Recommended Posts

I have a total of three PCs going through a router and I often use them to share files etc, but due to a recent virus attack I would like to isolate one of the PCs from the network so that it can't spread viruses etc through the network.

I'm guessing that once isolated it should still be able to use the printer (which is also plugged into the router) and continue to access the internet as well.

Any help would be much appreciated.

thanks for the reply.

what i meant was that it no longer has the ability to send/receive information to the other computers as it did when I had the recent virus problem. I've tried to change the workgroup but it still seems to be able to see/view/change the other computers information.

hope this clears what i mean!

  popisdead uk said:
Take it out of the same domain/workgroup. That will stop it sharing files
And where did you get that tidbit of misinformation from??

What workgroup your in has NOTHING to do with file sharing, and to be honest either does the domain really -- as long as you auth to the machine with a valid account you can access resources. A domain just makes it easier to give permissions since there is a central userbase.

And this clearly does not isolate the machine from possible viruses or exploits to the ports they are listening on, ie the file sharing ports, etc. Not having a valid account to auth with will not always protect you from a virus/exploit - but it will protect you from that machines virus from infecting every file it has permission too, depending on what account its logged in as, etc.

So blocking the account the other machine logs in with from having file share access would provide some minor protection. But if using SFS, thats not possible -- would need to have pro with the ability to give different accounts different access to files/shares, etc. But that would not protect you from an exploit using the file sharing ports, etc.

If you router does not allow you to setup vlans and put access control lists between them. Then your going to need to run software filewalls on the machines or put them behind a nat compared to the other machine. You would then need to do a port forward to allow printer access. Quite often this is port 9100, it would depend exactly how your sharing your printer - be it connected to a machine or on a stand alone printer server device, or if the printer has its own network card, etc.

Treating a machine(s) as hostile on the same local network is what software firewalls are good for! If you run software firewalls on your machines -- just use them to block access from that one machine.

One way as mentioned to put a line of protection between that machine and your other machines is to put the other machines behind another nat router.

example layout;

post-14624-1218542661_thumb.png

But I would REALLY NOT suggest this -- since the double nat comes with quite a few of its own headaches. Your best bet is to get a router that supports lan to lan firewall rules. There are few out there -- but not recalling any model numbers off the top of my head.. Would have to look around for one that does -- but they are out there for sure. What router do you have now?

Believe me -- I would love to get off the soapbox about FUD -- but it seems no matter how many times you state FACT and discredit FUD, it still manages to stay around. And the misconceptions about what a workgroup is and does just never seems to go way -- Arrrghhh ;)

I would love to know what you thought the question was asking -- that suggesting a different workgroup or domain would isolate it.

  technics said:
I have a total of three PCs going through a router and I often use them to share files etc, but due to a recent virus attack I would like to isolate one of the PCs from the network so that it can't spread viruses etc through the network.

I'm guessing that once isolated it should still be able to use the printer (which is also plugged into the router) and continue to access the internet as well.

Any help would be much appreciated.

So you want to stop computer (1) from giving it's virus to computers (2) and (3) on the network, but still want it to spread the virus to the internet?

You do know they make good FREE anti-virus software don't you? Right here on Neowin.

  BudMan said:
Believe me -- I would love to get off the soapbox about FUD -- but it seems no matter how many times you state FACT and discredit FUD, it still manages to stay around. And the misconceptions about what a workgroup is and does just never seems to go way -- Arrrghhh ;)

I would love to know what you thought the question was asking -- that suggesting a different workgroup or domain would isolate it.

I honestly don't know mate. It was early this morning when I read it. I think I thought he meant, .... I have no idea. Really.

If I had read it properly I would have seen what he was trying to do, and I would have ignored it.

Follow up: Router that supports lan to lan firewall rules, yes I know this model is EOL, but its an example of what I was talking about with lan to lan rules on a home priced router.

post-14624-1218551467.jpg

Also if your router will run dd-wrt or openwrt you can setup vlans and use iptables to deny specific traffic between the vlans, etc. Not sure if tomato can do this?

So you can accomplish what you want fairly simple with home priced network equipment to be sure. I do not believe the current web ui to dd-wrt supports lan to lan firewall rules? But can be done from the command line after a bit of reading for sure. Or I do believe you can run firewall builder on it. http://www.dd-wrt.com/wiki/index.php/Firewall_Builder which would give you a gui in building your rules.

