Koozali.org: home of the SME Server

Absolutely blocking a machine?

paranoid

Absolutely blocking a machine?
« on: December 12, 2002, 12:15:52 PM »
Hello,

there is one machine in our network which I'd like to absolutely
block from the internet. It should be able to access machines
on the LAN (shared drives only) (it would even be sufficient if
that machine had access to only the shares on the e-smith
server) but it must be absolutely impossible for it to access
the internet in any way.

To clearify a bit here's our structure:

...internet ...
     /\
      |
      .
      .
      .
      |
      |
     \/
[ADSL-Modem]
     /\
      |
      |
      | NIC1 of e-smith server
      |
[e-smith server]
      |
      | NIC2 of e-smith server
      |
      |
     \/
[ A simple HUB ]
 |     |     |     |
 |     |     |     |
 |     |     |     |
 |     |     |     |
\/    \/    \/    \/
A   B   C   D

Clients A, B and C are ok.
They run either some version of Windows or
some Linux (Debian or Mandrake).
These clients can access the internet unrestricted.
They also provide network shares (NetBIOS?)
themselves. Also they are able to access the Samba
shares on the e-smith server.

The e-smith server runs the folowing services:
 - provides internet access by using the ADSL line
 - provides e-mail (SMTP/IMAP)
 - provides space for files by having some ibays

The client I want to block is D which will run Windows
XP. It's much to 'talky' for my taste and even though it
is a legal, licensed copy I don't want any information
to be sent anywhere if I don't want it.

I'm quite paranoid that if I block the IP of client D it
will still be somehow possible for client D to use
one of clients A, B or C to access the internet.
(I don't mean a human - I really mean the OS).

How can I make it technically possible for D to get
access to the ibays but at the same time make it
technically impossible to get access to anything
else?

If it would help I could use a third NIC in the server
and physically connect client D to only this NIC.

I'm using V5.0 but plan to migrate to 5.5 soon.

Many, many thanks for your patience and please
excuse my english. If something isn't clear please
don't hesitate to ask.

best regards
paranoid

Johan

Re: Absolutely blocking a machine?
« Reply #1 on: December 12, 2002, 02:06:34 PM »
Hello Paranoid,

Gif this giy/machiene not the right Gateway in his network configuration off your network. Simpel gif him as gateway the IP from a other server are some thing else.

This client don't find the gateway so he could't to the internet. Ik hope you have some policies on you desktop computer's. But give it a try.

If this work you don't have to look in the wild world off the proxy config files ect.

Goodluck

Johan

TimH

Re: Absolutely blocking a machine?
« Reply #2 on: December 12, 2002, 03:46:52 PM »
Yep,

Just set PC D with a static IP config (i.e. not DHCP) and don't set any default gateway entry.

You will then need to ensure that the network properties cannot be modified unless you are an administrator on that PC.

Tim.

Kelvin

Re: Absolutely blocking a machine?
« Reply #3 on: December 13, 2002, 12:04:38 PM »
Additionally, after setting a fixed IP for that machine, modify the squid configuration file so that the IP address for this PC cannot use the SME server as a proxy for web access (proxying does not require a valid gateway as far as I'm aware, just a valid proxy server).

Either that or cut his cable and go back to "sneakerlan".

Kelvin

Boris

Re: Absolutely blocking a machine?
« Reply #4 on: December 14, 2002, 03:58:37 AM »
Remove modem from that computer too.