Page 1 of 2 12 LastLast
Results 1 to 16 of 18

Thread: Separate Home network, help required

  1. #1
    Laird Of The Glen jimborae's Avatar
    Join Date
    Oct 2003
    Location
    I come from a land of plenty......not
    Posts
    3,490
    Thanks
    259
    Thanked
    370 times in 303 posts
    • jimborae's system
      • Motherboard:
      • Gigabyte Aorus Z390 Pro
      • CPU:
      • Core i7 9700K@4.7Ghz
      • Memory:
      • Team Group DDR-3000 32Gig
      • Storage:
      • 1x Samsung 870 Evo 500Gb SSD, 1 x WD Red 4TB
      • Graphics card(s):
      • Gigabyte Radeon 5700XT watercooled
      • PSU:
      • XFX 850W Black Edition
      • Case:
      • Phantek Enthoo Prime
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • 2 xDell 24"
      • Internet:
      • PlusNet 70Mb

    Separate Home network, help required

    Hi all, looking for help. No1. son got his own laptop today for his 14th birthday which means I now have much less control on what he does and where he goes on it, thus I'm fully expecting it to get riddled with malware in the near future. I've imaged it so disinfecting it is no biggie but my concern is malware propogating through our home network and infecting other pcs or our home server. Therfore I think the best way to go is to somehow seperate the home network so he effectively is firewalled/on a seperate lan to the rest of the household. Sooooo looking for some good advice on how to acheive this. He wont need to access anything else on the network via his laptop except for the printer, the current home network is fairly basic with a main router (Asus RT-AC87u) feeding the rest of the house via wi-fi (mobile devices) and homeplugs (static devices). The home server & my pc's in the loft connect indirectly to the router via ethernet and a pro curve switch and not via home plugs.

    Cheers

    Jim
    Last edited by jimborae; 07-04-2016 at 04:25 PM.

  2. #2
    Anthropomorphic Personification shaithis's Avatar
    Join Date
    Apr 2004
    Location
    The Last Aerie
    Posts
    10,857
    Thanks
    645
    Thanked
    872 times in 736 posts
    • shaithis's system
      • Motherboard:
      • Asus P8Z77 WS
      • CPU:
      • i7 3770k @ 4.5GHz
      • Memory:
      • 32GB HyperX 1866
      • Storage:
      • Lots!
      • Graphics card(s):
      • Sapphire Fury X
      • PSU:
      • Corsair HX850
      • Case:
      • Corsair 600T (White)
      • Operating System:
      • Windows 10 x64
      • Monitor(s):
      • 2 x Dell 3007
      • Internet:
      • Zen 80Mb Fibre

    Re: Separate Home network, help required

    There are really only 2 ways to segregate the traffic and both are reliant on your router supporting the functionality....

    1. VLANs. You would want to create a new "unsecure" VLAN for your sons PC (and possibly the Wifi!) and then add a bridge to route traffic between the VLANs virtual interface and the WAN interface.

    2. Separate subnets. Different IP ranges for different machines and then a route to allow the new subnet to talk out onto the internet. A clever user could reconfigure the network connection to bypass this though.


    I do number 1 on a DD-WRT router but unsure if the Asus supports it.....you may need a new router.
    Main PC: Asus Rampage IV Extreme / 3960X@4.5GHz / Antec H1200 Pro / 32GB DDR3-1866 Quad Channel / Sapphire Fury X / Areca 1680 / 850W EVGA SuperNOVA Gold 2 / Corsair 600T / 2x Dell 3007 / 4 x 250GB SSD + 2 x 80GB SSD / 4 x 1TB HDD (RAID 10) / Windows 10 Pro, Yosemite & Ubuntu
    HTPC: AsRock Z77 Pro 4 / 3770K@4.2GHz / 24GB / GTX 1080 / SST-LC20 / Antec TP-550 / Hisense 65k5510 4K TV / HTC Vive / 2 x 240GB SSD + 12TB HDD Space / Race Seat / Logitech G29 / Win 10 Pro
    HTPC2: Asus AM1I-A / 5150 / 4GB / Corsair Force 3 240GB / Silverstone SST-ML05B + ST30SF / Samsung UE60H6200 TV / Windows 10 Pro
    Spare/Loaner: Gigabyte EX58-UD5 / i950 / 12GB / HD7870 / Corsair 300R / Silverpower 700W modular
    NAS 1: HP N40L / 12GB ECC RAM / 2 x 3TB Arrays || NAS 2: Dell PowerEdge T110 II / 24GB ECC RAM / 2 x 3TB Hybrid arrays || Network:Buffalo WZR-1166DHP w/DD-WRT + HP ProCurve 1800-24G
    Laptop: Dell Precision 5510 Printer: HP CP1515n || Phone: Huawei P30 || Other: Samsung Galaxy Tab 4 Pro 10.1 CM14 / Playstation 4 + G29 + 2TB Hybrid drive

