Re: Cable/DSL routers for network security (long)

From: Bill Gurley <bgurley_at_utk.edu>
Date: Thu, 30 Nov 2000 19:11:06 -0500

An excellent approach. But a couple of words of warning:

1. Don't go too crazy. There are rules about things like
connecting routers to other routers, etc., in order maintain
the electrical and data integrity of the network. If you're
connecting to 100BaseT, you're probably ok, but if you want
to connect a whole bunch of machines to a single 10Mbit
circuit, be careful.

2. Your local Network Management people may not like your
"rolling your own" approach, because it lessens their
ability to remotely monitor and control the network. (also
because it eats into their revenue flow!!) So you may want
to look into this a bit before investing too much time and
money.


"B. W. Bangerter" wrote:
>
> A simple, inexpensive means of improving network security--
>
> A topic that has been discussed several times in this forum, and at the
> AMMRL meeting at the past ENC at Asilomar, is security of spectrometer
> (and other) computers that are on LANs connected to the Internet. Many
> of us have had the mortifying experience of having one of our computers
> cracked into by an outsider bent on making trouble. The standard
> response to such an invasion is: "undo the network connection, reformat
> the disk, reinstall the OS, reinstall the application software." And
> get everything working again. Computer networking and security are
> complex matters, and most of us have little understanding of these
> things, and little inclination to learn more about this stuff than we
> must to keep our spectrometers operating and get our work done.
> Fortunately there is a simple and inexpensive step we can take to
> greatly improve the security of our computers.
>
> This solution is to connect our laboratory network (or even a single
> computer) to our enterprise network through a "Cable/DSL Gateway
> Router." These devices were designed to allow a cable or DSL subscriber
> to connect a small local network of computers to the service, using only
> a single IP address from the service provider. The devices use a method
> called network address translation (NAT) to allow multiple computers on
> a private network to connect to the outside using a single globally
> unique or registered IP address. They provide firewall features, in
> that outside computers are unable to learn of the existence of the
> private network addresses, some of the routers offer various packet
> filtering schemes, and the routers also provide for servers to run on
> the private network using "port mapping." Depending on the model, up to
> 253 private network addresses can be accommodated (that's a lot of
> spectrometers), and some include 10/100 switches. They are easily set
> up and administered, with Web browser or Telnet connections. Best of
> all, they are inexpensive - $100 to $250 or so. Manufacturers of these
> devices include:
>
> Netgear (RT311, RT314) http://www.netgear.com/
>
> Linksys (BEFSR11, 41, 81) http://www.linksys.com/
>
> SMC Networks (Barricade) http://www.smc.com/
>
> I am sure there are others. This is a rapidly growing market, with the
> proliferation of cable modem and DSL users across the country. The WWW
> sites offer data sheets and manuals for the gateway routers, and some
> have tutorials as well. The routers are available from most of the
> usual catalog vendors, such as PC Connection, Mac Warehouse, etc. I
> have been using a Netgear RT311 for a short while, and it seems to work
> as advertised. In addition to the security provided, we can now connect
> as many devices as we want, creating our own private IP addresses,
> paying the University for one registered address, and generally
> simplifying the network hassle. In our department, we plan to take most
> of the 400 or so computers off the 130.132. Yale domain and put them
> behind these gateway routers on private networks.
>
> Ben Bangerter

-- 
-Bill-
 Bill Gurley, Supervisor of Technical Services
 Department of Chemistry
 University of Tennessee, Knoxville Campus
Received on Fri Dec 01 2000 - 08:57:04 MST

This archive was generated by hypermail 2.4.0 : Sat Jun 03 2023 - 17:57:16 MST