Computing.Net > Forums > Security and Virus > LAN Security

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

LAN Security

Reply to Message Icon

Original Message
Name: ToPo (by topo)
Date: September 14, 2005 at 22:11:52 Pacific
Subject: LAN Security
OS: Win XP Pro
CPU/Ram: 1.2GHZ / 512 SD
Comment:

I have a very important question I'm hoping someone can answer...

I am supporting a small LAN with about 5 workstations, 1 of which is a Win XP Pro machine acting as a file server. All machines are protected by a hardware firewall and all are connected to the LAN through a D-Link cable/DSL router. Here is my problem... One of the users insists on using his computer for file sharing and downloading potentially harmful files through programs such as Kazaa... Is there any way to ensure his computer will not affect the other LAN workstations if harmful content were to arise on his system??... Should he be off the network??... Should he be off the LAN and on a seperate computer??...

Any ideas or suggestions will be much appreciated...

Asus A7V133
AMD Athlon 1.2Ghz
512Mb SDRAM
ATI Radeon 9600XT
SoundBlaster Live! Value


Report Offensive Message For Removal


Response Number 1
Name: clover
Date: September 15, 2005 at 04:09:45 Pacific
Reply:

Have a look at this it may be of use

http://www.grc.com/nat/nat.htm

good luck


Report Offensive Follow Up For Removal

Response Number 2
Name: ToPo (by topo)
Date: September 15, 2005 at 10:03:47 Pacific
Reply:

Thanks clover,

That web site was really informative, but it didn't have the info to solve my problem...

The problem is that all computers (including the potentially harmful one) on the LAN must be able to communicate with the 1 file server which is also on the same LAN... If I use multiple NAT routers, that will allow the file server to communicate with the other LAN workstations, but will not allow the workstations to communicate back to the file server... If I am wrong please let me know... I basically need this one potentailly harmful station to be able to access everything on the LAN, but not infect anything on the LAN including the file server if it is infected... if that is possible... if not... I'm open to any ideas that could solve this problem...

Thanks for your help,
ToPo

Asus A7V133
AMD Athlon 1.2Ghz
512Mb SDRAM
ATI Radeon 9600XT
SoundBlaster Live! Value


Report Offensive Follow Up For Removal

Response Number 3
Name: Dirty_Sanchez
Date: September 15, 2005 at 10:36:17 Pacific
Reply:

if the user downloads something harmful then yes, he can infect everyone else (including bringing in a trojan whiich may allow others access to your nw). THere have to be rules and guidelines followed for a NW to remain stable and safe. This is somehting you'll need to decide but, if he continues to do this, then it could happen. If this is a work network, how can he justify it as 'needed for work'? If you have the authority take him off, if not, find out who does.


Report Offensive Follow Up For Removal

Response Number 4
Name: ToPo (by topo)
Date: September 15, 2005 at 10:53:52 Pacific
Reply:

Unfortunatly he is the owner and what he says goes... As a temporary solution I was going to use another computer he has kicking around as a "jukebox" machine, where he can download music, files, etc... This machine will have all the sharing capabilites disabled, but will remain on the same LAN (to be connected to the internet)... what do you think?... good or bad? Will this still make the network vulnerable because of this "jukebox" machine even with file sharing disabled?

Asus A7V133
AMD Athlon 1.2Ghz
512Mb SDRAM
ATI Radeon 9600XT
SoundBlaster Live! Value


Report Offensive Follow Up For Removal

Response Number 5
Name: Dirty_Sanchez
Date: September 15, 2005 at 11:56:48 Pacific
Reply:

still not safe/perfect but, sometimes you have to do what you have to do with people like this. Actually something happening would be the best thing for him since he might then understand what he is doing if he lost work/time and had to do it again. Do you have a valid backup regime and current AV at least? Even if the other PC doesnt have file sharing enabled, it is still possible for him to infect everyone else from that PC and let people piggyback in with him.


Report Offensive Follow Up For Removal


Response Number 6
Name: johns3
Date: September 15, 2005 at 15:17:03 Pacific
Reply:

You may want to get a second router and subnet off the "jukebox" PC.

1st router
wan side configured to ISP
LAN side default out of the box if you wish.
IP 192.168.1.1
sub 255.255.255.0
enable DCHP


2nd router
WAN side DHCP off the 1st router
LAN side
IP 192.168.2.1
subnet 255.255.255.0
DHCP enabled

this will at least give you some protection.


Report Offensive Follow Up For Removal

Response Number 7
Name: ToPo (by topo)
Date: September 15, 2005 at 16:00:14 Pacific
Reply:

Thanks guys for your advice... I do have a scheduled backup routine in place for this network and up to date AV so i feel a little better in that respect... I think I'm going to go with JOHN3's idea of introducing a second router into the LAN with a second subnet... The more secure the better...

Thanks for all your help,
ToPo

Asus A7V133
AMD Athlon 1.2Ghz
512Mb SDRAM
ATI Radeon 9600XT
SoundBlaster Live! Value


Report Offensive Follow Up For Removal

Response Number 8
Name: Jennifer SUMN
Date: September 16, 2005 at 18:20:18 Pacific
Reply:

I'd say if he's that irresponsible regarding his own Company's Security, you all may soon be looking for new employment.

Let him do what he wants, and I'd recommend you look for employment somewhere that will actually appreciate your professionalism and attention to detail.

Soylent Green is PEOPLE!!!


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home



Results for: LAN Security

wlan secure!!no not at all
    Summary: hello you think your wireless lan is secure well just read this ************************************************* * * * The Definitive Guide To Wireless WarX'ing * ----------------...
www.computing.net/answers/security/wlan-secureno-not-at-all/3088.html

W32.apolre
    Summary: hi carrol, if the worm is aplore and not apolre, here's some info for you: This worm combines a VBS mass-mailing routine and includes an IRC bot which may allow an attacker to gain remote access to th...
www.computing.net/answers/security/w32apolre/2848.html

virus alert!!!!!
    Summary: New Strain of Mass-Email Virus Poses Increased Risk September 19, 2003 Security vendors on Friday continued to issue alerts about a new mass-mailing virus, which has been identified as a variant of t...
www.computing.net/answers/security/virus-alert/6536.html








Which MP3 player do you have?

iPod/iPhone
Zune
Something Else
None


View Results

Poll Finishes Today.
Discuss in The Lounge
Poll History






Data Recovery Software