Another option would be to run a linux distro as your router, ipcop I know allows for multiple segments and then rules between them. Any of the router distro's should be able to do something as basic as this.

What I would suggest is if your current router does not support either dd-wrt or lan to lan rules is since you would need to buy another router to use the double nat method anyway -- is purchase one that allows for lan to lan filtering, or one that supports 3rd party firmware that will allow you to do it.

thanks for that.. (just going out atm and will read your post when i return)

i just had a quick idea, which is probably very silly but thought i might ask anyway. would disabling/removing file and printer sharing for Microsoft networks in the local area connection properties help solve the problem i'm having?

thanks for that.. (just going out atm and will read your post when i return)

i just had a quick idea, which is probably very silly but thought i might ask anyway. would disabling/removing file and printer sharing for Microsoft networks in the local area connection properties help solve the problem i'm having?

On which machine? On the machine your worried about, or the other machines. If turn off file and print sharing on the machine your saying is hostile -- that does not prevent some type of infection from doing anything -- just that it would not be able to use the built in file and print sharing to do it.

But without know exactly which infection your looking to protect against.. You would need to understand its method of spreading to know if that could stop it.

Now doing it on the 3 other machines would prevent them from listing, and or anything from accessing file shares, etc.. EVEN yourself for you legit use, etc.. Its a pretty harsh fix -- and this does not mean that they would still be safe from any type of infection the other machine might pick up that uses say a rpc exploit, to compromise the other machines.

