• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Firewall/File Server How-To

AaronP

[H]F Junkie
Joined
Jan 13, 2005
Messages
11,527
I recently obtained a eMachine T1840. The system specs are:

Intel® Celeron® Processor 1.80 GHz (w/128KB L2 cache & 400MHz FSB)
Intel 845GL Chipset
128 MB DDR (PC2100)
40 GB HDD
40x12x40 Max. CD-RW Drive; 16x DVD Drive; 3.5" 1.44MB FDD
Intel Extreme Graphics 3D (845GL shared)
AC '97 Audio
10/100Mbps built-in Ethernet
56K* ITU v.92 ready Fax/Modem
Keyboard, Wheel Mouse, Stereo Speakers
6 USB 2.0 ports (2 on front), 1 Serial, 1 Parallel, 2 PS/2, Mic-In & Head Phone jack on front, Audio-In & Out, 3 PCI slots (2 available)
7.25"w x 14.125"h x 16"d

However the RAM has been updated to 340MB and I personally put in Windows XP Pro. I want to turn this into a physical Firewall/File Server for myself. But I don't know how I need to do that, so can anyone please point me in the right direction?
 
Just to clarify, do you want to connect this computer to the internet, then have all your other computers connect through it? If so you'll need a second ethernet card, one you can hook to your cable or dsl modem, then one to connect to your second computer, or to a router that your other computers hook up to. Then get some firewall software and install it on the computer connected to the internet. That's a start, i'm not completely sure where you would go from here. Run the Network Setup wizard, maybe.
 
What I want to do is use this Computer as a sort of "Gateway". Internet will flow through it before it flows to my Computer. My house is already has a network setup (currently only 2 computers of the possible 4 with the Linksys router). I just want it so I can put backup files on it when I need them (Say for a total format). But I also want it to act as a Fire Wall so the software one doesn't eat resources on my computer. But if that is what I need to do, then I'm in luck because I just so happen to have extra cable and an extra LAN card sitting around :D.
 
Yeah, that's where you start. Like I said i'm not sure how to configure the network after everything is hooked up. Just remember you gotta have that computer on all the time so that your networked computers can access the internet.
 
Here's what you wanna do, at the simplest level.

Install a second network card in the box.

Fire up XP Pro with your cable modem hooked up to one of the NICs, leave the other unplugged so as to make identifying them easier. Verify that the intended gateway/firewall box can access the internet, and troubleshoot that with your ISP if needed. In your Network connections control panel, rename the connection with Internet access to something that will identify it as such. Now, you want to share this connection with everyone else.

Bring the second NIC online (give it an appropriate name as well), and plug it into a switch (preferable) or hub, and plug all of your other boxes into the same switch/hub. Then, In Windows XP SP2, right click your Internet connected NIC, select 'properties,' click the 'advanced' tab and check the box 'allow other users to connect through this computer's internet connection' and click OK. It should cook for a few seconds and your network connections will go crazy for a second. After this, you have the shared connection ready to go, now to configure your clients

On your clients, make sure they are set to obtain their IP addresses automatically, then 'start' 'run' 'cmd' 'ipconfig /renew' It should spit out in the command prompt window an IP address in the range of 192.168.0.2 to 192.168.0.50, subnet mask of 255.255.255.0 and a default gateway of 192.168.0.1 Once you get this, verify that your clients can now access the Internet. Security is next.

Your clients are reasonably safe, as they do not have a routable IP address, only your gateway does. Only you allowing something stupid will cause a security breach on one of your client systems. You shouldn't need any firewall software on them. However, your gateway is quite vulnerable. Install anti-virus software that automatically updates itself and monitors writes to your hard disk. Install a good firewall program and (optional) block all ports except 20/21 (FTP) 25 (SMTP) 43 (DNS) 80 (HTTP) 443 (SSL) and ports you may need for games etc. Verify that your clients and server still have Internet access after setting up your security software, and tweak it as needed/desired. Also, create a user account that logs on automatically as a limited user (NOT a computer administrator) and set a secure password for all administrator accounts. As another level of security (you can't do this on XP Home) open up Computer Management, navigate to Local Users and Groups, and rename the system's built in Administrator account. Having the system logged on as a limited user will help prevent any software started while he's logged on (which is all the time) from making system wide changes/screwing stuff up.

Check out www.pricelessware.org if you need good free software for AV or firewall. everything on their list is spyware/adware/malware free.
 
Nice little walkthrough. I'll have to print that out and keep it. :D

If you DON'T set up your clients as limited users, you better make sure you've got good anti-spyware software installed on each one as well.
 
My advice:


Get a older PC from a garage sale. (must have PCI slots)
Install SmoothWall and 2 nics on older PC.
Connect the 1st nic to the modem and the 2nd to the switch.
Connect the newer PC to the network and enable file sharing.


A better solution to ICS, imo. may cost a little more, but you will be better off in the long run.
 
Thanks for the props on my walkthrough BeanMan. Global, I agree that ICS is far from the best NAT/PAT implementation out there. But I get the feeling that we don't want to stray into alternative OS territory here, and he's going to need a server licenses to do full blown routing and remote access on 'Doze.

ICS will also not allow him to host games on his client boxes, at least not very easily/intuitively. If that is an objective, one of the *Nix firewall/router implementations will be by far the best. I'm a Microsoft Certified System Administrator and am most of the way to Engineer, I know the limitations of MS products better than most. I've seen many of the 'gotchas' and procedures that only really work one way even those there is many to do them in MS products. For web surfing and such, ICS should work fine as long as he keeps an eye on security.
 
Back
Top