Home file server - keep off internet, lan only?

hippovsmouse

Member
Aug 2, 2014
43
0
16
If I have a small basic windows-based home file server or nas, how could I keep it off the internet, while allowing it lan access only? I see no reason to have that machine on the internet.

Thanks
 

hippovsmouse

Member
Aug 2, 2014
43
0
16
It's connected to my router so I can remote into it/share the drive on my small network etc
Just see no need to have it on the internet
 

hippovsmouse

Member
Aug 2, 2014
43
0
16
ok here's what I did:

on the "server" I opened my firewall and blocked outbound tcp, blocked udp- except I made a rule to allow udp on port 3389 (remote desktop port)
blocked icmp & icmpv6

went into properties for ip and changed the default gateway to something on a different subnet (machine can't get an ip from my router now)

remote desktop and shared network drive both seem to work fine.

do I need to set any rules in my router?

Did I do it right? Advice appreciated
 

Ketchup

Elite Member
Sep 1, 2002
14,546
238
106
All I did was:

Static IP address on the server.
Standard subnet.
No default Gateway.

Works fine for me, and available anywhere on the local network through remote desktop, shared folders, and other apps needed for tablets, etc. You will want to reserve the ip address on your router, so that it doesn't waste time trying to dish out the ip address to another device.
 
Feb 25, 2011
16,822
1,493
126
I see no reason to have that machine on the internet.

Downloading software patches.

By all means, firewall it so that nobody from the outside world can get TO it, but it should probably still have the ability to get out onto the internet itself.
 

Ketchup

Elite Member
Sep 1, 2002
14,546
238
106

I don't miss it personally. And with my configuration, it take all of 5 seconds to re-configure and get Windows Updates. But since I am not on the Internet, I don't need most of them. I usually let it update once a year just in case there might be a usability update in the mix.

As far as other programs, I just get them off one of the others and put them in a shared folder if the server needs to run them.
 

frowertr

Golden Member
Apr 17, 2010
1,371
41
91
And that's fine if that works for you. Nothing wrong with doing it that way. Myself, I'd forget in about a month or two's time what I did to "lock down" the computer from the Internet. Would make for a frustrating 15 minutes or so trying to remember the steps I need to undo.
 

hippovsmouse

Member
Aug 2, 2014
43
0
16
Why does it need internet access for windows updates? It's just a file server, I assume keeping that machine off the net helps to secure it.


The only thing is (I hadn't thought about this before) if I wanted to set up an ftp server or something, to share some files to myself when i'm not at home - I couldn't do it from the server directly, I would have to use a 2nd old computer I have, access the files I want to share to myself from that 2nd computer via the network, then set up the ftp on that 2nd computer.

So disallowing internet on the server may secure it more, but necessitates another computer if I want to share some of those files to myself over the internet.

This is just an (interesting) learning exercise for me, so I'm enjoying the learning rather than finding it frustrating
 

frowertr

Golden Member
Apr 17, 2010
1,371
41
91
Why does it need Internet access for Windows Updates? Well unless you are running a WSUS server, it needs access for those updates. Of course, you don't have to ever update the OS. That's up to you.

I find it too restrictive for myself but if it works for you then rock on.
 
Last edited:

Ketchup

Elite Member
Sep 1, 2002
14,546
238
106
Sure, having it on local only is a sacrifice, so it is up to you how far you want to go with it.

There is free online storage all over the place (onedrive, for example), so you could always use something like that for data you want to share, if you don't want to necessarily open an access point to your server.
 

hippovsmouse

Member
Aug 2, 2014
43
0
16
Sure, having it on local only is a sacrifice, so it is up to you how far you want to go with it.

There is free online storage all over the place (onedrive, for example), so you could always use something like that for data you want to share, if you don't want to necessarily open an access point to your server.

I'd just as soon not use a cloud service.
Maybe better to keep the file server offline, and use an old laptop or computer to be the ftp server? I have an old laptop I can use - I set up the ftp and browsed via network to the files on the server that I want to share to myself on the ftp, it seems to work fine.

It's either that, or run the ftp on the server directly
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |