LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 02-15-2007, 01:00 PM   #1
crash_override_me
Member
 
Registered: Aug 2005
Location: India, New Delhi
Distribution: Debian Etch, Ubuntu
Posts: 342

Rep: Reputation: 30
Question Blocking Net Access....


hi guys..

I have to setup a lab with complete networking...
Is any there any way by which i can configure all the PCs to communicate each other via lan.. but block internet access on them... as the lan is connected to a proxy server of our university, that is accessible to the whole univ. network...??

Can this be done thru some tweaking.. or do we need some software..??
 
Old 02-15-2007, 01:23 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
well you can configure the proxy to block their source addresses, or just don't give the pc's a default route out of the network.
 
Old 02-15-2007, 01:30 PM   #3
crash_override_me
Member
 
Registered: Aug 2005
Location: India, New Delhi
Distribution: Debian Etch, Ubuntu
Posts: 342

Original Poster
Rep: Reputation: 30
can u explain wat u r trying to say...??
 
Old 02-15-2007, 01:44 PM   #4
karpi
Member
 
Registered: Oct 2005
Location: Germany
Distribution: Suse
Posts: 134

Rep: Reputation: 15
Hello,

if only the Labs-Pcs should be able to communicate with each other I would do it the following way.

Just configure a network that is different from the Universitys Proxy and leave the standard(default)-gateway blank or set a wrong standard(default)-gateway. With this "wrong" network configuration the Lab wouldn't be able to communicate with the Proxy.

This can be done manually, configure each PC or via DHCP.

This is a rough but in my pov the securest way to limit the network acces to the Lab (Provided the users don't have root privilegs)


HTH
 
Old 02-15-2007, 03:03 PM   #5
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Quote:
Originally Posted by crash_override_me
can u explain wat u r trying to say...??
no, YOU need to say what YOU mean better... not sure what you don't understand about my reply... should surely be self explanatory for anyone able to set up their own lab...
 
Old 02-16-2007, 01:58 AM   #6
crash_override_me
Member
 
Registered: Aug 2005
Location: India, New Delhi
Distribution: Debian Etch, Ubuntu
Posts: 342

Original Poster
Rep: Reputation: 30
Quote:
Originally Posted by karpi
Hello,

if only the Labs-Pcs should be able to communicate with each other I would do it the following way.

Just configure a network that is different from the Universitys Proxy and leave the standard(default)-gateway blank or set a wrong standard(default)-gateway. With this "wrong" network configuration the Lab wouldn't be able to communicate with the Proxy.

This can be done manually, configure each PC or via DHCP.

This is a rough but in my pov the securest way to limit the network acces to the Lab (Provided the users don't have root privilegs)


HTH
will this allow all the PCs in the Lab to communicate each other..??
No the PCs wont have root priviledges...!!
 
Old 02-16-2007, 02:10 AM   #7
karpi
Member
 
Registered: Oct 2005
Location: Germany
Distribution: Suse
Posts: 134

Rep: Reputation: 15
Hi,

yes the PCs would be able to communicate with each other, because they are in the same network.

If the Proxy has the IP 192.168.3.2 and netmask 255.255.255.0 your Lab is isolated if you use
192.168.y.x (y any value from 1 to 254 without 2).

If the users have root privilegs the would be able to change your configuration ;-).

HTH
 
Old 02-16-2007, 02:28 PM   #8
crash_override_me
Member
 
Registered: Aug 2005
Location: India, New Delhi
Distribution: Debian Etch, Ubuntu
Posts: 342

Original Poster
Rep: Reputation: 30
the proxy has the IP: 172.x.y.z
Netmask: 255.255.0.0
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Blocking access on a particular app (via sudo) Harlin Linux - Security 10 10-22-2006 02:11 PM
blocking access by region? vbsaltydog Linux - Security 6 04-24-2006 10:04 AM
blocking smux after net-snmp rpm install relayer416 Linux - Software 0 02-16-2005 07:50 PM
How can I tell what is blocking access to my homepage Bjorkli Linux - Networking 0 09-14-2004 05:06 AM
shorewall blocking access to net mandrake 9 tewaru Linux - Newbie 2 12-04-2002 03:29 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:34 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration