Insulating one PC from the rest of the network

TechnoPro

Golden Member
Jul 10, 2003
1,727
0
76
Really simple home networking issue:

Two PCs are wireless connected to a wireless router. One user (PC1) wants to be absolutely certain that whatever nasties infect PC2, he will be insulated from them. My first thought is a software firewall for PC1. Any other steps that can be taken?
 

nweaver

Diamond Member
Jan 21, 2001
6,813
1
0
standard security/safety practices. S/W Firewall, AV, Spyware scans, etc. Anyone who thinks that the "h/w firewall is protecting me, I don't need to worry about it" is kidding themselves. The H/W firewall is a small part of overall security.
 
Jun 6, 2005
34
0
0
One would certainly take a HW firewall over a SW firewall though.. And, it is likely your best security measure. However, things like AV and anti-spyware are more reactive and help protect people from themselves. If you get a virus or spyware through a hardware firewall it's likely from something you initiated from inside, or allowed in. No firewall is the end all in security though, there should be different levels.
 

RedCOMET

Platinum Member
Jul 8, 2002
2,836
0
0
Originally posted by: nweaver
standard security/safety practices. S/W Firewall, AV, Spyware scans, etc. Anyone who thinks that the "h/w firewall is protecting me, I don't need to worry about it" is kidding themselves. The H/W firewall is a small part of overall security.

you mean like a multi-layered solution? separate subnet for the wireless clients, besides AV, software F/W and spyware scans.

I can think of using a linux router with three nics to have separate subnets, or you could use 2 routers to somewhat segment your network.
 

TechnoPro

Golden Member
Jul 10, 2003
1,727
0
76
Originally posted by: RedCOMET
Originally posted by: nweaver
standard security/safety practices. S/W Firewall, AV, Spyware scans, etc. Anyone who thinks that the "h/w firewall is protecting me, I don't need to worry about it" is kidding themselves. The H/W firewall is a small part of overall security.

you mean like a multi-layered solution? separate subnet for the wireless clients, besides AV, software F/W and spyware scans.

I can think of using a linux router with three nics to have separate subnets, or you could use 2 routers to somewhat segment your network.

This is a home scenario with basic off-the-shelf equipment, and no budget to add to the existing setup. As such, it would seem that I am stuck with software based solutions.
 

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,553
430
126
If these two PCs do not need to share files between them.

A variation of the principle in this page might help.

"Infested prone" guy on front. "Safe" Guy behind Segregation.

Wireless Segregation - http://www.ezlan.net/shield.html

:sun: