henrypp / simplewall

Simple tool to configure Windows Filtering Platform (WFP) which can configure network activity on your computer.
GNU General Public License v3.0
6.29k stars 487 forks source link

Neither pop-ups, nor logged entries for most app blocks #154

Closed ltguillaume closed 5 years ago

ltguillaume commented 6 years ago

In v2.2.2, most of the time I still get no pop-ups for new apps that are blocked, or it takes over a minute before I actually get the pop-up. There's no log enty for the apps either. Anything I can do to improve this?

ltguillaume commented 6 years ago

I just got a pop-up of a an app that was blocked 4 hours ago.

ltguillaume commented 6 years ago

This might have something to do with my running Windscribe (which also uses the Windows Filtering Platform): sometimes I get to see the simplewall popups as soon as I disconnect Windscribe.

Is there anything that can be done so that simplewall works nicely with other services using the WFP API? I reckon there are many, including the OpenVPN client (in addition to Windscribe).

ltguillaume commented 6 years ago

https://github.com/henrypp/simplewall/issues/120#issuecomment-385089739

tokariu commented 6 years ago

I do not have any VPNs running and no Windscribe and get the same issues. Pop-Ups are showing up very delayed (sometimes never) when an app tries to connect to the internet.

I remember this issue occured since v2.2.3 and I think it was not a problem in v2.2.2. something must have been changed that causes this trouble.

ltguillaume commented 6 years ago

I had the same issues in 2.2.x

ltguillaume commented 6 years ago

The Windscribe techs seem to be convinced that the issue lies with simplewall:

All the Windscribe firewall does is block connectivity to all IPs except for the IP of the VPN server you're connected to. This assures that there are no leaks outside of the tunnel.

LAN Firewall bypass also whitelists RFC1918 IPs, to allow connectivity to other LAN devices.

We also pre-resolve the API IPs, and whitelist these as well, so the app can make API calls while disconnected and the firewall is still ON.

What you describe seems to be a bug with Simplewall (...)

Source: https://www.reddit.com/r/Windscribe/comments/8f5u4x/simplewall_uses_wfp_possible_issues_with/

tokariu commented 6 years ago

In v2.2.2, most of the time I still get no pop-ups for new apps that are blocked, or it takes over a minute before I actually get the pop-up. There's no log enty for the apps either. Anything I can do to improve this?

I'm still having this problem everyday even in v2.2.6RC. I open a new program and it gets blocked (due to whitelisted apps allowed only). But there is no pop-up opening to ask for permission. Sometimes I have to restart the app twice or even 3 times in a row and sometimes i have to wait 5 minutes, then suddenly the popup shows up and I can allow the app to go online. There was a time, i think it was before 2.2.x where the popups showed up instantly right after the first start of the app. I hope this will work again soon as it's pretty annoying in the everyday life.

henrypp commented 6 years ago

@tokariu, are you on windows 32-bit? check 2.2.7!

tokariu commented 6 years ago

@henrypp no I'm all testing on W7x64 and simplewall 2.2.7 Just had the same problem again. Had downloaded a new app, Hexchat for testing, and after installing/starting no popup showed up, even after the 2nd start. Then suddenly after 3 minutes, simplewall showed the popup.

tokariu commented 6 years ago

v2.2.8RC running and I don't get any notifications for newly installed apps. I tried with steam and gog-client.

for steam: I had to close and wait again for minutes to show the popup notification. even after allowing steam.exe, there was never showing up a notification for steamwebhelper.exe which is required to browse the steamgames. Solution was to manually browse to and add all steam executables, then whitelist them. This is like not having a notfication system at all, because it is not working.

gog-client: mostly the same issues as with steam, however here no notification showed up at any time. I completely had to whitelist all .exes manually.

