Application of anti-virus programs today is considered natural - the attitude{relation} and to systems of protection of the PC in a network to which programs of a class of personal gateway screens (PMEH, a firewall, Personal Firewall) concern should become same. The personal gateway screen is the universal software providing reliable protection of a computer from non-authorized access to various information resources available on him under report TCP/IP at job of a computer in local or wide-area networks, for example in the Internet.
Basis of this program is the driver cooperating directly with the driver of network layer. The driver supervises all IP-traffic which is acting and starting with a computer. The personal gateway screen in most cases after installation does not demand additional adjustments and provides protection of a computer at a stage of his loading. At installation of the personal gateway screen to computers it is not showed any additional requirements is there can be a stationary or portable computer with operational system Windows 95/98/Me/NT/2000/XP and the modem or a network map.
Firewalls supervise all network activity of the PC, tracing a status of ports and attempts of connection to them from the Wide-area network (aspiration of nocuous programs to penetrate on local Windows-environment), and also fixing all programs on PC which without the sanction try to leave for the Internet. Usually PMEH are distributed on a commercial basis and cost{stand}, as a rule, from 10 up to 70 dollars. But there are also pleasant exceptions: some companies from marketing reasons allow to use the firewalls free-of-charge - in the private{individual} order, on the domestic PC, for non-commercial objectives.
Let's briefly stop on how all the same work PMEH. All communication{connection} in the Internet is realized by means of an exchange of first-aid kits of the data. Each package is passed the machine of the addressee from the initial machine. A package - fundamental unit of an information stream in the Internet. In essence, the PC "agree", that they are connected, and each accepting machine sends back packages of acknowledgement{confirmation} that the machine sending them "has learned{has found out}", that the data have been received. To reach{achieve} the addressee, the package should contain the address of the addressee and number{room} of port determining, what the program should process this package. That the computer of reception knew the sender of a package, each package also should contain the IP-address and number{room} of port of the accepting machine. In other words, any package travelling to the Networks, necessarily contains addresses of the sender and the addressee. And this information first of all requires protection.
The software of gateway protection "examines" each PC (all his ports) and each package of the data before that will reach{achieve} the necessary computer and other applications to which these packages are addressed will be started. Before end of a session of communication{connection} all subsequent entering packages are checked only on conformity of port and the address of the addressee, and also the address of the sender. By virtue of it ways of hacker's attacks existing today often are based on substitution of the address of a proceeding package on the address already participating in a session of communication{connection}. As at installation of a session of communication{connection} connection between two PCs is bidirectional and as owing to the restrictions imposed by reports of communication{connection}, the length of transmitted packages is final for guaranteed qualitative connection packages in counter streams are marked by special image. Their structure includes ASK-BATS (acknowledgement), confirming correct reception of the previous package. On absence of these bitov the firewall defines{determines}, that the new session of communication{connection} is established. Thus, the packages being a part of established connection, pass through a firewall, and the packages intended for attempt of connection and having the same addresses of the addressee, - are blocked.
Over the modern market dominates three categories of firewalls: filters of packages, contextual filters and gateways of a level of the applications, usually named proxy-servers.
There are filters of packages of the following levels: applied, transport, network and channel, and the given classification is not unique. First three filters can be entered into error by the malefactors who have forged headings IP-, TCP-and UDP-packages. A channel level, that is a level of interface to the physical environment, it is meaningful to supervise only in a local area network. At modem connection with the provider this operation gives nothing, as in this case all packages at a channel level come only from the provider and any information on the physical address of the site - sender in them does not contain.
Contextual filters work more reliably, but areas of their application are limited. Besides they are not capable to reflection of the new attacks developed after their occurrence. Usually such filters are used for search of keywords, which strict parents forbid to read to children.
Gateways are convenient in corporate networks, but are absolutely not necessary for private{individual} users. To tell the truth, if someone has two computers, that, having allocated one under the proxy-server, it is possible to try to secure another.
There is a set of utilities which allow to send packages from an another's name and thus to mislead personal firewalls. However, malefactors sometimes operate also quite legal from the point of view of a firewall with means. We admit{allow}, the victim has decided to visit Web-page. Certainly, the firewall should pass{miss} all packages going from this site. Now we shall assume, that the server on which the site is located, gives free-of-charge (or paid) a hosting to all interested persons. In this case attacking, having placed on this server the program, can free "bomb" a victim packages, filter which a firewall cannot.
