Network Zones
A 'Network Zone' can consist of an individual machine (including a single home computer connected to Internet) or a network of thousands of machines to which access can be granted or denied.
Background Note: A computer network is a connection between computers through a cable or some type of wireless connection. It enables users to share information and devices between computers and other users within the network. Obviously, there are certain networks that you'd like to grant access to, like your home or work network. Conversely, there may be other networks with which you'd like to restrict communication - or even block entirely. |
Note 1: Adding a zone to this area does not, in itself, define any permission levels or access rights to the zone. This area allows to define the zones so you can quickly assign such permissions in other areas of the firewall. Note 2: A network zone can be designated as 'Trusted' and allowed access from the 'Manage Network Connections' interface(An example would be your home computer or network). Note 3: A network zone can be designated as 'Blocked' and denied access by using the 'Blocked Zones ' interface. (An example would be a known spyware site). Note 4: An application can be assigned specific access rights to and from a network zone when defining an Application Rule. Similarly, a custom Global Rules can be assigned to a network zone to all activity from a zone. Note 5: By default, Comodo Firewall automatically detects any new networks (LAN, Wireless etc) once you connect to them. This can be disabled by deselecting the option 'Enable automatic detection of private networks' in the Firewall Settings panel. |
You can use the search option to find a network zone in the list by clicking the search icon at the far right in the column header.
- Enter the name of the item to be searched in full or part in the search field.
- Click the right or left arrow at the far right of the column header to begin the search.
-
Click the icon in the search
field to close the search option.
Defining a new Network Zone
To add a new network zone:
Step 1 - Define a name for the zone
-
Click the handle at the bottom and select 'Add' > 'New Network Zone'.
A dialog box will appear, prompting you to specify a name for the new zone.
-
Choose a name that accurately describes the network zone you are creating.
-
Select the checkbox 'Public Network' if you are defining a network zone for a network in a public place, for example, when you are connecting to a Wi-Fi network at an airport, restaurant etc., so that Comodo Firewall will optimize the configuration accordingly.
-
Click 'Apply' to confirm your zone name.
This adds the name of your new zone to the Network Zones list.
Step 2 - Select the addresses to be included in this zone
-
Select the network name, click the handle at the bottom and choose 'Add' > 'New Address' (or right click on the new network zone and select 'Add' > 'New Address' from the context sensitive menu).
The 'Address' dialog allows you to select an address from the Type drop-down box shown below (Default = Any Address). The Exclude check box will be enabled only if any other choice is selected from the drop-down box.
Select Address:
You can choose any IP Address by selecting Any Address in the Type drop-down box. This menu defaults to an IP range of 0.0.0.0- 255.255.255.255 to allow connection from all IP addresses.
You can choose a named host by selecting a Host Name which denotes your IP address.
You can choose an IPv4 Range by selecting IPv4 Address Range - for example the range in your private network and entering the IP addresses in the Start Range and End Range text boxes.
You can choose a Single IPv4 address by selecting IPv4 Single Address and entering the IP address in the IP address text box, e.g., 192.168.200.113.
You can choose IPv4 Mask by selecting IPv4 Subnet Mask. IP networks can be divided into smaller networks called sub-networks (or subnets). An IP address/ Mask is a subnet defined by IP address and mask of the network. Enter the IP address and Mask of the network.
You can choose a Single IPv6 address by selecting IPv6 Single Address and entering the IP address in the IP address text box, e.g., 3ffe:1900:4545:3:200:f8ff:fe21:67cf.
You can choose IPv6 Mask by selecting IPv6 Subnet Mask. IP networks can be divided into smaller networks called sub-networks (or subnets). An IP address/ Mask is a subnet defined by IP address and mask of the network. Enter the IP address and Mask of the network.
You can choose a MAC Address by selecting MAC Address and entering the address in the address text box.
- Exclude (i.e. NOT the choice below): The opposite of what you specify is applicable.
-
Click 'OK' to confirm your choice.
-
Click 'OK' in the 'Network Zones' interface.
The new zone now appears in the main list along with the addresses you assigned to it.
-
Quickly called as 'Zone' when creating or modifying a Firewall ruleset
-
Quickly called and designated as a blocked zone from the 'Blocked Zones' interface
To edit the name of an existing Network Zone
-
Select the name of the zone in the list (e.g. My Home), click the handle at the bottom center and choose 'Edit' from the options or double click on the network zone name.
-
Edit the name of the zone.
To add more addresses to an existing Network Zone
- Select the network name, click the handle at the bottom and choose 'Add > A new Address' from the options (or right click beside the network zone name and 'Add' > 'New Address' from the context sensitive menu)
- Add new address from the 'Address' interface.
To modify or change the existing address in a zone
- Click the arrow button beside the network zone name to expand the addresses
- Double click on the address to be edited (or select the address, click the handle at the bottom and choose 'Edit' from the options)
- Edit the address from the 'Address' interface.