Anti-Leak) feature monitors components of each application you run;
Windows Boot-up protection defends your system before any malicious programs can be loaded;
Moore
##############

ATTACK REPORTS

##############

Outpost can be set to report all attacks / portscans and connections made to and from the system , here is an example popup warning,
[after this you can check the alerts tracker for the information that was logged by Outpost]
Moore
###########

LOG VIEWER

###########

Using the Outpost log viewer, you have access to all the logged information about your system thats been recorded so far , the ALERTS TRACKER is the first tab in the log viewer and shows all firewall attacks and outpost firewall rule activations :
Moore
the log viewer will give you full details of all allowed and blocked / denied connections , you can even add the filters you only want to see to your favourites , to quickly get to the information you use the most.
Moore
###############################
DNS Cache Log
###############################

For the log of the DNS Cache plug-in, the following information is available in the Columns dialog:

QUOTE
Name of the Column
Description
Date/Time
Time and date of the DNS recording.
Domain Name
Domain name that was added or removed from the DNS cache.
Event
Operation performed with the given DNS.
IP
IP address assigned to the domain name.
Moore
###############################
Attack Detection -Active Content log viewer
###############################

Outpost Firewall Guide to Attack detection plugin :
http://www.outpostfirewall.com/guide/the_o...k_detection.htm
Moore
######################
BLOCKPOST V2 Plugin by DMUT
######################

Blockpost V2 Import Guide:
http://www.bluetack.co.uk/forums/index.php?showtopic=1515


Outpost Firewall Guide to Blockpost plugin :
http://www.outpostfirewall.com/guide/the_o...s/blockpost.htm


QUOTE
If you have a question regarding this plug-in,
please post it in Official Agnitum Forums www.outpostfirewall.com in Plug-in Developers area.

This plug-in provided "Restricted Zone" feature,
i.e. every IP-packet and every higher protocols packet: ICMP, TCP, UDP, HTTP, etc.
from or to IP address in "Restricted Zone" list to be dropped/rejected.

This plug-in has maximum possible priority in OP packet processing algorithm,
this means: higher than "Trusted application", "Trusted Zone", etc. No one from your applications,
including operation system, could be able to send or receive any IP data
and higher from (or to) host included in "Restricted Zone".

Feedback and bug reports are strongly appreciated, please use this forum http://www.outpostfirewall.com/forum/forum...p?s=&forumid=56
Some tips:
- click on column to sort block list, and double-click to reverse sorting
- to edit entry, right click on it and data from entry to be transferred to "Add new entry" panel,
  then delete current entry from a list, do some edit and then click "Add"
- do not use "Rebuild" too often, it's takes a lot of time, and create noticeable DNS traffic;
  some ISP may think you doing DOS attack
- to select all items, do double right-click on list
Moore
you can also add ip ranges instead of domain names ,
especially handy if you are adding your ips by hand while offline ,
Moore
importing your choice of ips really saves a lot of time , smile.gif
you can use the blocklist manager if you want to download and convert your choice of ip
lists or use the online converter or even just select your own and make a custom list
Moore
###############
Muchod's HTTPLog Plug-In
###############

A plugin to log HTTP requests and answers.

Only interface/GUI module because it uses the HTTPFILT kernel plugin messages.

Can be useful to get the strings to use in Ads plug-in blocker or to understand the HTTP protocol (verbose mode).

The plug-in doesn't have Properties Dialog , it only uses a pop-up menu to toggle the Verbose mode on/off and to set the log size limit.


Outpost Firewall Guide HTTPLOG page :
http://www.outpostfirewall.com/guide/the_o...ns/http_log.htm


This is the verbose mode:
Moore
Normal HTTP mode :
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.