Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Setting up a secure LAN with no access to Public Internet?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
PCTFW: Release of PCTFW v6.0.0.52 beta »
« Security Software Updates - 5 July 2009  
AuthorAll Replies


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
·AT&T U-Verse
·AT&T Midwest

reply to slajoh01
Re: Setting up a secure LAN with no access to Public Internet?

The following will probably work, though I have not tested it.

Call you routers R1 and R2. You decide which is which based on your other needs.

R1 connects to Internet, and your Internet connected computers are on LAN ports (or WiFi) from router R1.

Router R2 is for your LAN that is not to be connected to internet. Connect the WAN port of R2 to one of the LAN ports of R1. But, in the WAN configuration for R2, manually assign it an IP address on its WAN side (should be an IP suitable for the LAN side of R1, but outside the DHCP range). However, do notassign an internet gateway IP in the WAN settings or R2. Or, alternatively, if it insists, then assign a bogus internet gateway IP - an IP appropriate for the LAN side of R1, but an IP that is not used by anything in your network. That should allow computers connected to the R2 LAN to access computers on the R1 LAN, but not access the Internet.

For even greater isolation, use an ethernet switch. The switch uplink connects to the LAN of R1. All the computers for the LAN of R1 connect through the switch, and the WAN side of R2 connects through the switch. Setup MAC filtering on R1 to disallow access by the WAN MAC address used by R2. That will leave R1 actively blocking access by R2. However, access to the LAN of R1 is still possible since that only uses the switch and does not depend on sending packets through R1.

As previously mentioned, I have not actually tried this. So if you get it working, post a report on how it works out.
--
AT&T dsl; Speedstream 5100b modem; openSuSE 11.0; firefox 3.0.11

slajoh01

join:2005-04-23
Thanks for this info and I will print this out too.
Both of my routers have an option to backup my router settings first before I test it out.
-
Forums » Up and Running » Security » SecurityPCTFW: Release of PCTFW v6.0.0.52 beta »
« Security Software Updates - 5 July 2009  


Wednesday, 02-Dec 08:28:05 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [153] Comcast Releasing Promised Usage Meter
· [69] Baltimore To Ban Lazy Cable Installs
· [60] Latest Consumer Reports Survey Not Kind To AT&T
· [56] Broadband Killed The Game Console
· [52] Rogers Unveils The ISP Dream Model
· [45] ACTA: Global Three Strikes
· [41] Rural Carriers Quickly Embracing Fiber
· [35] Charter Exits Chapter 11
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [26] Vivendi Agrees, Comcast/NBC Deal Soon
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· [Phish] email from CDC "personal vaccination profile" [Spam, Scam and Phishbusters]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Furnace starts, then shuts off. [Home Repair & Improvement]
· Ooma changing features [VOIP Tech Chat]
· [Newsgroups] Newzleech down? [Filesharing Software]
· [Config] cisco asa 5505 with multiple outside IP addresses [Cisco]
· Wind getting a little more aggressive [TekSavvy]
· Data Usage Meter Launched [Comcast HSI]
· UBB round 2 at the CRTC [Canadian Broadband]