It is not necessary to forget and about vulnerability of the stack of reports TCP/IP (Transmission Control Protocol/Internet Protocol) which by the nature does not meet modern safety requirements in what, naturally, it is impossible to blame his developers.
So, the personal firewall is a category of the software intended for blocking of a certain kind of the network traffic with the purpose of reduction of opportunities of penetration from an external part of a network in internal, protected firewall. As an internal part of a network separately taken computer can act - in this case it is the programs working, as a rule, under management Windows 95/98/NT/2000/XP which problem is protection of the unique computer connected to the Internet. The specified problem is realized by means of kill of the entering and proceeding network traffic, the control of the current connections, revealing of suspicious actions. Rather often such programs in passing provide blocking advertising, acceleration of job with the Network, blocking of active contents of Web-pages. Program firewalls also are applied and as the software established{installed} on routers, proxy-servers, etc. In the big corporate networks, but usually it is very expensive{dear} products inaccessible to the simple user.
One of the most powerful on functionalities among personal firewalls the products described below which serve as a barrier between the PC and the Internet possess, providing protection against breaking, against ill-intentioned post investments of different types and against attempts of some programs is latent to send the personal information to the Network.
Agnitum Outpost Firewall 1.0.1817
After installation of the given package the program works in a mode of training, and any rules for it{her} are not stipulated, but concerning each entering and proceeding connection the program will give out a window of dialogue with the offer to create a rule for him or to make individual action: to pass{miss} or block. Rules which are created in this mode, are immediately applied to kill of the entering and proceeding traffic. Also in the program some operating modes are stipulated:
? A mode of blocking - the system blocks all connections for which the obvious image have not been determine rules, that is the system works by a principle « that is not authorized, it is forbidden »;
? A mode of full blocking - in this mode all connections irrespective of are cut, they are resolved{allowed} or forbidden. The similar mode is very useful, when receive from somebody threat of immediate attack;
? A mode of disconnect - the program hangs in system tree and does{makes} nothing;
? An allowing{A resolving} mode - all connections and all traffic which have not been forbidden by obvious image in rules are resolved{allowed}.
Modes can change easily and quickly the user, and in case of need the system immediately starts to operate according to new rules of job of protection.
Besides in this program additional functions are realized also. The firewall supports the demilitarized zone (that is there is an opportunity to create a IP-sheet on all traffic), and only from these IP the firewall will pass{miss} entering packages. Against scanning ports the mode of the invisible being (Stealth) when the system does not respond on pingi is stipulated and does not give out any ICMP-messages at searches; in a window of adjustments there are variants of behaviour at such searches which can vary. For convenience and speed a plenty of standard rules is built - in system, but it is possible to create and own rules. Additional modules are supported also, some of which are delivered with the program and are standard. Module " Advertising " allows "to cut" banners and everything, that to them is similar. Similar it is sharp occurs on the size of a banner or under the link, and in the program the most widespread sizes and links are initially stipulated, but it is possible to add and the. The filter of active contents srezaet the forbidden active elements on pages, is useful for "ubivanija" pop-up windows, etc. The control over contents of pages Is carried out also: if you do not want to see any bad word on pages, bring in it here and you more never with it will meet. Here blocking of access on sites brought in the list is stipulated, but she is addressed to parents who are concerned with moral shape of children more likely. Caching DNS helps to move faster on the Internet. The detector of attacks defines{determines} scanning, blocks attack and analyzes suspicious actions, and also allows to establish the IP-address attacking. From other advantages it is necessary to mention presence of the Russian-speaking interface that facilitates adjustment.
The firewall possesses the following basic properties:
? An opportunity of use of the program at once after installation without preliminary adjustment;
? An opportunity easily and quickly to create a safe configuration at job in the Network, using inviting messages of system and adjustment by default;
? The simple user interface, allowing to form even the most complex adjustments by one or several pressing of buttons;
? A plenty of adjustments for restriction of access from the Network and access to the network of working applications and adjustments of job of service reports (for experienced users or in case of special requirements to safety);
? Use of an invisible operating mode at which in the Network your computer is not capable to find out other computers;
? Use of an invisible operating mode at which in the Network your computer is not capable to find out other computers;
? Compatibility with all versions of system Windows 95/98/2000/Me/NT/XP and low system requirements.
