Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 11-29-2005, 05:05 AM   #1
Banned
 
Join Date: Jan 2001
Location: Toronto
Posts: 298
Network architecture and viruses

hi ho,
On occasion I fix peoples machines and have found that some of these machines have infected other machines on my network.Is there any way to keep my machines on my network with internet access but physically segregate new machines in case they have a network aware virus.I was thinking cable modem to switch then setup each machine with its own router?
Dont think dual or triple homed machines with dmz would help because the threat is internal...
DoGG is offline   Reply With Quote
Old 11-29-2005, 08:37 AM   #2
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,776
Before connecting the customer's machine to your router, bring it up standalone, disable NetBIOS over TCP/IP, disable Client for MS Networks, disable all protocols except TCP/IP, and disable filesharing. This will still allow you to get the machine on the Internet.
glc is offline   Reply With Quote
Old 11-29-2005, 12:53 PM   #3
Banned
 
Join Date: Jan 2001
Location: Toronto
Posts: 298
K

K...if I do these 4 things there is no way i can get a network virus from an infected machine?
DoGG is offline   Reply With Quote
Old 11-29-2005, 10:17 PM   #4
I am, in reality, a moose
Staff
Premium Member
 
mbossman2's Avatar
 
Join Date: Aug 1999
Location: RTP, NC
Posts: 2,441
depending upon your size and budget there are some powerful applications to do exactly this but they ain't cheap:

http://www.cisco.com/en/US/products/ps6128/index.html
__________________
Veritas Principium Libertas

Traveling Moose
mbossman2 is offline   Reply With Quote
Old 11-30-2005, 08:55 AM   #5
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,776
Forgot 1 thing - make sure the customer's machine is not using the same workgroup name as yours. Make sure all your machines are using active virus protection, software firewalls would be another layer of protection. I would not say "never" but all this sure sounds pretty safe to me.
glc is offline   Reply With Quote
Old 11-30-2005, 02:43 PM   #6
Banned
 
Join Date: Jan 2001
Location: Toronto
Posts: 298
ok

Ok thanks you 2 for the info.Was it you GLC that owns your own shop or was it HAL2000 maybe.If it was youis this the procedure that you use in the shop?
DoGG is offline   Reply With Quote
Old 12-01-2005, 04:29 AM   #7
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,776
I don't go to that extreme for a few reasons. My network has NetBIOS over TCP/IP disabled anyway, I fileshare with NetBEUI, and my workgroup name is quite unique. All my machines have Zone Alarm and AVG. Most of my work is done onsite, but when I do bring a machine in, I look it over standalone before plugging in the network cable, if it's got critters I clean them up with command line McAfee which I keep updated on my USB key.
glc is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 01:13 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2