Re: Blocking Internal machines from Access to the Internet



On 2006-07-31, Ken Roberts <forums@xxxxxxxxxxxxx> wrote:

Kevin T. Neely wrote:
On 2006-07-30, Kevin T. Neely <ktneely@xxxxxxxxxxxxxxxxxxx> wrote:
I am trying to block a host on my internal network from reaching the
WAN and therefore the internet. I am using shorewall to configure my
iptables firewall but am having trouble crafting a proper rule.

It's been a while since I played with Linux-based firewalls, so forgive
me for not providing real examples. My only recent firewall experience
is on Cisco gear.

My approach would be to deny access by default, and then add it
specifically for those machines that need it. However, with this

Thank you for the help and advice. This is definitely not an office
setup. Basically, my "miscreants" are the children who like to find
sneaky ways to stay up as late as possible using the internet on their
newly-installed computers in their rooms. I have setup DHCP
reservations for their computers and they are currently not skilled
enough to get around that meager security measure. I don't really
mind if they figure out how to get around what I setup, since doing so
would really teach them a lot about computers and networking that I
cannot otherwise get them to learn, so major security is not a big
deal.

What I want, however, is for the connection to drop right as I change
the rule. As it stands, even with the REJECT and DROP rules, open
connections (like an AIM client) remain open until they reboot their
computer or stop/restart the client, which is not what I want.

I'm running a Linux firewall because I want one device that I can use
as firewall, ssh server, mail server, etc. and not run a medium-sized
office's worth of equipment in getting the services I want. I also
want to be able to log certain traffic to hard disk, for which I need
an always-on computer.

I do have an older, managed BayNetworks switch I suppose I could use
and set the port by which my logging server is connected to mirror the
router port. But that is a lot more noise/heat for my little office
closet I'm not sure I want to incur.


Better yet, if you can figure a way to have two separate networks you
could enable/disable access for the whole network, which will prevent
your miscreant from just changing the IP address to get access.

I have it like this:

Inet
|
cable modem
|
router
|
switch - {wired desktop computers}
|
Wireless AP


And it's like that. However, I have a third interface in the router
and am contemplating setting the wireless to a different subet than
the wired lan so that I can protect the internal network a bit more.
Once I do this, I /could/ disable the wireless at night (their
computers are connected via wireless), but then my laptop,
etc. wouldn't work, and I go to bed later than they.

K

--
In Vino Veritas
http://astroturfgarden.com
.



Relevant Pages

  • RE: Wireless access
    ... Well, How about setting your wireless in a complete DMZ off the Firewall, ... and only HTTP traffic can flow out to the internet and nothing else. ... to facilitate one-on-one interaction with one of our expert instructors. ...
    (Security-Basics)
  • Re: workgroup/file sharing
    ... I have 2 win xp computers with SP3 installed, ... and netgear wireless router; NIS on both PCs; one PC is ... by 1) a misconfigured firewall or overlooked firewall (including a stateful ... Install them on the target machine. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Perhaps the most OBVIOUS question you will ever see.
    ... I am not saying it is a good idea to run an open wireless access ... Internet firewall in place, I would worry more about the threat from ... Packets to and from machines on the wired network are not ...
    (microsoft.public.security)
  • Re: Is it practicable to share an internet connection w/o setting up a network?
    ... was the only one who wanted the broadband cable internet so I've been ... way of doing that without linking our computers together. ... You can set up a wireless router in Client Isolation mode. ... Also, like a previous poster mentioned, if you use a firewall to block ...
    (alt.internet.wireless)
  • Re: Sharing a wireless connection with other computers
    ... I have 3 computers, one has a wireless internet card, the ... What I am trying to do is share the internet connection ...
    (microsoft.public.windowsxp.network_web)