It is not necessary for user to be able to apply all opportunities of system as she is capable to work effectively and with the adjustments established by default to successful application of firewall Outpost Firewall. Many additional opportunities, for example such as restriction of receipt or sending of ICMP-messages of the certain types, are intended only for few (skilled) users of system.
The new approach by development of the personal firewalls, realized at system engineering Outpost Firewall, is the modular principle of the organization. It means, that the significant part of opportunities on protection of a computer is realized as the connected modules representing files with expansion *.dll. Such modules are not connected in any way with each other. Having created new modules, it is possible to add without problems them in already established system.
Speaking more particularly, at use of system Outpost Firewall probably:
? To limit the list of the applications receiving access in the Network; thus for each of these applications it is possible to specify the list of allowable reports, ports, directions of the reference{manipulation};
? To forbid or limit receipt on a local computer of the undemanded information, in particular:
- Banner advertising,
- Pop-up windows in Web-pages,
- The data from the certain Web-pages;
? To limit or forbid use of the program components which have been built - in Web-pages, such as Java-applets and programs in language JavaScript, ActiveX, etc.;
? To limit or forbid use cookie;
? To define{determine} a zone of friendly IP-addresses (for example, addresses of a local area network in which the given computer is established). In this zone Outpost Firewall fails the control and does not limit a network exchange;
? To carry out check of the attached files acting on email;
? To receive from the program of the prevention{warning} at attempt to attack your computer from the Network and to prevent such attempts.
Today given PMEH is one of the most popular in our country and the countries CIS, that, most likely, it is connected to his very big functionality and his free distribution. Besides there is also version Pro (paid) with a little more expanded opportunities.
ZoneAlarm 3.1.395
This product from Zone Labs is intended for demonstration of opportunities of technology TrueVector which, basically, can be built in any products including foreign developers.
New version ZoneAlarm in comparison with previous has not received serious development some, nevertheless in "depth" of its{her} interface there will be many interesting opportunities. The firewall still works at a level of applications, however now it is possible to resolve or forbid selectively access to concrete ports or their groups (for example, typical for job with Web, FTP, etc.). However, such adjustment needs to be spent in addition, and are by default resolved (naturally, with the consent of the user) all kinds of access.
PMEH differs nice design and simple, but the thought over interface. ZoneAlarm allows to block activity of any programs addressing to Windows from the Internet or trying independently to leave for the Network from the PC, it is simple enough in management, supposes adjustment of job of applications in a local area network or the Internet (at a level "to allow, "forbid, "ask") and their functioning as servers.
It is loaded ZoneAlarm as the usual Windows-application and though theoretically it does not provide the level of safety similar Tiny Personal Firewall (is (see lower), but such level and is not required to the overwhelming majority of users. At more - less suspicious activity the program gives out on the screen beautiful okoshko - or with the information on attempt of connection to a computer, informing the IP-address of the removed machine and offering{suggesting} on the Web-page to define{determine} the provider (the owner of this IP-address), or with a question: to resolve or forbid to the certain application job in the Network. At a permanent job with a personal computer the similar approach with a pop-up window is more convenient and is evident, rather than recording of all traffic with which the ordinary user to understand not begins.
ZoneAlarm distinguishes carried out programs and limits their opportunities, in particular supervises transfer of the data from a computer in the Internet.
There are two zones ZoneAlarm - local and the Internet - zone. In a local zone there is a computer of the user and other computers incorporated into a network; all other machines concern to a zone of the Internet. Each zone can appoint low (Low), average (Medium) and high (High) levels of protection. By default to a local zone the average level of protection that allows to communicate freely enough is appointed, including in common to work with files in Windows environment. In a zone of the Internet the high level of protection operates: sharing files is forbidden, all ports are latent from an external world and all privileges appointed to applied programs operate. Only the appointed privileges on a low level operate.
For full blocking connections it is enough to click on an icon as a padlock in the top part of interface ZoneAlarm. Then, having chosen window Pass Lock in section Programs, it is possible to resolve data exchange for the certain programs. At detection of attempt of any applied program to establish connection with an external world in this mode, ZoneAlarm directs search to the user, blocking thus any connections, behind exception specially resolved{allowed}.