You need to isolate the friendly machines from the hostile machine. This can be done with firewalls on each of the friendly machines, or with firewall between them (the lan to lan rules example) or by putting the friendly machines behind a nat to the network the hostile machine is on, etc. etc.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Download The Inclusion Equation: Leveraging Data & AI (worth $21) for free by Steven Parker Claim your complimentary eBook worth $21 for free, before the offer ends on June 24. The Inclusion Equation is a comprehensive, one-of-a-kind guide to merging DEI and employee wellbeing concepts with data analytics and AI. In this book, renowned thought leader and professional keynote speaker Dr. Serena Huang explains exactly how to quantify the effectiveness of new talent strategies by connecting them to a firm ROI estimate, enabling readers to approach and win the favor of higher-ups in any organization with the same effectiveness that marketing and financial departments do. This book is written in a style that is appealing and accessible to all readers regardless of technical background, but with enough depth to provide real insight and strategies. Dr. Serena H. Huang distills her 10 years of Fortune 500 people analytics leadership experience into tools and framework you can leverage to measure and improve DEI and wellbeing in your workplace. Some of the topics explored in this book include: Attract and retain top talent, including Gen Z and Millennials, with tailored DEI and wellbeing strategies Quantifying not only a talent strategy's perceived initial effect on an organization, but also its improvement and expansion over time Turning DEI and wellbeing from illusive corporate concepts to quantifiable metrics Harness the power of AI to create synchronized DEI and wellbeing strategies that maximize ROI Getting serious attention from your CEO and CFO by quantifying HR initiatives Using data storytelling to demonstrate the business impact of DEI and wellbeing Preparing for the future by understanding the role of AI in creating an inclusive and healthy workplace The Inclusion Equation is a complete guide for DEI and wellbeing, covering getting started in measurement to using storytelling to influence leadership. This is the contemporary playbook for any organization intending to substantially improve their diversity, equity, inclusion, and employee wellbeing by leveraging data & AI. This book is also perfect for any data analytics professionals who want to understand how to apply analytics to issues that keep their CEOs up at night. Whether you are a data expert or data novice, as long as you are serious about improving DEI and wellbeing, this book is for you. This free to download offer expires June 24. How to get it Please ensure you read the terms and conditions to claim this offer. Complete and verifiable information is required in order to receive this free offer. If you have previously made use of these free offers, you will not need to re-register. While supplies last! Download The Inclusion Equation: Leveraging Data & AI (worth $21) for free Offered by Wiley, view other free resources The below offers are also available for free in exchange for your (work) email: AI and Innovation ($21 Value) FREE – Expires 6/11 Unruly: Fighting Back when Politics, AI, and Law Upend [...] ($18 Value) FREE - Expires 6/17 SQL Essentials For Dummies ($10 Value) FREE – Expires 6/17 Continuous Testing, Quality, Security, and Feedback ($27.99 Value) FREE – Expires 6/18 VideoProc Converter AI v7.5 for FREE (worth $78.90) – Expires 6/18 Macxvideo AI ($39.95 Value) Free for a Limited Time – Expires 6/22 Excel Quick and Easy ($12 Value) FREE – Expires 6/24 The Inclusion Equation: Leveraging Data & AI ($21 Value) FREE – Expires 6/24 Microsoft 365 Copilot At Work ($60 Value) FREE – Expires 6/25 Natural Language Processing with Python ($39.99 Value) FREE – Expires 6/25 How to Engage Buyers and Drive Growth in the Age of AI ($22.95 Value) FREE – Expires 7/1 Using Artificial Intelligence to Save the World ($30.00 Value) FREE – Expires 7/1 Essential: How Distributed Teams, Generative AI, [...] ($18.00 Value) FREE – Expires 7/2 The Chief AI Officer's Handbook: Master AI leadership with strategies to innovate, overcome challenges, and drive business growth ($9.99 Value) FREE for a Limited Time – Expires 7/2 The Ultimate Linux Newbie Guide – Featured Free content Python Notes for Professionals – Featured Free content Learn Linux in 5 Days – Featured Free content Quick Reference Guide for Cybersecurity – Featured Free content We post these because we earn commission on each lead so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. Other ways to support Neowin The above deal not doing it for you, but still want to help? Check out the links below. Check out our partner software in the Neowin Store Buy a T-shirt at Neowin's Threadsquad Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: An account at Neowin Deals is required to participate in any deals powered by our affiliate, StackCommerce. For a full description of StackCommerce's privacy guidelines, go here. Neowin benefits from shared revenue of each sale made through the branded deals site.
    • It's basically been a rite of passage to blow up your first WSUS server by trying to sync the drivers database. Anyone who has done this has certainly seen the tens of thousands of driver packages and asked "what is all of this literal garbage?". Seems Microsoft is asking the same question. I do hope they won't take it too far and start removing drivers needed to run legacy systems, but there's definitely a happy medium to be found between "only the latest versions for actively supported hardware" and "every version of every driver ever for all time".
    • Stable..... No, he isn't..
    • Of course the sales are bad. Who even asked for a thinner phone with way less battery? Lightness? It's still a giant brick, it's just a thinner giant brick. It makes no sense at all. Making folding phones thinner, now that does make sense. Because when folded, the thinner it is unfolded, the more usable and pocketable it is when folded. You already expect worse battery at expense of actually being more pocketable. Galaxy Flip, when folded is half the size of S Ultra models and about as thick. That does make a big difference when fitting it in a pocket. But the phone that's as big as Ultra, making it thinner, you don't really solve anything, it's still a giant slab that barely fits into a pocket. All the "Mini" phones made way more sense than this thin crap. Especially now that it's literally impossible to find a phone smaller than 6.5". My dad only needs phone for calls and SMS and he doesn't want to go with smartphone because they are all so massive. Especially cheaper ones. Like, he'd be fine with Galaxy A06 for all he cares in terms of hardware, but it only comes in giant 6.7" format. It's useless. Or is he suppose to find a 800€ old gen iPhone Mini or Zenfone? He doesn't even need those stupid specs and such stupid price. And then you see old people fumbling around with giant smartphones and they don't even need 3/4 of features on them.
  • Recent Achievements

    • First Post
      emptyother earned a badge
      First Post
    • Week One Done
      Crunchy6 earned a badge
      Week One Done
    • One Month Later
      KynanSEIT earned a badge
      One Month Later
    • One Month Later
      gowtham07 earned a badge
      One Month Later
    • Collaborator
      lethalman went up a rank
      Collaborator
  • Popular Contributors

    1. 1
      +primortal
      664
    2. 2
      ATLien_0
      270
    3. 3
      Michael Scrip
      218
    4. 4
      Steven P.
      161
    5. 5
      +FloatingFatMan
      157
  • Tell a friend

    Love Neowin? Tell a friend!