|
| Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free! |
LAN Security
|
Original Message
|
Name: ToPo (by topo)
Date: September 14, 2005 at 22:11:52 Pacific
Subject: LAN SecurityOS: Win XP ProCPU/Ram: 1.2GHZ / 512 SD |
Comment: I have a very important question I'm hoping someone can answer... I am supporting a small LAN with about 5 workstations, 1 of which is a Win XP Pro machine acting as a file server. All machines are protected by a hardware firewall and all are connected to the LAN through a D-Link cable/DSL router. Here is my problem... One of the users insists on using his computer for file sharing and downloading potentially harmful files through programs such as Kazaa... Is there any way to ensure his computer will not affect the other LAN workstations if harmful content were to arise on his system??... Should he be off the network??... Should he be off the LAN and on a seperate computer??... Any ideas or suggestions will be much appreciated... Asus A7V133 AMD Athlon 1.2Ghz 512Mb SDRAM ATI Radeon 9600XT SoundBlaster Live! Value
Report Offensive Message For Removal
|
|
Response Number 2
|
Name: ToPo (by topo)
Date: September 15, 2005 at 10:03:47 Pacific
|
Reply: Thanks clover, That web site was really informative, but it didn't have the info to solve my problem... The problem is that all computers (including the potentially harmful one) on the LAN must be able to communicate with the 1 file server which is also on the same LAN... If I use multiple NAT routers, that will allow the file server to communicate with the other LAN workstations, but will not allow the workstations to communicate back to the file server... If I am wrong please let me know... I basically need this one potentailly harmful station to be able to access everything on the LAN, but not infect anything on the LAN including the file server if it is infected... if that is possible... if not... I'm open to any ideas that could solve this problem... Thanks for your help, ToPo Asus A7V133 AMD Athlon 1.2Ghz 512Mb SDRAM ATI Radeon 9600XT SoundBlaster Live! Value
Report Offensive Follow Up For Removal
|
|
Response Number 3
|
|
Reply: if the user downloads something harmful then yes, he can infect everyone else (including bringing in a trojan whiich may allow others access to your nw). THere have to be rules and guidelines followed for a NW to remain stable and safe. This is somehting you'll need to decide but, if he continues to do this, then it could happen. If this is a work network, how can he justify it as 'needed for work'? If you have the authority take him off, if not, find out who does.
Report Offensive Follow Up For Removal
|
|
Response Number 4
|
Name: ToPo (by topo)
Date: September 15, 2005 at 10:53:52 Pacific
|
Reply: Unfortunatly he is the owner and what he says goes... As a temporary solution I was going to use another computer he has kicking around as a "jukebox" machine, where he can download music, files, etc... This machine will have all the sharing capabilites disabled, but will remain on the same LAN (to be connected to the internet)... what do you think?... good or bad? Will this still make the network vulnerable because of this "jukebox" machine even with file sharing disabled? Asus A7V133 AMD Athlon 1.2Ghz 512Mb SDRAM ATI Radeon 9600XT SoundBlaster Live! Value
Report Offensive Follow Up For Removal
|
|
Response Number 5
|
|
Reply: still not safe/perfect but, sometimes you have to do what you have to do with people like this. Actually something happening would be the best thing for him since he might then understand what he is doing if he lost work/time and had to do it again. Do you have a valid backup regime and current AV at least? Even if the other PC doesnt have file sharing enabled, it is still possible for him to infect everyone else from that PC and let people piggyback in with him.
Report Offensive Follow Up For Removal
|
|
Response Number 6
|
Name: johns3
Date: September 15, 2005 at 15:17:03 Pacific
|
Reply: You may want to get a second router and subnet off the "jukebox" PC. 1st router wan side configured to ISP LAN side default out of the box if you wish. IP 192.168.1.1 sub 255.255.255.0 enable DCHP 2nd router WAN side DHCP off the 1st router LAN side IP 192.168.2.1 subnet 255.255.255.0 DHCP enabled
this will at least give you some protection.
Report Offensive Follow Up For Removal
|
|
Response Number 7
|
Name: ToPo (by topo)
Date: September 15, 2005 at 16:00:14 Pacific
|
Reply: Thanks guys for your advice... I do have a scheduled backup routine in place for this network and up to date AV so i feel a little better in that respect... I think I'm going to go with JOHN3's idea of introducing a second router into the LAN with a second subnet... The more secure the better... Thanks for all your help, ToPo Asus A7V133 AMD Athlon 1.2Ghz 512Mb SDRAM ATI Radeon 9600XT SoundBlaster Live! Value
Report Offensive Follow Up For Removal
|
|
Response Number 8
|
|
Reply: I'd say if he's that irresponsible regarding his own Company's Security, you all may soon be looking for new employment. Let him do what he wants, and I'd recommend you look for employment somewhere that will actually appreciate your professionalism and attention to detail. Soylent Green is PEOPLE!!!
Report Offensive Follow Up For Removal
|

Post Locked
This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
Go to Security and Virus Forum Home
Results for: LAN Security
wlan secure!!no not at all Summary: hello you think your wireless lan is secure well just read this ************************************************* * * * The Definitive Guide To Wireless WarX'ing * ----------------... www.computing.net/answers/security/wlan-secureno-not-at-all/3088.html
W32.apolre Summary: hi carrol, if the worm is aplore and not apolre, here's some info for you: This worm combines a VBS mass-mailing routine and includes an IRC bot which may allow an attacker to gain remote access to th... www.computing.net/answers/security/w32apolre/2848.html
virus alert!!!!! Summary: New Strain of Mass-Email Virus Poses Increased Risk September 19, 2003 Security vendors on Friday continued to issue alerts about a new mass-mailing virus, which has been identified as a variant of t... www.computing.net/answers/security/virus-alert/6536.html
|
|

|