ZoneAlarm it is positioned as means of protection for small office networks. The program is able to work correctly with component Internet Connection Sharing which is included in Windows 98SE/Me/2000/XP, than competitors cannot while to brag. For this purpose the program needs to be established and accordingly to adjust on a network gateway though developers recommend to do it and on each workstation. Besides preventions can be received both on a gateway, and on client PCs, and adjustments of the program can be protected the password.
Norton Internet Security 2003
Norton Internet Security 2003 provides protection against threats of the mixed type like Nimda and Code Red which use various methods of an attack and are capable to cause in short terms significant damage.
The basic functionalities added in Norton Internet Security 2003, include module Norton Intrusion Detection, the advanced means of the control over preservation of confidentiality of the information, function Norton Spam Alert and more convenient interface in use. Norton Intrusion Detection provides to users an additional level of protection due to automatic blocking of the dangerous attacks quickly extending with the Internet - traffic. Norton Privacy Control contains new means of protection of the private{individual} information, such, for example, as search of the confidential data in proceeding electronic letters and in the enclosed files, and also in instant messages.
To number of the improvements brought in the program for convenience of users, the interface, independent protection, system of the notification about ocurrence in a network concern more simple in job, an opportunity to block information interchange by one pressing of a key and evidently to display a status of system of safety on the monitor.
While the separate elements of a firewall included in package Norton Internet Security 2003, protect entering and proceeding streams of the information and protect a computer from hackers, doing{making} his invisible. Additional module Norton Intrusion Detection adds one more level of safety - thanking his abilities automatically to fix and stop such dangerous program codes, as Nimda and Code Red. When the system registers attempt of intrusion, she automatically blocks attack and stops any further message with a computer of a hacker.
Norton Internet Security 2003 has still a lot of new functions for preservation of private{individual} data of the user in inviolability: Norton Privacy Control now allows to prevent outflow of the confidential data through the standard email using report POP3, and also through instant messages of users of systems AOL Messenger and Windows/MSN Messenger.
Norton Internet Security 2003 allows to filter a spam, protecting a mail box from filling with irritating letters from collective dispatches and any useless information. Norton Spam Alert reveals similar messages and the Subject marks them as a spam in a field «: » The processed letter, then the user can solve itself whether delete this letter, but also, can appoint the certain rule according to which the system will automatically move similar messages to the specified folder. As against other decisions offered{suggested} for kill of a spam and demanding use of special separate means of viewing of letters, Norton Spam Alert allows to use still the habitual post client working under report POP3, for example program Microsoft Outlook. Due to changes brought in this function, the user has an opportunity even more effectively to block banners on the visited{attended} pages, pop-up both automatically opening windows and other messages of advertising character distracting attention. Thus, the user having access in the Internet through removed modem connection, essentially increases bandwidth soedinenja.
A number{line} of the improvements realized in Norton Internet Security 2003, transform it into the most convenient decision for protection against modern threats at job in the Internet, namely:
? Anew developed interface simplifying use of a product and at the same time increasing his productivity;
? Module Alert Assistant giving to the user the information detailed and accessible to understanding which helps him to react to arising threats of safety adequately;
? Function Internet Disconnect raising safety at the expense of granting to the user of an opportunity immediately to break off connection by one pressing of the button at first attributes of hostile activity in the Network;
? The means of control Security Monitor having idle time in circulation the interface and allowing to the user constantly to watch{keep up} a status of system of safety and dataflows;
? The function of automatic updating LiveUpdate checking each time at ocurrence of the user in the Internet presence of the latest descriptions of viruses, adjustments of firewalls, signatures for means of the control over integrity of networks and structures of Internet - applications, and then if necessary independently loading and establishing{installing} them in system;
? Option Visual Tracking, allowing to establish geographic location of a computer from which attack is conducted;
? Function Network Notification, submitting to the user a signal during that moment when the computer appears the connected to wireless or usual local area network;
? Mechanism Password Protection responsible for safety of made adjustments and not allowing dangerous program codes to deactivate functions Norton Internet Security;
? Kill of news from the conferences, being an additional component of means of system Parental Control in structure Norton Internet Security 2003 which allows parents to forbid to children access to the information not intended for them.
The full version of program Norton AntiVirus 2003 included in package Norton Internet Security 2003, provides to users all-round anti-virus protection. This program automatically deletes viruses, protects electronic letters and the files sent with instant messages, and also constantly supports anti-virus bases in the updated status, not demanding intervention on the part of the user.
