Networking Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me

The Shed is going Social! Join us on FaceBook and Twitter and chime in on the conversation.

Go Back   Dev Shed ForumsSystem AdministrationNetworking Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old June 26th, 2012, 06:37 AM
siDev12 siDev12 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2012
Posts: 4 siDev12 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 54 m 27 sec
Reputation Power: 0
Security when using a network switch

Hello

Complete newbie to networking and needed some advice.

I have a Wireless and 4 port internet router provided by my ISP and have all 3 ports used by other wired devices. I have 3 more machines I need to connect to the internet and so I was thinking of getting a 4 port Gigabit Ethernet Switch.

If I were to connect this switch to the 4th available port of my ISP wireless router, I presume all of the machines connected to that switch would be able to receive the internet connection.

My concern is that if someone were to connect to my ISP router via wireless (which I do for iphone and laptops), with the switch now connected to the ISP router, are people able to access files from the other machines that are connected to the switch?

I do not want this to happen as my aim is to have only the computers attached to the switch to talk to each other, share files, etc and not if anyone is accessing the internet router wirelessly.

Any advice would be appreciated

Thanks
Si

Reply With Quote
  #2  
Old June 26th, 2012, 08:33 AM
E-Oreo's Avatar
E-Oreo E-Oreo is offline
Lost in code
Click here for more information.
 
Join Date: Dec 2004
Posts: 7,931 E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)  Folding Points: 945 Folding Title: Novice Folder
Time spent in forums: 2 Months 7 h 48 m 54 sec
Reputation Power: 7053
Quote:
My concern is that if someone were to connect to my ISP router via wireless (which I do for iphone and laptops), with the switch now connected to the ISP router, are people able to access files from the other machines that are connected to the switch?

Yes, assuming the machines are file sharing in some way.

Some routers allow you to configure "guest" wireless networks that are segregated from your main local network.

Alternatively you could configure the firewalls on each of the connected machines to block local traffic.

Using a second router instead of a switch would probably work too, although I've not set up a network in that way before.
__________________
PHP FAQ
How to program a basic, secure login system using PHP

Quote:
Originally Posted by Spad
Ah USB, the only rectangular connector where you have to make 3 attempts before you get it the right way around

Reply With Quote
  #3  
Old June 26th, 2012, 08:59 AM
siDev12 siDev12 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2012
Posts: 4 siDev12 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 54 m 27 sec
Reputation Power: 0
Quote:
Originally Posted by E-Oreo
Yes, assuming the machines are file sharing in some way.

Some routers allow you to configure "guest" wireless networks that are segregated from your main local network.

Alternatively you could configure the firewalls on each of the connected machines to block local traffic.

Using a second router instead of a switch would probably work too, although I've not set up a network in that way before.


Thanks for the info! I'll be having a mac 10.6, win vista and win 7 and potentially a NAS on this network so hope that each of them will offer an easy way to talk to each other, receive an internet connection but be able to block any unwanted intruders.

If I used a gigabit router instead, what advantages would I have of using that over a switch? Would the approach to security be the same? Do most routers offer this 'guest' feature? What term for this feature, would I need to look out for when buying a router?

Forgive my lack of knowledge, but with the firewall - when you say block local traffic, does that mean that I wouldn't be able to share files in a folder from one machine to the other? Or does 'local traffic' refer specifically to the WWW?

To be honest, if I can try and configure another router with 'guest' wireless networks as you described - that'd probably be ideal.

Thanks.

Reply With Quote
  #4  
Old June 26th, 2012, 10:41 AM
E-Oreo's Avatar
E-Oreo E-Oreo is offline
Lost in code
Click here for more information.
 
Join Date: Dec 2004
Posts: 7,931 E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)E-Oreo User rank is General 91st Grade (Above 100000 Reputation Level)  Folding Points: 945 Folding Title: Novice Folder
Time spent in forums: 2 Months 7 h 48 m 54 sec
Reputation Power: 7053
With a separate router you wouldn't be able to easily share between the three connected to your first router and the three connected to your second router. It would put the machines on separate local networks.

I don't know whether the guest feature is common or not. My Netgear router has it and it's just called a guest network. The router I have is not an incredibly high end one.

With a firewall you could allow connections to and from specific machines on specific ports and block the rest.

Reply With Quote
  #5  
Old June 26th, 2012, 12:23 PM
siDev12 siDev12 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2012
Posts: 4 siDev12 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 54 m 27 sec
Reputation Power: 0
Quote:
Originally Posted by E-Oreo
With a separate router you wouldn't be able to easily share between the three connected to your first router and the three connected to your second router. It would put the machines on separate local networks.