  3. Received thanks from:

    jimborae (07-04-2016)

  4. #3
    Laird Of The Glen jimborae's Avatar
    Join Date
    Oct 2003
    Location
    I come from a land of plenty......not
    Posts
    3,490
    Thanks
    259
    Thanked
    370 times in 303 posts
    • jimborae's system
      • Motherboard:
      • Gigabyte Aorus Z390 Pro
      • CPU:
      • Core i7 9700K@4.7Ghz
      • Memory:
      • Team Group DDR-3000 32Gig
      • Storage:
      • 1x Samsung 870 Evo 500Gb SSD, 1 x WD Red 4TB
      • Graphics card(s):
      • Gigabyte Radeon 5700XT watercooled
      • PSU:
      • XFX 850W Black Edition
      • Case:
      • Phantek Enthoo Prime
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • 2 xDell 24"
      • Internet:
      • PlusNet 70Mb

    Re: Separate Home network, help required

    Cheers for the reply, yeah those are the options that I pretty much figured just wanted to check I wasn't missing anything else.

    Option 1 is supported by my main router out of the box, and it currently runs Merlin firmware which is supposed to give even more functionality but I'll have to investigate how to set this up. Any tips or guides you can recommend?

    Option 2 - From what I've been reading wont this require 2 other routers (which I have) connected via their wan ports to the main router??? Would be physically more difficult to do I reckon as I'll have to change a whole host of other settings and re set up a second router for the rest of the house hold to use. But it is doable and I have the kit to do it.
    Last edited by jimborae; 07-04-2016 at 04:25 PM.

  5. #4
    bored out of my tiny mind malfunction's Avatar
    Join Date
    Jul 2003
    Location
    Lurking
    Posts
    3,923
    Thanks
    191
    Thanked
    187 times in 163 posts
    • malfunction's system
      • Motherboard:
      • Gigabyte G1.Sniper (with daft heatsinks and annoying Killer NIC)
      • CPU:
      • Xeon X5670 (6 core LGA 1366) @ 4.4GHz
      • Memory:
      • 48GB DDR3 1600 (6 * 8GB)
      • Storage:
      • 1TB 840 Evo + 1TB 850 Evo
      • Graphics card(s):
      • 290X
      • PSU:
      • Antec True Power New 750W
      • Case:
      • Cooltek W2
      • Operating System:
      • Windows 10
      • Monitor(s):
      • Dell U2715H

    Re: Separate Home network, help required

    Some routers offer a guest wifi feature as well - with various options for isolation and bandwidth control

  6. #5
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: Separate Home network, help required

    Yes, subnet is probably the simplest way. You could get something like pfsense to form a somewhat more resilient firewall and put him behind that, but that may be overkill.

    https://www.pfsense.org Or just download the software and install it on your own hardware.

    Of course, the best defence is educating him about the risks, but 14 year old makes don't deal with risk very well, and of course it won't happen to him !
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  7. Received thanks from:

    jimborae (07-04-2016)

  8. #6
    Laird Of The Glen jimborae's Avatar
    Join Date
    Oct 2003
    Location
    I come from a land of plenty......not
    Posts
    3,490
    Thanks
    259
    Thanked
    370 times in 303 posts
    • jimborae's system
      • Motherboard:
      • Gigabyte Aorus Z390 Pro
      • CPU:
      • Core i7 9700K@4.7Ghz
      • Memory:
      • Team Group DDR-3000 32Gig
      • Storage:
      • 1x Samsung 870 Evo 500Gb SSD, 1 x WD Red 4TB
      • Graphics card(s):
      • Gigabyte Radeon 5700XT watercooled
      • PSU:
      • XFX 850W Black Edition
      • Case:
      • Phantek Enthoo Prime
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • 2 xDell 24"
      • Internet:
      • PlusNet 70Mb

    Re: Separate Home network, help required

    Quote Originally Posted by peterb View Post
    ......
    Of course, the best defence is educating him about the risks, but 14 year old makes don't deal with risk very well, and of course it won't happen to him !
    So true and education is not his forte, he's a very imature/young 14yr old.

