Jump to content

Recommended Posts

Posted

Hi,

 

We have a meeting/training room where we have companies giving us product demo's etc...

 

What would be the best of having a network point in the room that gives them internet access securely without the possiblity of their machine compromising our lan.

 

Would a firewall i.e smoothwal in between this data point and our network do the job or not?

 

Or any other ideas.

 

Our internet is provided by the lea via a cisco router, all of our traffic has to go out via their internal proxy server as well.

 

If you need more info shout.

 

Ben

Posted

Sounds like an ideal job for Smoothwall, set up the meeting room on the red interface to protect your network and enable snort for intrusion detection. Smoothwall (free version) will only provide a firewall on one interface, so the meetings room won't be protected against attacks from within your network. If you need to firewall incoming and outgoing traffic between your network and the meetings room, can be done with iptables - or maybe check some of the smoothwall mods on the smoothwall forum.

 

edit: and of course you'll need to open http and https to the LEA proxy

Posted
You could use the orange interface as well and implement the full firewall mod this allows you to fully control the traffic between each interface.
Posted

Thats what I thought having used smoothie free and corporate before, obviously with this setup it would give out dhcp on the green interface which would be the meeting room secure point and then the red, internet interface is actually my internal lan I presume? or as the firewall will allow all traffic from the green onto the red is that actually going to protect the rest of the lan?

 

Ben

Posted

Cheers CN will have a look at it now.

Gotta download any iso's etc... I need from home because doubt it will work at school.

 

 

Ben

Posted

I think in the smoothwall case the meeting room would be on the orange interface which is usually the DMZ or a Wireless AP and your Lan would be green. Im not sure if it supports that kind of configuration though.

I think you will probably get the desired result with the mod I mentioned with a basic red and green. You just need to say traffic on the internet ports you need can only go to your router IP and nowhere else on green.

Alternatively a basic Linux install with IP tables configured by Shorewall is fairly easy to use.

Posted

Ok Chris thanks for that I'm keen to ge ta smoothie box installed again and have a play but will look at others toos. Just will be nice to have a data point labelled "Secure Internet" and be able to have demo guys just plug into without worrying about the state of their laptop because they all tell me there are no viruses etc... on their laptop.

 

Ben

Posted

Ok got smoothie express 2 installed but still playing with it. I suppose the ideal solution would be a small appliance type device maybe a mini-itx machine that could be transported to wherever the contractor/sales person needs internet access and then plugged in between them and your network.

 

As we have a conference room where these things normally take place I can trial this with a standard mini tower pc.

 

Ben

Posted
You could also try IPCOP - I know that this allows you to run SNORT on the Red and Green interfaces plus it's a little more feature-rich out of the box than Smoothwall Free (or whatever it's name is).
Posted
Thanks for the suggestion I'm happy with my smoothwall express these have a fond place in my heart.

 

Ben

 

I guess it's down to which side you took when the projects split ;)

Posted

I am watching this thread interest as we are about to start community room and idea of having a secure network point from rest of network sounds good...

 

Just thinking there might be times when staff want to use it and access main network is there anyway to do this with smooth or IPCOP by having some kind of client installed on laptop like for example..

 

ideas

 

Russ

Posted
If you have managed switches, why not vlan it?

 

VLAN it to where? You're going to have to make a gateway for that VLAN somewhere. Simplest would be to make that a spare LAN interface on your WAN router and set some ACLs, but if you don't have a spare i/f then a linux NAT box would be fine.

 

Well unless your switches also route & implement layer-3 ACLs.

Posted

We don't have control over out wan router as that is an lea managed service.

 

If I were to use a small mini-itx pc which can be bought with ipcop loaded and setup via cf card for £250 then this could be moved to where ever an outside salemans/contractor may require internet access. If I vlan'ed it then I would have to change that everytime someone wanted to plug in via a different network point.

 

Ben

Posted

Russ you may be able to do it by allowing certain macs address to access everything on the red rather than just say http and https using the full control firewall mod when I've got it all set up I'll have a look.

 

Though smoothie was giving me problems today so I did try an ipcop install but that didn't work properly either turned out to be a faulty nic on the red.

 

Ben

  • 2 weeks later...
Posted

Sorry to bump but we have just initiated this as a test. Partly for external people coming in and partly to hook 'nasty' machines we get asked to look at from time to time.

 

Quick question though. We have it all set up, the safe NIC attached to the network pointing directly at the router. The unsafe NIC attached to it's own hub that ports are hooked into. We have set Smoothwall to be a DHCP and given it a different IP range and sub net and not touched the firewall, so only web traffic works. I am still a bit cautious as to how safe it is to just hook random and sometimes downright dirty computers to the network, even being segregated as it is.

 

Can someone allay my fears that all is well? Mainly along the lines of worst case scenario that a contractor comes in and has a nasty worm, hooks into the segregated network and nothing bad can happen. We have tried some tests, but with the completely different sub-net and range that seems to stop most things seeing anythign else, but as I said I'm still a little uneasy to blindly trust it!

 

ta

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...