Offistart - Virtual Offices, Office Space, Business Support Services
*Home>>>Shared Offices

Restrict internet on LAN?


We have 40 - 50 users in our office on a simple TCP/IP lan. All PC's are connected to ethernet switch over a workgroup. Each PC has a fixed IP address. We also have a dsl modem (shared by all users) which given them access to the internet. We would like to provide all users with access to email; however, we would like to restrict most of the users (barring a few) from internet access. I am aware of blocking port 80 on a router to (selectively) restrict the http from some ofthe IP addresses. My questions is whether I need to replace all switches with the large multi-port router (so that all PC's are individually connected to the router) or whether by merely replacing the dsl modem with a dsl router, I can achieve the same result.

My current connection is as follows:
dsl modem -> server -> switch -> all lan users
where "->" = connected to

you don't need to replace all switches with the large multi-port router. only one router is enough because to increase the RJ45 ports of the router u can attach one or more switches with one router. so overall all switches that would be attached with router will become a part of router ports. so in ur case just get a router like 4 port or 8 port or else then put new router just after ur server; in ur already running infrastructure with ur switches. n then use the firewall of that router for restrictions to all or specific users. or even u can replace the server with the router. coz routers are DHCP servers for internet sharing. and i think your server is just working as a DHCP server for internet sharing. new routers also have a printer sharing port. do u know that?.

You can run an email server that has access to the world (the internet). Restrict access to the world to everyone except the few people you want to give access. (A virtual LAN setup would make it easy.)

No, switches forward the MAC address of the computers properly to the router, so you don't need a multiport router.

The answer to the question you are asking is known as a firewall filter. Most routers support port filtering by client IP, so use either static DHCP leases or disable the DHCP server and use manual IP addresses on the computers themselves and restrict access on the OS to prevent tampering with IP configuration.

A Static DHCP server is recommended because you can administer it from the router and not from each workstation.

If you don't have a good router, you don't really need a corporate one unless you want a DPI firewall. Custom Firmware enables a lot of features that are found on corporate firewalls such as QoS, Firewall Filters, Static DHCP lease etc, and static routing

Get this router for $70
http://www.newegg.com/Product/Product.as...

Then flash with tomato firmware
http://www.polarcloud.com/tomato
Setup is easy and straight forward

For fully customizable router, such as multiple WAN (convert a LAN port into a second or third WAN port) use OpenWRT firmware with X-wrt GUI. It also has a VPN server built into the router! Use with the WRT54GL

http://x-wrt.org/
http://downloads.x-wrt.org/xwrt/kamikaze...
Direct Link
http://downloads.x-wrt.org/xwrt/kamikaze...

OpenWRT is powerful and fully customizable, but QoS is not as good. Use Kamikaze 7.09 and not White Russian.

Get the Linksys WRT54GL (and not WRT54G/GS) as it supports Tomato, OpenWRT and DD-Wrt firmware (not recommended).

Tags
  Offices to Lease   Rent Offices   Business Centers   Service Offices   Branch Offices   Temporary Offices   Shared Offices   Commercial Space   Office Space   Business Services   Business Address   Call Forwarding
Related information
  • Is this laptop right for me?

    This computer is quite fast, and it has a ton of RAM. It will be fast for anything you want to do, and will stay that way for years to come. If you don't mind spending the extra cash, go fo...

  • Working Problems with Women Workers?

    Oh I bet they were all SOOOOO madly in love with you! lol.. kidding... They probably just wanted attention.. women are generally attention seekers.... they wanted you to hit on them .. they didn...

  • Why Women Act this way?

    Invited to coffee everyday for three years, she obviously enjoys your company, but she was married thats a situation I would personally not want to be involved in! Avoid the lure of married wome...

  • Gary Spatz BBB Ripoff?

    YES, we went through the exact same thing. We even had an appointment with the same guy. After reading this we did not bother to show up. I'm calling the BBB and the City Attorneys Office an...

  • How many siblings do you have?

    i have 3 siblings 2 sisters and one brother ..im the littlest :) my twin and i do fight all the time ...but we get along

    ...
  • VPN between 2 remote sites?

    do a site to site vpn with vpn capable routers. SOnic wall has a great easy to use product line. yu will need static ips or ddns at each site.

    ...
  • Would you report this to human resources?

    why don't the people who are complaining report it? It shouldn't fall on your shoulders just because of your position. THat being said, a group effort may be best--if a petittion is wri...

  • If Bill Clinton, Obama, and McCain were running, who would you vote for?

    Obama for change!!!

    ...
  •  

    Categories--Copyright/IP Policy--Contact Webmaster