Segregating NAS from internet?

VirtualLarry

No Lifer
Aug 25, 2001
56,447
10,117
126
What's the best way to do this? I want to have PCs on the LAN / WLAN that have internet access, and can access the NAS over the LAN, but I don't want the NAS to have internet access, nor internet access to the NAS?

Separate subnet for NAS, behind third router, and use static routes using reserved IP ranges, and delete the default gateway? (Not sure if you can delete the default gateway on a router?)

Or simply assign static IPs to the NAS in a separate subnet, and try to firewall those IPs off from the internet in the router's config?

Or would MAC address blocking be better? Wouldn't that block the NAS off from the WLAN or the LAN though?
 
Feb 25, 2011
16,822
1,493
126
Firewall rules. Doesn't have to be on a separate subnet. Just keep the NAS IP from going out into the world.
 

Ketchup

Elite Member
Sep 1, 2002
14,546
238
106
I gave my file server a static IP (also marked on the router as reserved), standard subnet mask, and no default gateway.

It is available on every device on my network and no Internet access, without having to mess with the firewall.
 

Emulex

Diamond Member
Jan 28, 2001
9,759
1
71
Make sure you use a non-routable subnet should your router default back to factory settings (thanks AC-RT66u!) you don't end up given away the farm!
 

avos

Member
Jan 21, 2013
74
0
0
Just remember if your WLAN and LAN are separate subnets and you don't set a gateway on the NAS it needs to have an interface on both subnets.

Though personally I would probably still go the firewall approach as no default gateway is also going to break VPN access to it. But that is mostly because I like to at least have the ability to remotely access my devices if needed. That and I'd like to have the option to segment my network if needed.
 

azazel1024

Senior member
Jan 6, 2014
901
2
76
There are umpteen different ways you can do this. What is the purpose?

If you want it for security sake, then don't go the empty gateway IP route. You could do it within the router (if your router supports it). I'd do it before the router with a semi-managed/managed switch and VLANs. Setup the VLAN rules so that the NAS doesn't have access to the router.

So the router is a member of VLAN 1, the NAS is a member of VLAN 2 and everything else attached to the network is a member of VLAN 1 and 2. Done. Router accidently gets reset or hacked, no worries, NAS can't even see that the router is there.
 

kevnich2

Platinum Member
Apr 10, 2004
2,465
8
76
The only way to be a member of two valan's is by using tags and making each port a trunk port or a general port. Consumer NIC's typically don't have this ability unless the OP installs two NIC's in every system so each NIC can be a part of both VLAN's

I am curious on why the OP wants to do this in the first place? What's the purpose you want to achieve?
 

azazel1024

Senior member
Jan 6, 2014
901
2
76
You can do that through the switch, you don't have to do VLAN tagging with the NIC. Or at least I can certainly do it though my TP-Link SG2216, Trendnet TEG160sw and DLink DGS-1100. I assume other switches can perform the same "magic".
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |