Isolate several machines on one subnet

  • Thread starter Thread starter Harry Putnam
  • Start date Start date
H

Harry Putnam

I don't see any other general network winxp group so hopefully this
goes here.

First a quick summary of my current setup:



INTERNET
|
DSLMODEM
|
------------- NETGEAR FVS318 fw/router---------------
| | | | |

Mch1 Mch2 mch3 mch4 mch5
Lin win win win win


I want to isolate mch3-5 to only the local network.

That is, only mch 1 a linux machine and mch2 a winxp pro machine,
should be able to freely access the internet. 3-5 should only be able
to talk to/from the local net.

I realize this would not be true isolation as anyone getting to 1-2
would have access to 3-5 so all bets are off. Its more about having
to worry about downloads or link clicks etc.

The Netgear FVS318 appears not to be able to do this for me. But I
could be wrong there. I see no options that look usefull for it.
Blocking of sites might do it but appears it would be a long process
settting itup. Not sure if one can give a net range and have that be
all that is accessable.

I' happily hear that the router can do this.

However:
I'm thinking there is software available that can be deployed on a per
machine basis that can do this.

My reasons are:

3-5 are heavy hitters for graphics work. Any amount of spyware,
adware, virus sw, firewall etc that can be kept off these three will
greatly help.

All the big players in graphics work are heavy resource hogs and don't
want to be competing with spysweeper, counterspy, pc-cillun, kerio
etc, etc etc.

I might have Photoshop, silverfastAI, Imatch and ACDsee all running
while working. These are all 3.2GB machines but still....

I realize this is not really an especially secure way of operating but
I'm really sick of having problems while graphic editing. Never
knowing for sure if its other stuff interfering or what.

I don't really want to spend any more time than really necessary on
network stuff, since I'm in a heavy learning phase on the graphics
stuff.
 
Harry Putnam said:
I don't see any other general network winxp group so hopefully this
goes here.

First a quick summary of my current setup:



INTERNET
|
DSLMODEM
|
------------- NETGEAR FVS318 fw/router---------------
| | | | |

Mch1 Mch2 mch3 mch4 mch5
Lin win win win win


I want to isolate mch3-5 to only the local network.

That is, only mch 1 a linux machine and mch2 a winxp pro machine,
should be able to freely access the internet. 3-5 should only be able
to talk to/from the local net.

I realize this would not be true isolation as anyone getting to 1-2
would have access to 3-5 so all bets are off. Its more about having
to worry about downloads or link clicks etc.

The Netgear FVS318 appears not to be able to do this for me. But I
could be wrong there. I see no options that look usefull for it.
Blocking of sites might do it but appears it would be a long process
settting itup. Not sure if one can give a net range and have that be
all that is accessable.

I' happily hear that the router can do this.

However:
I'm thinking there is software available that can be deployed on a per
machine basis that can do this.

My reasons are:

3-5 are heavy hitters for graphics work. Any amount of spyware,
adware, virus sw, firewall etc that can be kept off these three will
greatly help.

All the big players in graphics work are heavy resource hogs and don't
want to be competing with spysweeper, counterspy, pc-cillun, kerio
etc, etc etc.

I might have Photoshop, silverfastAI, Imatch and ACDsee all running
while working. These are all 3.2GB machines but still....

I realize this is not really an especially secure way of operating but
I'm really sick of having problems while graphic editing. Never
knowing for sure if its other stuff interfering or what.

I don't really want to spend any more time than really necessary on
network stuff, since I'm in a heavy learning phase on the graphics

If they don't need access to the other machines or the other machines to
them then use a static IP configuration with a different subnet. If they
need access to other machines on the network then you need a router of some
sort to hook them up to. There are other tricks like editing the host file,
misconfiguring the DNS on those machines etc.

Kerry
 
Harry Putnam said:
I don't see any other general network winxp group so hopefully this
goes here.

First a quick summary of my current setup:



INTERNET
|
DSLMODEM
|
------------- NETGEAR FVS318 fw/router---------------
| | | | |

Mch1 Mch2 mch3 mch4 mch5
Lin win win win win


I want to isolate mch3-5 to only the local network.

That is, only mch 1 a linux machine and mch2 a winxp pro machine,
should be able to freely access the internet. 3-5 should only be able
to talk to/from the local net.

I realize this would not be true isolation as anyone getting to 1-2
would have access to 3-5 so all bets are off. Its more about having
to worry about downloads or link clicks etc.

The Netgear FVS318 appears not to be able to do this for me. But I
could be wrong there. I see no options that look usefull for it.
Blocking of sites might do it but appears it would be a long process
settting itup. Not sure if one can give a net range and have that be
all that is accessable.

I' happily hear that the router can do this.

However:
I'm thinking there is software available that can be deployed on a per
machine basis that can do this.

My reasons are:

3-5 are heavy hitters for graphics work. Any amount of spyware,
adware, virus sw, firewall etc that can be kept off these three will
greatly help.

All the big players in graphics work are heavy resource hogs and don't
want to be competing with spysweeper, counterspy, pc-cillun, kerio
etc, etc etc.

I might have Photoshop, silverfastAI, Imatch and ACDsee all running
while working. These are all 3.2GB machines but still....

I realize this is not really an especially secure way of operating but
I'm really sick of having problems while graphic editing. Never
knowing for sure if its other stuff interfering or what.

I don't really want to spend any more time than really necessary on
network stuff, since I'm in a heavy learning phase on the graphics
stuff.

Assign a static IP address and subnet mask, but no default gateway or
DNS server address, to 3-5. If you think that people will try to
change those settings, give those people limited user accounts.
--
Best Wishes,
Steve Winograd, MS-MVP (Windows Networking)

Please post any reply as a follow-up message in the news group
for everyone to see. I'm sorry, but I don't answer questions
addressed directly to me in E-mail or news groups.

Microsoft Most Valuable Professional Program
http://mvp.support.microsoft.com
 
Back
Top