This is a read-only archive. No new posts or registrations. Privacy Page
Hardware

Setting up a restricted network help

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, im pretty much a newbie in the practical area of setting up proper networks, ive set up enough home networks but never tryed anything more complex than connecting some computers to a router (sometimes through a switch) to get internet access, however im trying to set up a "harder" network and would appreciate any assistance, ive made a simple schematic on how i want the network to be working (hosted on imageshack):

[external image: Posted Image]

The owner (my parent :P) is something of a technophobe, so he doesnt want the terminals to have access to the internet, so the line between the switch and the router doesnt exist, ill refer to the subnetwork on the switch as the closed one.

What i want to do is to allow someone from the outside (internet) to access the closed network to be able to work from far away, im trying to figure out the best way to do it, and for that i need to clarify some doubts.

Can i block traffic going from router to switch (or viceversa) except for a specific port? Would setting up a VPN be a good solution? Could i add a password to allow the laptops internet access while blocking everyone else (except for that specific port)?

Im open for any solutions you may come up with, thank you for your time and atention.
Well, the idea of not allowing the workstations to access the internet doesn't really work if you need to access them from the internet. Its totally going to be decided by what solution you use to access the machines remotely. There is absolutely nothing here complicated enough, big enough, or demanding enough to require the added complexity of a VPN. The simplest method would to be to use a free version of LogMeIn or TeamViewer. Both of these require access to the internet over standard ports that would also allow regular internet browsing. So, it can't be blocked. Your only other solution would be to use remote desktop, which means every workstation needs to be a Professional or Business edition Windows operating system, and you will have to reconfigure the registry on each one to give them unique listening ports for RDP and/or you will need to configure several different ports on the router to be forwarded to each workstation. Blocking internet access would be done on the router, but it is likely to not give very granular control and it may be difficult to block a workstation and not a laptop. But, if there is any chance of doing it, that is where you do it. What you need is a real firewall device.
I'm no expert in these things so the Tech Team can probably find holes in my theories… but… what I'd do is… Set your network up so all computers have assigned addresses. Then using your router as the gateway… you should be able to block internet access to all but specific addresses (the laptops) and I think you'd need to disable dchp. Or… maybe better yet… don't connect your switch to the router… but add a wi-fi card to the computer you want to access with LogMeIn and password protect everything. Sounds like a fun problem. Good luck.
The system the company uses hasnt been created by me, so im not sure how it works, by what i have seen it appears to be a simple client/server program with multiple windows (and limited connections), so my bet is it uses a range of ports that i could open on the router while closing all others, using Tomk sugestion i could maybe limit the connection only to the IPs (or Mac addresses) of the computers i want blocked and allow only certain ports, it would probably be easier to block mac addresses since i wouldnt have to change any other settings in the router (but would probably have to redo some of the work when the ethernet cards change). About that firewall device option, i have no idea how firewall devices work or how expensive theyr are so some more info on that would be nice, would a proper firewall protect the computers on the closed network from virus infections or hack attacks? as i said, im new at network stuff especially at a comertial level, so it would have to be a somewhat easy to set up solution with low maintainance, is a firewall device a good option? Thanks for the replies so far.
If you want the type of granular control that you are asking for, with more advanced features like protocol filtering (you allow one protocol of port 80, but not a different protocol over port 80), then you need something more sophisticated than that cheap router. For a cheap, and pretty easy solution (but it does require a stand alone computer to run, but any cheap thing with two network cards will work, I build new boxes for $200 for this product in little mini cases) check out www.untangle.com. It has the features you need, as well as more sophisticated features as paid for apps. This all may be too complicated for what you are interested in. But, I personally think you (or whoever is making the decisions) has already made it more complicated than it should be. :)
If it was up to me i would just connect the switch to the router and it would be done, but the owner is a hardcore technophobe, the idea of having internet access on the same pcs where the system is makes him tremble :P im thinking ill just block any http protocol connections (or even just the port 80) and consider it done, i doubt the system is in danger of an external attack, its the internal "oh look shiny button on a .cn page" im worried about.
Because the computers are behind NAT, it is impossible for any of them to be attacked externally. The user is always the most dangerous aspect of any security setup. Maybe you should point out to the technophobe, that technically he will have to unplug his internet connection if he really wants to keep his computers safe from attack. And, that is only taking into consideration external attacks. What about rogue users? These computers are still plenty vulnerable. You have your remote access software sitting there waiting for attack, and you have other computers on the network that you are going to grant internet access to. So, when one of those computers get infected, or any other infected computer is plugged into the network, ALL the other computers become easily available for attack regardless of your firewall settings. I guess the whole point of my rambling is, if you want to protect the machines, unplug them from the wall. Anything else is kind of being ridiculous. If you want those machines to be safe, I understand, but that will involve removing those machines from the network, or isolating them on their own network if they need communication between each other. And, that means no remote access. If you just want to reduce the risk, then simply block people from accessing the internet on those computers.
I guess that last part is the solution ill be going for, block the computers so the user cant cause any trouble, i dont think we need to worry about external attacks or rogue users, as long as the users cant access the internet the boss should be happy. Edit: Thanks for the help btw, i was going to get myself into some over complex situations :P

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI