Networking Forums

Networking Forums > Network Hardware > Home Networking > Restricting Network

Reply
Thread Tools Display Modes

Restricting Network

 
 
Clive
Guest
Posts: n/a

 
      03-22-2007, 10:10 AM
I know this may not be directly related to Networking, but here goes.

I recently bought to new laptops to replace ageing desktops. No
problem networking everything.

The laptops connect via wireless and the desktops cat5/6. I would like
to put the old desktops in two spare bedrooms to allow family and
friends who stay with us Web access (using Firefox - my prefered
browser), but would not want them being able to do anything else on
the network i.e. access other laptops/desktops, printers.

Is there anyway I can setup something like this - so they just have
browser access?

Thanks

Clive

 
Reply With Quote
 
 
 
 
Mike Scott
Guest
Posts: n/a

 
      03-22-2007, 01:33 PM
Clive wrote:
> I know this may not be directly related to Networking, but here goes.
>
> I recently bought to new laptops to replace ageing desktops. No
> problem networking everything.
>
> The laptops connect via wireless and the desktops cat5/6. I would like
> to put the old desktops in two spare bedrooms to allow family and
> friends who stay with us Web access (using Firefox - my prefered
> browser), but would not want them being able to do anything else on
> the network i.e. access other laptops/desktops, printers.
>
> Is there anyway I can setup something like this - so they just have
> browser access?


Yes, if you're prepared to put the "guest" machines on a separate
network segment on a firewalled router, and set up the firewall tables
accordingly. I used to do just this at home, separating an untrusted
"kids" segment from a trusted "parents" segment - all windows file/print
traffic was prohibited between segments; most internet-bound traffic was
permitted from either.

/But/ I use an old PC running freebsd as internet
gateway/jack-of-all-trades, a solution that may not suit the
non-unix-minded. I rather doubt that there's a domestic quality router
around that would fill the purpose.
 
Reply With Quote
 
Dr Zoidberg
Guest
Posts: n/a

 
      03-22-2007, 08:04 PM
Mike Scott wrote:
> Clive wrote:
>> I know this may not be directly related to Networking, but here goes.
>>
>> I recently bought to new laptops to replace ageing desktops. No
>> problem networking everything.
>>
>> The laptops connect via wireless and the desktops cat5/6. I would
>> like to put the old desktops in two spare bedrooms to allow family
>> and friends who stay with us Web access (using Firefox - my prefered
>> browser), but would not want them being able to do anything else on
>> the network i.e. access other laptops/desktops, printers.
>>
>> Is there anyway I can setup something like this - so they just have
>> browser access?

>
> Yes, if you're prepared to put the "guest" machines on a separate
> network segment on a firewalled router, and set up the firewall tables
> accordingly.


No need to do that.
Assuming the old machines are running 2k or xp it's not all that hard to
lock them down so that all they can do is run a browser of your choice with
no access to any other apps or settings.

Although I do wonder , if these guests are so untrustworthy , why they are
being allowed into the house and given a computer to play with

--
Alex

"I laugh in the face of danger. Then I hide until it goes away"

www.drzoidberg.co.uk www.ebayfaq.co.uk


 
Reply With Quote
 
Linker3000
Guest
Posts: n/a

 
      03-22-2007, 09:01 PM
Clive wrote:
> I know this may not be directly related to Networking, but here goes.
>
> I recently bought to new laptops to replace ageing desktops. No
> problem networking everything.
>
> The laptops connect via wireless and the desktops cat5/6. I would like
> to put the old desktops in two spare bedrooms to allow family and
> friends who stay with us Web access (using Firefox - my prefered
> browser), but would not want them being able to do anything else on
> the network i.e. access other laptops/desktops, printers.
>
> Is there anyway I can setup something like this - so they just have
> browser access?
>
> Thanks
>
> Clive
>


If your Internet Access is via a router with multiple LAN ports, check
whether it supports VLAN - with this you place the ports into groups so
they are effectively isolated from each other but can share Internet access.

eg:

VLAN 1 = LAN Port 1 for Desktop #1
VLAN 2 = LAN Port 2 for Desktop #2
VLAN 3 = LAN Ports 3 + 4 + Wifi

You can certainly do this with the Draytek 2600/2800 routers.
 
Reply With Quote
 
Mike Scott
Guest
Posts: n/a

 
      03-23-2007, 07:36 AM
Dr Zoidberg wrote:
> Mike Scott wrote:
>> Clive wrote:

....
>>> like to put the old desktops in two spare bedrooms to allow family
>>> and friends who stay with us Web access (using Firefox - my prefered
>>> browser), but would not want them being able to do anything else on
>>> the network i.e. access other laptops/desktops, printers.
>>>
>>> Is there anyway I can setup something like this - so they just have
>>> browser access?

>> Yes, if you're prepared to put the "guest" machines on a separate
>> network segment on a firewalled router, and set up the firewall tables
>> accordingly.

>
> No need to do that.
> Assuming the old machines are running 2k or xp it's not all that hard to
> lock them down so that all they can do is run a browser of your choice with
> no access to any other apps or settings.


Too obvious :-) But even a browser is dangerous - if the "guests" are
so untrustworthy, even firefox could let them (whether accidentally or
by design) install all manner of Evil Things on the guest machine -
which is why all things windows need barring from an effectively
untrustable workstation. And if the "guests" are also Evil, what's to
stop them bringing their own (bootable?) disks along.......

>
> Although I do wonder , if these guests are so untrustworthy , why they are
> being allowed into the house and given a computer to play with


Mere incompetence would be quite enough, plus window inbuilt security,
to potentially cause problems.

 
Reply With Quote
 
tinnews@isbd.co.uk
Guest
Posts: n/a

 
      03-23-2007, 08:18 AM
Dr Zoidberg <alexNOOOOOO!!!!!!!@drzoidberg.co.uk> wrote:
> Mike Scott wrote:
> > Clive wrote:
> >> I know this may not be directly related to Networking, but here goes.
> >>
> >> I recently bought to new laptops to replace ageing desktops. No
> >> problem networking everything.
> >>
> >> The laptops connect via wireless and the desktops cat5/6. I would
> >> like to put the old desktops in two spare bedrooms to allow family
> >> and friends who stay with us Web access (using Firefox - my prefered
> >> browser), but would not want them being able to do anything else on
> >> the network i.e. access other laptops/desktops, printers.
> >>
> >> Is there anyway I can setup something like this - so they just have
> >> browser access?

> >
> > Yes, if you're prepared to put the "guest" machines on a separate
> > network segment on a firewalled router, and set up the firewall tables
> > accordingly.

>
> No need to do that.
> Assuming the old machines are running 2k or xp it's not all that hard to
> lock them down so that all they can do is run a browser of your choice with
> no access to any other apps or settings.
>

But since you can run just about *anything* through a browser window
and/or use port 80 for just about any traffic it's not too difficult
to get around even that restriction.

--
Chris Green
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Restricting access on a wifi network Andrew Wireless Networks 6 12-12-2008 09:23 PM
Restricting computers on a network ib_redbeard Windows Networking 3 06-09-2006 01:53 AM
restricting access Bob Wireless Networks 0 03-26-2006 10:43 PM
home network but restricting childrens access to the web andy b Wireless Networks 4 07-26-2005 12:31 PM
restricting bandwidth Charles J Stella Broadband Hardware 2 06-12-2004 01:11 AM



1 2 3 4 5 6 7 8 9 10 11