25-11-2009, 18:27
|
#1
|
Inactive
Join Date: Apr 2009
Location: Westhouses, Alfreton, Derbyshire
Services: BWI (Bennylaball Wireless Internet), Freesat Humax thingy
Posts: 22
|
Client Isolation
Hi all, i have had a request from one of my customers to stop his clients from being able to see each other on the network and only allowing internet traffic, I suggested a layer 2 switch and forward all the network ports to the gigabit port on the switch and feed that to the router, but i found out he has a large wireless network and cabled network. I am thinking about setting him up a PPPOE server and attaching it to the Active Directory, does anyone else have any ideas as that will be alot of messing about setting up PPPOE on all there machines!
|
|
|
25-11-2009, 19:05
|
#2
|
Inactive
Join Date: Dec 2007
Posts: 18,385
|
Re: Client Isolation
Just block all local IP's on locked down firewalls apart from the gateway/router, with it being active directory I presume you can set a global security policy blocking firewall modifications
|
|
|
25-11-2009, 19:21
|
#3
|
cf.mega poster
Join Date: Jun 2003
Location: Mansfield, Notts
Age: 45
Services: Virgin Media Telephone and 100Mb broadband, Sky Q
Posts: 1,994
|
Re: Client Isolation
Quote:
Originally Posted by Kymmy
Just block all local IP's on locked down firewalls apart from the gateway/router, with it being active directory I presume you can set a global security policy blocking firewall modifications
|
Windows firewall and group policy
BTW, my post has totally changed, got hold of the wrong end of the stick first reply.
BTW2, Every switch is at least Layer 2(MAC level), did you mean Layer 3?
|
|
|
25-11-2009, 19:30
|
#4
|
Inactive
Join Date: Apr 2009
Location: Westhouses, Alfreton, Derbyshire
Services: BWI (Bennylaball Wireless Internet), Freesat Humax thingy
Posts: 22
|
Re: Client Isolation
Yes i did mean layer 3 my mistake, the client doesnt use active directory for routing, i use a cisco PIX, i was hoping i could put a linux box in line with the router as im not a windows guy.
|
|
|
25-11-2009, 19:34
|
#5
|
cf.mega poster
Join Date: Jun 2003
Location: Mansfield, Notts
Age: 45
Services: Virgin Media Telephone and 100Mb broadband, Sky Q
Posts: 1,994
|
Re: Client Isolation
Quote:
Originally Posted by Bennylaball
Yes i did mean layer 3 my mistake, the client doesnt use active directory for routing, i use a cisco PIX, i was hoping i could put a linux box in line with the router as im not a windows guy.
|
You wouldn't use active directory for routing, you'd set the default domain policy to enable the firewalls on the client PC's. You'd then put out a policy via AD that set each firewall to block communication to anything that isn't a server or internet connection.
|
|
|
25-11-2009, 21:16
|
#6
|
Inactive
Join Date: Apr 2009
Location: Westhouses, Alfreton, Derbyshire
Services: BWI (Bennylaball Wireless Internet), Freesat Humax thingy
Posts: 22
|
Re: Client Isolation
Ooooo I see i will have to read a bit into active directory like i said im not a windows guy, if i get asked this again for a network with no active directory how would i go about doing this?
[MOD: removed repeated sections]
Argh, every time i refresh it re-posts my last post
|
|
|
26-11-2009, 17:18
|
#7
|
Inactive
Join Date: Dec 2007
Posts: 18,385
|
Re: Client Isolation
Quote:
Originally Posted by Bennylaball
Argh, every time i refresh it re-posts my last post
|
If you refresh directly after a post then it'll resubmit the post data, best to click on the thread link instead of refresh
Extra data and also the reply quoting the data - deleted
|
|
|
27-11-2009, 12:02
|
#8
|
Inactive
Join Date: Oct 2009
Location: In a box
Services: Lots
Posts: 211
|
Re: Client Isolation
 you delete my post - I though it was quite funny, granted not related to the thread in any way, but still funny
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 21:06.
|