Re: sandbox for Window$



Russell L. Harris <rlharris@xxxxxxxxxxxxxxx> wrote:
I wish files on a machine running Window$ to be accessible to other
computers in the LAN, while preventing the Window$ machine from
accessing the Internet for http, ftp, email, etc. And, the Window$
machine must not be able to see or communicate with other machines in
the LAN, except for file transfers initiated by the other machines.

If you were to run MS Windows in a VM or behind a Linux-based server you
could use iptables to do this. You would probably benefit from something
to help you set up the rules in the FORWARD chain. For example -

FORWARD: From MS Windows to LAN
Allow established
DENY all

FORWARD: From MS Windows to Anywhere
DENY all

FORWARD: From LAN to MS Windows
Allow all

FORWARD: From Anywhere to MS Windows
DENY all

My preferred subsystem layer is shorewall. Others will prefer different
subsystems, including GUI-based helpers. Still others will prefer writing
iptables rules directly.

Chris


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx
Archive: http://lists.debian.org/f37tq7x4b8.ln2@xxxxxxxxxxxxxxxxx



Relevant Pages

  • Re: warum PnP Dienst =?ISO-8859-15?Q?=FCber?= Netzwerk?
    ... >> Ich habe noch keinen Dienstleister gefunden, der ein sicheres LAN durch ... >> Windows Terminal-Server, z.B. in ein eigenes Netz und ein OpenVPN Server ... > Windows Remote Desktop Protocol Denial of Service Vulnerability ...
    (microsoft.public.de.german.win2000.networking)
  • Re: Alternatives to using a Personal Firewall
    ... In the past I've tried disabling ... Windows Media Player, Windows Genuine Advantage Notification (every time ... When malware is already run, ... If running TCP/IP on Your LAN, ...
    (comp.security.firewalls)
  • Re: http://LongPathTool.com - find and delete/copy path too long files from your hard drive or L
    ... Windows tool to copy or delete files and folders with path too long or ... Normally one can't access such files under Windows and therefore can't ... files from your hard drive or LAN ...
    (microsoft.public.vc.mfc)
  • Re: Cryptographic and Userenv problems after power failure
    ... Outlook runs fine from the LAN computers, ... I continued and numerous identical windows kept popping up. ... After that issue was taken care of, I had no internet connectivity. ...
    (microsoft.public.windows.server.sbs)
  • Re: Debian + Magic Jack
    ... (stable, testing or sid)? ... I have just 1 box with Windows XP in my lan for this matter, ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)