  9. #7
    Laird Of The Glen jimborae's Avatar
    Join Date
    Oct 2003
    Location
    I come from a land of plenty......not
    Posts
    3,490
    Thanks
    259
    Thanked
    370 times in 303 posts
    • jimborae's system
      • Motherboard:
      • Gigabyte Aorus Z390 Pro
      • CPU:
      • Core i7 9700K@4.7Ghz
      • Memory:
      • Team Group DDR-3000 32Gig
      • Storage:
      • 1x Samsung 870 Evo 500Gb SSD, 1 x WD Red 4TB
      • Graphics card(s):
      • Gigabyte Radeon 5700XT watercooled
      • PSU:
      • XFX 850W Black Edition
      • Case:
      • Phantek Enthoo Prime
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • 2 xDell 24"
      • Internet:
      • PlusNet 70Mb

    Re: Separate Home network, help required

    Quote Originally Posted by malfunction View Post
    Some routers offer a guest wifi feature as well - with various options for isolation and bandwidth control
    Yep mine has that, in fact I can set multiple guest wi-fi networks however I'm sure he'll end up plugging a cable in to it from the switch in his room at some point (TV & Xbox will connect to this as well).

  10. #8
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: Separate Home network, help required

    Quote Originally Posted by jimborae View Post
    Yep mine has that, in fact I can set multiple guest wi-fi networks however I'm sure he'll end up plugging a cable in to it from the switch in his room at some point (TV & Xbox will connect to this as well).
    Ah yes "Oh Lord, please send me a teenager while they still know everything!"

    You might want to look at smoothwall http://www.smoothwall.org. If that was hard wired to a cable in his room... Or probably put the rest of the family's system behind the firewall and just wait for the inevitable
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  11. #9
    Laird Of The Glen jimborae's Avatar
    Join Date
    Oct 2003
    Location
    I come from a land of plenty......not
    Posts
    3,490
    Thanks
    259
    Thanked
    370 times in 303 posts
    • jimborae's system
      • Motherboard:
      • Gigabyte Aorus Z390 Pro
      • CPU:
      • Core i7 9700K@4.7Ghz
      • Memory:
      • Team Group DDR-3000 32Gig
      • Storage:
      • 1x Samsung 870 Evo 500Gb SSD, 1 x WD Red 4TB
      • Graphics card(s):
      • Gigabyte Radeon 5700XT watercooled
      • PSU:
      • XFX 850W Black Edition
      • Case:
      • Phantek Enthoo Prime
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • 2 xDell 24"
      • Internet:
      • PlusNet 70Mb

    Re: Separate Home network, help required

    Quote Originally Posted by peterb View Post
    ..........
    You might want to look at smoothwall http://www.smoothwall.org. If that was hard wired to a cable in his room... Or probably put the rest of the family's system behind the firewall and just wait for the inevitable
    Thanks will check it out.

  12. #10
    Laird Of The Glen jimborae's Avatar
    Join Date
    Oct 2003
    Location
    I come from a land of plenty......not
    Posts
    3,490
    Thanks
    259
    Thanked
    370 times in 303 posts
    • jimborae's system
      • Motherboard:
      • Gigabyte Aorus Z390 Pro
      • CPU:
      • Core i7 9700K@4.7Ghz
      • Memory:
      • Team Group DDR-3000 32Gig
      • Storage:
      • 1x Samsung 870 Evo 500Gb SSD, 1 x WD Red 4TB
      • Graphics card(s):
      • Gigabyte Radeon 5700XT watercooled
      • PSU:
      • XFX 850W Black Edition
      • Case:
      • Phantek Enthoo Prime
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • 2 xDell 24"
      • Internet:
      • PlusNet 70Mb

    Re: Separate Home network, help required

    Looking into things further in the long run it maybe easier to drop ethernet down to his room from the Pro Curve and set up a vlan on that. Short term just do the guest wi-fi option till long term solution sorted.

  13. #11
    RIP Peterb ik9000's Avatar
    Join Date
    Nov 2009
    Posts
    7,704
    Thanks
    1,840
    Thanked
    1,434 times in 1,057 posts
    • ik9000's system
      • Motherboard:
      • Asus P7H55-M/USB3
      • CPU:
      • i7-870, Prolimatech Megahalems, 2x Akasa Apache 120mm
      • Memory:
      • 4x4GB Corsair Vengeance 2133 11-11-11-27
      • Storage:
      • 2x256GB Samsung 840-Pro, 1TB Seagate 7200.12, 1TB Seagate ES.2
      • Graphics card(s):
      • Gigabyte GTX 460 1GB SuperOverClocked
      • PSU:
      • NZXT Hale 90 750w
      • Case:
      • BitFenix Survivor + Bitfenix spectre LED fans, LG BluRay R/W optical drive
      • Operating System:
      • Windows 7 Professional
      • Monitor(s):
      • Dell U2414h, U2311h 1920x1080
      • Internet:
      • 200Mb/s Fibre and 4G wifi

    Re: Separate Home network, help required

    I think my router lets you assign access privileges to the LAN, WAN, etc based on Mac address - so if you log his network card mac address for the LAN you may be able to block/direct him to a subnet that way. My old one definitely did. Having just gone into the parental controls recently my new one seems to be far inferior to the old D-Link I used to have 6 years ago! I hope it's not the case for assigning subnets too...

    out of interest how are you managing what he accesses? Do you use any parental control software or just an honesty system?

