Re: Visitors on LAN

From:
Date: 10/19/02


Date: Sat, 19 Oct 2002 12:39:38 +0100


"Bill Greenley" <bg@bgnospam.com> wrote in message
news:m2Cr9.63085$gr6.59283@rwcrnsc53...
> Is the following a safe/viable means of allowing visitors/vendors to
attach
> to office LAN for Internet access without exposing the LAN (inexpensive
> solution):
>
> The "visitor" port is attached to a SOHO broadband router/switch that has
> DHCP enabled. It's "inside" subnet is 192.168.x with subnet mask of
> 255.255.255.0. On its broadband side it will do a DHCP request on the
> office LAN and receive an "external" IP address in 192.168.y with subnet
> mask 255.255.255.0 This sets up its default gateway (our existing router
to
> Internet) and DNS.

It depends what you are trying to protect. The address trnaslation within
the SOHO router will allow access to "internet" style services on your LAN
(i.e pop mail, web intranet), but should block windows style files shares.

If you want to be more secure a better way may be to connect the SOHO router
to a DMZ on your main firewall - that way you can define exactly what they
have access to on the internal network.

>
> Or, do I have this "daisy-chain" reversed? Seems it would complicated
port
> forwarding or incoming HTTP proxy if I reversed this?
>
> tia

--
Good luck

Stephen Hope - remove xx from address.



Relevant Pages

  • RES: DMZ design
    ... DMZ cannot access the Office LAN and from Office LAN just the ... necessary access to the internet (e-mail, http and any other port access ... technical IT security event. ...
    (Security-Basics)
  • Re: dual dns servers and vpn over broadband
    ... > everything it needs to via dns. ... > be able to resolve the office lan system names. ... > server then everything is tickety boo... ... all dns-names visible from Internet (but you are not supposed to ...
    (comp.unix.bsd.freebsd.misc)
  • Ethernet VS WiFi network
    ... I have a small office lan to which I connect from home via an ... accesspoint. ... can browse the internet and I can see the shares at the office network. ...
    (microsoft.public.windowsxp.network_web)
  • Cable connects but WiFI does not
    ... I have a small office lan to which I connect from home via an ... accesspoint. ... can browse the internet and I can see the shares at the office network. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Routing and RRAS Problem - Pleasehelp
    ... Traffic from your "internal" subnet can get ... out to the Internet by default routing, but the return traffic will fail. ... You need to add an extra route to the Linksys router so that it knows how to ...
    (microsoft.public.windows.server.networking)