Isolating one PC in an office

Reply

Join Date: Feb 2008
Posts: 31
Reputation: brundle is an unknown quantity at this point 
Solved Threads: 0
brundle brundle is offline Offline
Light Poster

Isolating one PC in an office

 
0
  #1
Apr 16th, 2008
I need to isolate one computer in a small office from the office network - from both NetBIOS networking with other machines and at the IP level. The office is just one of a number of businesses in one building - each office has its own network & internet connection hardware connected to a patchbay in a cupboard - I've already tried some measures to physically isolate the machine in question with some wiring changes, but as soon as the device is plugged into the patchbay, the router that provides the office internet connection appears to connect the whole lot anyway (basic NetGear ADSL router).
We have a Netgear Smartswitch on which I've set up a VLAN to encompass all the machines I do want networked and another VLAN that only includes this one machine and the internet port. I can still ping the other office machines from the `isolated` PC and vice versa even though it can't be accessed via NetBIOS. Is a VLAN strictly a Layer 2 thing, or would a Layer 3 managed switch incorporate VLANs that operate at the IP level too? We have some security requirements to fulfil for a planned project, and until there is money available I can't simply move the isolated PC to its own dedicated internet connection (which is the ideal). I know I could use a firewall and block internal private addresses but if the project takes off, a hardware device that deals with unwanted traffic before it can get to the PC in the first place would be the best option.The PC in question will be used for remote-assistance, accessing other computers over the internet. Any suggestions and insight welcome.
Reply With Quote Quick reply to this message  
Join Date: Apr 2005
Posts: 16,273
Reputation: jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all jbennet is a name known to all 
Solved Threads: 543
Moderator
Featured Poster
jbennet's Avatar
jbennet jbennet is offline Offline
Moderator

Re: Isolating one PC in an office

 
0
  #2
Apr 16th, 2008
you can modify the protocol bindings so that certain protocols only work on certain interfaces.

I dit it once (a long time ago) with a windows NT server. Back then , i used IPX for the internal (netware) network card and TCPIP for the internet-facing card, meaning it was more secure as there could be no passthrough at all.
If i am helpful, please give me reputation points.
Reply With Quote Quick reply to this message  
Join Date: Feb 2008
Posts: 31
Reputation: brundle is an unknown quantity at this point 
Solved Threads: 0
brundle brundle is offline Offline
Light Poster

Re: Isolating one PC in an office

 
0
  #3
Apr 21st, 2008
Thanks for the reply - I've already removed the Windows Networking Client and File & Printer Sharing from the PC in question, disabled NetBIOS over TCP/IP - it doesn't need any connection at all to the internal network. I'll probably end up insisting on a separate router and put the machine in its own subnet, no need for expensive equipment that way....
Reply With Quote Quick reply to this message  
Join Date: Jan 2007
Posts: 1,765
Reputation: DimaYasny will become famous soon enough DimaYasny will become famous soon enough 
Solved Threads: 85
Moderator
Featured Poster
DimaYasny DimaYasny is offline Offline
Posting Virtuoso

Re: Isolating one PC in an office

 
0
  #4
Apr 21st, 2008
a second router is the way to go of course
and it's not expensive at all
Real stupidity always beats Artificial Intelligence. (Terry Pratchett)

BA BizMg, MCSE, DCSE, Linux+, Network+
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Network Security Forum


Views: 1264 | Replies: 3
Thread Tools Search this Thread



Tag cloud for Network Security
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC