SearchSearch   ProfileProfile   Log inLog in   RegisterRegister 

Network Security

 
Post new topic   Reply to topic    FirstSpot Forum Index -> Pre-sales Support Forum
View previous topic :: View next topic  
Author Message
sanjeet



Joined: 23 Nov 2003
Posts: 4
Location: Queenstown, New Zealand

PostPosted: Sun Nov 23, 2003 11:36 pm    
Post subject: Network Security

We have a firspot server sitting on our LAN network. The public network interface is connected to our LAN (which is a switch that connects all our existing computers together and has an ADSL connection) The private network interface is connected to a wireless access point.

When a guest connects wirelessly to Firstspot, I noticed that they can browse the network. They are able to view the contents of other guest's computers connected to Firstspot and also our computers that are on our office LAN including our file server.

How do we secure our office LAN network from guests that are connected to Firstspot?
The only thing guest should have access to is the internet connection and not be able to browse the network.

Please advice.
Back to top
kevin
Forum facilitator


Joined: 26 Sep 2003
Posts: 442

PostPosted: Tue Nov 25, 2003 5:51 am    
Post subject:

We've tested out the scenario you described and were able to reproduce the problem. That should be a bug and we'll get it fixed.

As most of our customers connect the public nic directly to the Internet, this scenario is much less experienced and concerned. Thanks very much for pointing out the issue to us.

~ Patronsoft Limited ~
Back to top
burg538



Joined: 24 Oct 2003
Posts: 5
Location: netherlands

PostPosted: Tue Nov 25, 2003 6:30 pm    
Post subject: network

We have had the same problem but could enter the option "Disable client to Client communication" in our accesspoint, maybe your AP have the same option. It solved our problem.
Back to top
sanjeet



Joined: 23 Nov 2003
Posts: 4
Location: Queenstown, New Zealand

PostPosted: Tue Nov 25, 2003 9:29 pm    
Post subject: Temporary Solution for Network Security

Hi,
We have temporarily resolved this issue by installing Zone Alarm on the Firstspot Server. Through the Zone Alarm configuration :-

Private Interface Card:-
Block incoming NetBIOS (ports 135, 137-9,445)
Block outgoing Netbios NetBIOS (ports 135, 137-9,445)
Block incoming ping (ICMP Echo)
Block outgoing ping (ICMP Echo)

This will prevent the visitor based network from accessing the internal network. They won't be able to ping any computer on the internal network or browse it through network neighborhood or search by computer name.

But among the users on the visitor based network, each other still has access to one another.

Thanks.
Back to top
Display posts from previous:   
Post new topic   Reply to topic    FirstSpot Forum Index -> Pre-sales Support Forum All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group