Besides ability automatically to delete viruses, Norton AntiVirus 2003 is able besides to delete trojany and worms, blocking the last in outcoming mail still before for them corresponding descriptions will appear. Plus to this Norton AntiVirus 2003 can register and warn distribution of the viruses created on the basis of scripts, not demanding thus of presence of the last obnovlenij anti-virus bases. And at last, Norton AntiVirus 2003 automatically checks and clears the files enclosed in instant messages sent through such popular programs, as Yahoo! Instant Messenger, AOL Instant Messenger and Windows/MSN Messenger.
To put it briefly, the majority of users of package Norton as a whole will be reliably protected. This full-function product is constructed on a basis of very effective firewall for time AtGuard, but, unfortunately, the developer does not support it more and does not advance.
eSafe Desktop 3.1
eSafe Desktop - one of few functionally exhaustive complexes having a high-grade firewall, the anti-virus program, functions of kill of the acting information and an opportunity to reflect the attack of other types in particular made with application of scripts JavaScript and elements of management ActiveX. The complex eSafe Desktop checks all entering files, Java-and ActiveX-applets, scripts and the attached files of email on presence of nocuous activity, and also protects the confidential data from casual or deliberate copying and from sending through the Internet. In the program eSafe Desktop filters of the information for elimination of undesirable words and expressions are stipulated. Besides eSafe Desktop blocks Trojan programs and the ports usually used by hackers. The given tool is delivered already adjusted on reflection of numerous typical attempts of intrusion, such, for example, as Trojan NetBus.
The user can block in addition concrete ports for data exchange with concrete addresses. Such opportunity of adjustment of a configuration on the basis of rules provides significant flexibility, however also serious lack from here follows: any of these rules is not entered into a configuration by default. Besides in an initial configuration eSafe Desktop it is not stipulated at all an interdiction on use NetBIOS for teamwork with files through the Internet.
Interesting unique feature eSafe Desktop - function Sandbox (sandpit) with which help it is possible to define{determine} where and as the applied program can carry out manipulations with file system. For example, the user can forbid to write down to the new program the data in any file outside of its{her} own catalogue. In a mode of training Sandbox establishes rules of behaviour, tracing actions of the applied program.
With the help of screen Administrator it is possible to impose the certain restrictions on operations which are authorized to be carried out to different users of a computer. In particular, it is possible to forbid access to functions eSafe Desktop, to stores in section « my computer » and even to commands "To execute" and « End of job » in the menu "Start-up".
The thought over approach to purpose of access rights allows the manager to set various levels of restrictions for individual users of Windows environment, depending on their needs{requirements} for access to documents and programs and from a degree of trust to them. In the configuration of a firewall of the privilege accepted by default, as well as rules, do not operate before to use, therefore, them, it is necessary to appoint them. With the help eSafe Desktop the manager can limit access on Web-sites or to news groups, being based on keywords or categories to provide reliable kill of the infected packages, to prevent use of the certain words in many Internet - applications, to protect from casual loss the personal information and to limit use of the Internet.
Having used adjustments eSafe Desktop, the manager can block also access to this or that group of the Web-sites forbidden for viewing, being guided thus keywords or IP-addresses. In case of need the manager can create lists of the sites resolved{allowed} to viewing within the limits of which users can work in the Internet. Thus eSafe Desktop supervises any changes in file system of a computer.
As the anti-virus program eSafe Desktop does not represent anything oustanding but if you are involved with other opportunities of a package remember, that use of one more anti-virus program alongside with eSafe Desktop will not call difficulties. Indoubtedly, eSafe Desktop - the interesting program functionally advanced and not deprived certain{determined} advantages, but, except for function Sandbox and an opportunity to appoint the privilege, she is allocated with nothing among competing products. As by default the best and most attractive functions are not involved in the program, she hardly will interest beginning{starting} users. However eSafe Desktop it is distributed free-of-charge, and you risk nothing, if will try to work with her. Also it is necessary to note presence of Russian interface that will help to understand functions of the given firewall better.
Let's result some the basic features eSafe Desktop:
? Protection from hostile Java-, ActiveX-and other nocuous modules;
? Management of access to files, ports and resources of the Internet;
? Presence of the anti-virus mechanism completely certificated by the International organization on protection of the information (ICSA);
? Blocking undesirable contents on the basis of keywords;
? Restriction of time of access in the Internet;
? Restriction of access to undesirable Web/FTP-sites;
? Restriction of access to local or to network drives;
? Prevention of unauthorized changes of a configuration;
? Prevention of unauthorized installations of the software, and also his use;
? Automatic removal{distance} cookies and kehshiruemoj information;
? Job with all Internet - applications and all types of connections.
