How secure is this ?

Goosemaster

Lifer
Apr 10, 2001
48,775
3
81
Router1----Pc1
|
|
Router2
|
|
Pc2






ROUTER1:Linksys wrt54g WAN: DHCP / INTERNAL IP: 172.16.64.130

IP scheme:
-network 172.16.64.128
-subnet mask 255.255.255.128

Wired:
-NAT
-DHCP disabled; Only static addresses

Wireless:
-WPA-PSK TKIP or AES (AES is slow as hell though so I stuck with TKIP) resets @ 3600ms
-802.11g only


ROUTER 2:Webramp modified with Sonicwall firmware INTERNAL IP: 172.16.64.194

IP scheme:
-network 172.16.64.192
-subnet mask 255.255.255.192

Wired:
-NAT
NAT One to one
External IP: 172.16.64.133
Mask: 255.255.255.128
Internal IP: 172.16.64.196
Mask: 255.255.255.192

-DHCP disabled; Only static addresses
-Gateway set to 172.16.64.130

Hardware Firewall:
-Every port blocked but 80, netbios and smtp
-Stealth
-Netbios out WAN

PC1 is a multimedia PC that gets a lot of spyware, adware, and viruses due to inexperienced users.
PC2 is a business computer that must remain isolated from the entire network except via netbios.



Is this setup secure? (besides the fact that I am spilling the beans )
What can be done to increase security?

P.S. I am remembering this from memory so if something doesn;t make sense, please bring it up. The network was up and running, so it was setup correctly.....my memory however, isn't as slick
 

Goosemaster

Lifer
Apr 10, 2001
48,775
3
81
Originally posted by: BML
What are you securing against? attackers? spyware? virus?

Anything shy of the devil himself. It is the company's accounting respository. They said they wanted to network both PCs but wanted high security.
 

VirtualLarry

No Lifer
Aug 25, 2001
56,540
10,167
126
I kind of glossed over the tech details like IPs and stuff, but ... let me get this straight, you want to network two PCs, one insecure, but one that should be secure, but you want to expose the secure PC's netbios ports to the insecure one? IMHO, "you're crazy".

You should either set up an additonal PC for insecure internet access, and set up a seperate secure LAN, with both the client and server business PC, or leave the secure accounting PC standalone, and set up an additional insecure PC for someone else to use to access the internet.

It's not so much of a technical issue, but a site security-policy one. Exposing a PC that is supposed to be kept secure, over a network, to a PC that is knowingly going to be running unknown, untrusted, insecure code (trojans/spyware/viruses/etc), is a foolish security policy decision. Best to have three PCs in this situation, and totally segregate secure and insecure machines onto seperate LANs. Remember, security is only as good as the weakest link in the chain, and allowing an insecure machine to communicate directly with a "secure" machine, is cutting a big hole right though your perimiter security defenses.

Edit: Err, first paragraph said for effect, didn't actually mean that personally, of course. Please don't take it that way. It's hard to connotate inflection on these boards.
 

MtnMan

Diamond Member
Jul 27, 2004
8,914
8,099
136
Lot of detail about what you want to stop, but what are you trying to share between PC1 and PC2?

What shares and services do you have setup?
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |