|
-
October 27th, 2004, 07:38 AM
#1
Registered User
Single directional access?
I have two networks, netork a and network b, connected with two routers like so:
wan
|
router 1 ----- network a
|
|
|
router 2 ----- network b
ideally, network a would be able to have full access to network b, but not the other way around.
network b needs to access the WAN, but must not be able to access network a.
what is the best way to achieve this?
oh - most machines are win98se and there is no network server ( )
-
October 27th, 2004, 07:50 AM
#2
Geezer
what is the best way to achieve this?
Err with a server ? - what clients do we have besides 98 se ? - we want something like xp pro so we can use ACL's (access control lists) & do 'complex' filesharing
-
October 27th, 2004, 08:10 AM
#3
Registered User
yeah i know, however budget constraints prohibit a server. these same budget constraints also mean that upgrading the network to xp pro is not an option either :*( there is one xp pro box but unfortunately it is rarely on, and due to its location cannot be left on most of the time.
i was hoping to do it with some clever static routes on router 1, is this likely to work?
-
October 27th, 2004, 08:24 AM
#4
Registered User
Couldn't you setup a firewall on the machines on Network A to deny access from Network B? I would assume you can do this, but still allow access to Network B if the firewall is setup right...
Then again, that may be impossible, or out of the scope of the free version of most firewalls. Just an idea though...good luck!
-
October 27th, 2004, 08:29 AM
#5
Geezer
..ideally, network a would be able to have full access to network b, but not the other way around.
network b needs to access the WAN, but must not be able to access network a.
So can you define this a bit better ? do we really, really need access to 'everything' ? Otherwise I was gonna suggest you use your sole xp client, turn on 'complex' file sharing (well NOT use simple filesharing really ) & use that as a 'file server' - best I can currently think of as a 'no cost solution' here 
As for using routing somehow, maybe with IP blocking on the routers somehow ? (this'll be hard though if you use dhcp, but might be okay with static addressing - I can't say I've considered this before, as this situation screams' I need a central server please' to me )
-
October 27th, 2004, 09:24 AM
#6
Registered User
thanks for your help . have looked into it further, and have managed to get it working using firewall rules on router 2, which is not ideal but will do. the only problem i have left is that the print server uses the LPR protocol, but i am unsure on which port this operates. how can i find out?
also are there any basic free ftp servers for win98se?
-
October 27th, 2004, 10:12 AM
#7
Geezer
 Originally Posted by Six Eyed Smily
thanks for your help  . have looked into it further, and have managed to get it working using firewall rules on router 2, which is not ideal but will do. the only problem i have left is that the print server uses the LPR protocol, but i am unsure on which port this operates. how can i find out?
also are there any basic free ftp servers for win98se?
Welcome of course ..
File & print sharing is on port 139 ? but I now see 'everything' doesn't need shared, so yup ftp server will do that (& put the 'needing sharing' stuff on that - good thinking )..
Now free ftp server s/w .. well this used to be easy, but now all the 'good uns' charge .. IIS for a 'laughable suggestion' , Blaze FTP ? , & a few 'maybes' here - though I'd just 'lash' for something like Cuteftp Or 'whatever' to get some 'official' support (shouldn't be so dear ?)
-
October 27th, 2004, 02:03 PM
#8
Registered User
that would be a free ftp server, not client. sorry.
-
October 27th, 2004, 02:59 PM
#9
Geezer
 Originally Posted by Six Eyed Smily
that would be a free ftp server, not client. sorry.
Many of the clients will have server versions too, I was only doing 'vague suggestions' so some more suggestions ! - on this list, Cerberus is really free (thats ok), serve-u (used to be freeware & now isn't) & GuildFTPD (freeware) I think are worth a 'mooch' ..
-
October 28th, 2004, 06:13 AM
#10
Registered User
cheers - cerberus looks ideal - low cpu usage will come in handy too. as it is behind a whole stack of firewalls and NAT boxes, security isnt really an issue.
the printer port - windows file and printer sharing is on 139. however LPR is a unix protocol, and from what i can gather from googling it seems to be able to operate on a variety of ports. my print server is short on documentation, which doesnt help.
any ideas?
-
October 28th, 2004, 06:58 AM
#11
Geezer
 Originally Posted by Six Eyed Smily
the printer port - windows file and printer sharing is on 139. however LPR is a unix protocol, and from what i can gather from googling it seems to be able to operate on a variety of ports. my print server is short on documentation, which doesnt help.
any ideas?
(So still trying to keep 'free' in mind) ..Perhaps put a s/w firewall client on one of the pc's, like kerio or za, put on the 'ask/learn' feature & then it should ask if the port traffics allowed if you try a print .. if you are using a range of ports, a few sheets of paper printed out should at least give you a start ?
-
October 28th, 2004, 07:39 AM
#12
Registered User
now thats a good suggestion. will give that a go.
wish companies wouldnt try to be so 'user friendly' that they dont give you any information also wish this client had a larger budget. ahh well.
-
October 28th, 2004, 02:12 PM
#13
Registered User
 Originally Posted by Six Eyed Smily
cheers - cerberus looks ideal - low cpu usage will come in handy too. as it is behind a whole stack of firewalls and NAT boxes, security isnt really an issue.
the printer port - windows file and printer sharing is on 139. however LPR is a unix protocol, and from what i can gather from googling it seems to be able to operate on a variety of ports. my print server is short on documentation, which doesnt help.
any ideas?
if you can print out a configuration page, that should list the port. Alternatively, if you have machines that currently print to this device, you can check the port set up on the individual workstations, and that should tell you which one the printer is listening on...
-
October 29th, 2004, 04:53 AM
#14
Registered User
turns out its on port 515 -thanks.
-
October 29th, 2004, 04:58 AM
#15
Geezer
 Originally Posted by Six Eyed Smily
turns out its on port 515 -thanks.
Are you all 'good to go' now then ? Is that case closed ?
Similar Threads
-
By 70-240 in forum Certification
Replies: 14
Last Post: February 20th, 2012, 03:35 AM
-
By cpenergy in forum Microsoft Office
Replies: 2
Last Post: March 15th, 2001, 10:35 AM
-
By Melmac in forum Microsoft Office
Replies: 4
Last Post: March 8th, 2001, 09:17 AM
-
By Bjorn in forum Windows NT/2000
Replies: 3
Last Post: February 17th, 2001, 12:58 PM
-
By lvilleda in forum Windows NT/2000
Replies: 0
Last Post: November 3rd, 1999, 05:17 PM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|
Bookmarks