At the moment a plenty of scanners is accessible to the Russian users. Many scanners, switching eSafe Desktop, are certificated by the International organization on protection of the information for protection against the viruses which have been found out in the Internet. However, having relied on the good scanner, the user cannot protect system from unknown viruses which are the most dangerous. The scanner which has been built - in in the client eSafe Desktop, and also monitoring of unknown viruses are a basis for the finished anti-virus protection.
Tiny Personal Firewall 4.5
The original decision in technological plan Tiny Personal Firewall becomes more active even before loading Windows, being placed between the adapter of the network interface and OS that guarantees protection of a computer on a low level and at the earliest stages of job - any network service basically cannot become more active prior to the beginning of functioning this firewall.
For installation it is not required special knowledge. After installation the firewall is started automatically, and further at the first reference{manipulation} of any application from a local computer to the Internet the question will be set to the user, whether it is necessary to resolve or forbid access to the Network. And to post clients, obviously, it is meaningful to give browsers the constant sanction to not answer the same questions at each connection to the Internet; other programs can be adjusted is more thin. Tiny Personal Firewall possesses floppy means of such adjustment, allowing to specify for each Internet - application the set corrected his jobs in the Internet: The network report (TCP, UDP, ICMP), a direction of data transfer (in the PC from the Network, from the PC in the Network), an allowable range of used ports and IP-addresses of the removed application (for example if the FTP-client always addresses to the certain FTP-server it is better to adjust it to the concrete IP-address of this server), and also ways of recording by each rule. That under a kind of the standard application in a computer the nocuous program has not crept in, controllable Tiny Personal Firewall the application is supplied with the signature on a structure of the message 5 (MD5).
Functioning of a firewall copes rules which can become attached to concrete applications, to IP-addresses, numbers{rooms} of ports and even to time intervals. The interface of the program is extremely simple and so clear, that in the complete set even there is no Help. It is separately possible to load the user's guide in format PDF which instead of the detailed description of purpose of each button is devoted to recommendations on adjustment of safety in various situations. Tiny Personal Firewall provides three levels of protection: minimal (all types of connections while them have not forbidden corresponding rules are resolved{allowed}), maximal (full contrast minimal) and average (same as maximal, but with the predetermined set of the rules allowing{resolving} typical services: DNS, Ping and some other). However, as it was already spoken, creation of such rules does not cause the slightest difficulties. In Tiny Personal Firewall the opportunity remote konfigurirovanija and viewing of magazine is stipulated even.
Sygate Personal Firewall 5.0
Sygate Personal Firewall supports three operating modes: Block All (to forbid all connections), Normal (normal) and Allow All (to resolve all connections). By default after installation of the program the normal operating mode that allows to penetrate into adjustments of the program not especially is switched on. All applications are defined{determined} hurriedly and established in mode Ask (to ask). For applications it is stipulated too three modes; besides mode Ask, exists two more: Allow (to allow) and Block (to block). Applications also can be adjusted manually, and the mode for more thin adjustment of the given application - Advanced Application Configuration is stipulated. Rather convenient magazine which is broken into separate groups is conducted: Security Log (security magazine), System Log (system magazine), Traffic Log (magazine of the entering / proceeding traffic) and Packet Log (magazine of batch transfer). For each of magazines there are the additional filters, allowing to reduce or increase the deduced{removed} information in the given magazines. The following filters are stipulated: 1 Days Logs (to deduce{remove} the information for one day), 3 Days Logs (for three days), 1 Week Logs (for a week), 1 Month Logs (for a month) and, at last, Show All Logs (to deduce{remove} all existing information). A firewall as well as Outpost Firewall, by default does not give out any IMCP-messages that allows to remain imperceptible for the hooligan sending pingi in the Network.
Sygate Personal Firewall also blocks job of Trojan programs if nevertheless they at you appeared. There is rather well configured adjustment of rules, there is an option of adjustment of global variables, including definition of the trusted addresses, and convenient dynamic system of the help. Plus to this - adjustment of global variables and adjusted rules of the protection, new system of the help, the control of entering and proceeding ICMP-packages over their type, and also the console of messages.
|