I have no idea why there is no notification popup coming up immediately after the program start, but the current situation really sucks. could it be due to the amount of already whitelisted/blacklisted apps simplewall? the more apps listed, the longer the notfication reaction?

henrypp commented 6 years ago

@ltGuillaume, @tokariu

what latest simplewall version working well? what OS do you use? any AV/SandBox app used by you both?

tokariu commented 6 years ago

hm it's been quite some time where the notifications worked well for me. I can't say it with certainness. If i would guess, I'd say it was the early beta versions ~v2.2.1 - .3 but it could even be earlier in the old non-beta versions. the system where I run simplewall (v2.2.8RC, x64) is a Win7x64 OS with latest updates applied. Avira Antivir used as AV and sandboxie is installed. But I'm not running it on any sandbox/VM. Actually I don't see any installed app that might interfer with simplewall.

ltguillaume commented 6 years ago

When I first updated to 2.2.8, I got notifications that my browser was blocked (it was indeed), even though it was checked (using whitelist mode). I needed to restart simplewall, and - to be sure - I disconnected my LAN adapter and disabled & re-enabled the filters.

I'm using an NTLite'd Windows 10 1709 x64. No antivirus. Windows Defender stripped out (not the firewall, obviously). Sometimes I use Sandboxie, but it's not doing anything most of the time. As you are well aware (haha), I'm using Windscribe that adds another WFP sublayer.

To be honest, I cannot recollect any version that didn't have hickups when it comes to popups. @tokariu mentions v2.2.x, but I had these issues back then as well.

tokariu commented 6 years ago

today I set a new record for popup delay.

currently using v2.2.8RC. Yesterday I started a new game, it connects to the internet but it doesn't require internet to run, so i could play offline aswell. i played a few minutes then closed the game. my computer wasn't shut down last night, so it still runs today. today I got the pop-up message that the game .exe wants to connect to the internet... thats about 24 hours later. Also to mention, while the popup is showing up, the mentioned game .exe is NOT running it was closed a day ago (i verified that with task manager). if it wasnt that bad it'd already be funny again ;)

ltguillaume commented 6 years ago

Yeah same here. Sometimes I get them 4hrs later, sometimes even more. Any other way we can help to resolve this?

henrypp commented 6 years ago

Try release version 2.2.12

ltguillaume commented 6 years ago

Still not working, sorry :-(

kiwijam commented 6 years ago

Notifications are working again for me, thank you.

In more detail: at some point simplewall notifications started becoming delayed. However, clicking the systray icon would make all queued notifications appear at once. Notifications stopped working altogether for me a couple versions later. Clicking the systray icon didn't help either. I then wiped my rule set hoping it would bring back notifications - to no avail. I then uninstalled simplewall and rolled back a couple versions. This didn't help either. I then rolled back even further to 2.2.5 and notifications were working again. Notifications started working again for me in 2.2.12.

henrypp commented 6 years ago

@kiwijam you can use "Reset" settings feature and then re-install filters

tokariu commented 6 years ago

can confirm the problem still exists in 2.2.12. the rundll32 notifications from issue https://github.com/henrypp/simplewall/issues/193 are showing up 5 hours after the process ran and terminated.

henrypp commented 6 years ago

Hey people, go test who have problem: https://github.com/henrypp/simplewall/issues/193#issuecomment-396875573

henrypp commented 6 years ago

2.3 fix this problem?

ltguillaume commented 6 years ago

It looks like there's a lot of improvement, yes! Thanks! I'll keep you posted :-)

tokariu commented 6 years ago

there is still something strange going on, though. While the popup notifications come up almost instantly again in v2.3 like it used to be, some of the notifications still seem to have hours of delay. it happend yesterday, as there were coming up popups of applications I used half a day ago and while they we're not running at all.

this obiously means that there is a case where either simplewall switches completely back to old behaviour, or it is having still problems with some applications but not all. I restarted filters and the simplewall.exe then it seemed to be working again.

ltguillaume commented 6 years ago

Looked like it worked for a while (on v2.3). But now I've updated to v2.3.3, I have the following issues:

g-i-o-r-g-i-o commented 2 years ago

simplewall 3.6.1 64 bit shows empty popups for new rules, the title of the popup is: network alert -simplewall