I see, so aside from the 3 machines on the separate router being able to share the internet connection from the first (ISP) router, any other device attached to the first router cannot be accessed by the 3 machines on the second router? (so ethernet printers for example)

Quote:
Originally Posted by E-Oreo
With a firewall you could allow connections to and from specific machines on specific ports and block the rest.


Right, so this looks to be what I might need to work towards. So if I got a NETGEAR GS105, attached it to my ISP Router for the 3 machines that I'll connect the NETGEAR to access the internet. For the firewall settings, is that something that I need to set on each machine or on the ISP Router? (I presume the NETGEAR doesn't have any 'settings' that can be accessed). Apologies again for what is probably a simple concept to grasp. I've never set up a network before.

If I am needing to adjust the firewall settings for each machine, how will I know what ports I would need to block without restricting access to the internet and not have to worry about the 3 machines being able to share data between each other? If you have any links to simple explanations as to how to do this, I would be grateful.

Thanks again!

Reply With Quote
  #6  
Old June 26th, 2012, 05:49 PM
seack79 seack79 is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: May 2004
Location: surfing the interwebz
Posts: 2,317 seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level) 
Time spent in forums: 2 Weeks 1 Day 20 h 52 m 41 sec
Reputation Power: 1940
A simple thing to look for is a setting called, "access point isolation" on the wireless router. This prevents wireless clients from talking to other machines on the network; and vice versa.

Reply With Quote
  #7  
Old June 27th, 2012, 10:24 AM
AdamPI's Avatar
AdamPI AdamPI is offline
Automagically Delicious
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: May 2004
Location: 127.0.0.2 - I live next door.
Posts: 2,198 AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level) 
Time spent in forums: 3 Weeks 6 Days 22 h 13 m 56 sec
Reputation Power: 2735
Did I miss something or is there a reason why encryption cannot be put on the wireless LAN to keep everyone off of it? Is this an all-private network?
__________________
Adam TT

Reply With Quote
  #8  
Old June 27th, 2012, 06:34 PM
seack79 seack79 is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: May 2004
Location: surfing the interwebz
Posts: 2,317 seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level)seack79 User rank is General 14th Grade (Above 100000 Reputation Level) 
Time spent in forums: 2 Weeks 1 Day 20 h 52 m 41 sec
Reputation Power: 1940
I think the OP wants to allow people on the network, but not let them access each other's files on the LAN.

Reply With Quote
  #9  
Old June 28th, 2012, 01:59 PM
Sepodati's Avatar
Sepodati Sepodati is offline
Banned (not really)
Dev Shed God 20th Plane (14500 - 14999 posts)
 
Join Date: Dec 1999
Location: Brussels, Belgium
Posts: 14,628 Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)Sepodati User rank is General 51st Grade (Above 100000 Reputation Level)  Folding Points: 97169 Folding Title: Advanced FolderFolding Points: 97169 Folding Title: Advanced FolderFolding Points: 97169 Folding Title: Advanced FolderFolding Points: 97169 Folding Title: Advanced FolderFolding Points: 97169 Folding Title: Advanced Folder
Time spent in forums: 3 Months 6 Days 2 h 39 m 6 sec
Reputation Power: 4375
Send a message via ICQ to Sepodati Send a message via Yahoo to Sepodati
If you want to offer a network to guests with machines that you don't trust and that shouldn't talk to anything else on your network, then you either need a wireless router that'll support a guest network with a separate SSID or a separate wireless router.

If you and your guests need common access to things like the printer and NAS, then that's going to be difficult.

If you can't trust machines on your network, then you're going to either need some specific firewall rules in your router (if supported) or individual firewall/security software on each computer (or have them locked down).

It would help if you gave a little more background on exactly what you're trying to accomplish.
__________________
-- Cigars, whiskey and wild, wild women. --

Reply With Quote
  #10  
Old June 28th, 2012, 02:53 PM
AdamPI's Avatar
AdamPI AdamPI is offline
Automagically Delicious
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: May 2004
Location: 127.0.0.2 - I live next door.
Posts: 2,198 AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level)AdamPI User rank is General 26th Grade (Above 100000 Reputation Level) 
Time spent in forums: 3 Weeks 6 Days 22 h 13 m 56 sec
Reputation Power: 2735
See, the way I read it was that the OP was asking the "what if someone were to do that like I do?" Not so much as a "What happens when I allow them to..." Maybe I'm reading into it too much.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationNetworking Help > Security when using a network switch

Developer Shed Advertisers and Affiliates



Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 


Powered by: vBulletin Version 3.0.5
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

© 2003-2013 by Developer Shed. All rights reserved. DS Cluster - Follow our Sitemap