  14. #12
    Laird Of The Glen jimborae's Avatar
    Join Date
    Oct 2003
    Location
    I come from a land of plenty......not
    Posts
    3,490
    Thanks
    259
    Thanked
    370 times in 303 posts
    • jimborae's system
      • Motherboard:
      • Gigabyte Aorus Z390 Pro
      • CPU:
      • Core i7 9700K@4.7Ghz
      • Memory:
      • Team Group DDR-3000 32Gig
      • Storage:
      • 1x Samsung 870 Evo 500Gb SSD, 1 x WD Red 4TB
      • Graphics card(s):
      • Gigabyte Radeon 5700XT watercooled
      • PSU:
      • XFX 850W Black Edition
      • Case:
      • Phantek Enthoo Prime
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • 2 xDell 24"
      • Internet:
      • PlusNet 70Mb

    Re: Separate Home network, help required

    Quote Originally Posted by ik9000 View Post
    I think my router lets you assign access privileges to the LAN, WAN, etc based on Mac address - so if you log his network card mac address for the LAN you may be able to block/direct him to a subnet that way. ...

    out of interest how are you managing what he accesses? Do you use any parental control software or just an honesty system?
    Access is currently on an honesty system, he knows I regularly check his browsing history etc and to be frank he's too naive to go to darker places intentionally....though I suspect that will change in the next 12-18 months so parental controls will have to be implemented at some point.

  15. #13
    Senior Member Smudger's Avatar
    Join Date
    Oct 2005
    Location
    St Albans
    Posts
    3,866
    Thanks
    674
    Thanked
    619 times in 451 posts
    • Smudger's system
      • Motherboard:
      • Gbyte GA-970A-UD3P
      • CPU:
      • AMD FX8320 Black Edition
      • Memory:
      • 16GB 2x8G CML16GX3M2A1600C10
      • Storage:
      • 1x240Gb Corsair M500, 2TB TOSHIBA DT01ACA200
      • Graphics card(s):
      • XFX Radeon HD4890 1GB
      • PSU:
      • Corsair HX520
      • Case:
      • Akasa Zen
      • Operating System:
      • Windows 10 Home
      • Monitor(s):
      • Dell 24"
      • Internet:
      • Virgin 200Mbit

    Re: Separate Home network, help required

    If he's 14, he probably already knows about incognito mode...

  16. #14
    Laird Of The Glen jimborae's Avatar
    Join Date
    Oct 2003
    Location
    I come from a land of plenty......not
    Posts
    3,490
    Thanks
    259
    Thanked
    370 times in 303 posts
    • jimborae's system
      • Motherboard:
      • Gigabyte Aorus Z390 Pro
      • CPU:
      • Core i7 9700K@4.7Ghz
      • Memory:
      • Team Group DDR-3000 32Gig
      • Storage:
      • 1x Samsung 870 Evo 500Gb SSD, 1 x WD Red 4TB
      • Graphics card(s):
      • Gigabyte Radeon 5700XT watercooled
      • PSU:
      • XFX 850W Black Edition
      • Case:
      • Phantek Enthoo Prime
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • 2 xDell 24"
      • Internet:
      • PlusNet 70Mb

    Re: Separate Home network, help required

    Quote Originally Posted by Smudger View Post
    If he's 14, he probably already knows about incognito mode...
    Nope he doesn't, as I said he's pretty naive and not IT literate yet.

  17. #15
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: Separate Home network, help required

    Quote Originally Posted by Smudger View Post
    If he's 14, he probably already knows about incognito mode...
    Yes, it's down to key loggers and a proxy server logging all the sites...
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  18. #16
    RIP Peterb ik9000's Avatar
    Join Date
    Nov 2009
    Posts
    7,704
    Thanks
    1,840
    Thanked
    1,434 times in 1,057 posts
    • ik9000's system
      • Motherboard:
      • Asus P7H55-M/USB3
      • CPU:
      • i7-870, Prolimatech Megahalems, 2x Akasa Apache 120mm
      • Memory:
      • 4x4GB Corsair Vengeance 2133 11-11-11-27
      • Storage:
      • 2x256GB Samsung 840-Pro, 1TB Seagate 7200.12, 1TB Seagate ES.2
      • Graphics card(s):
      • Gigabyte GTX 460 1GB SuperOverClocked
      • PSU:
      • NZXT Hale 90 750w
      • Case:
      • BitFenix Survivor + Bitfenix spectre LED fans, LG BluRay R/W optical drive
      • Operating System:
      • Windows 7 Professional
      • Monitor(s):
      • Dell U2414h, U2311h 1920x1080
      • Internet:
      • 200Mb/s Fibre and 4G wifi

    Re: Separate Home network, help required

    Quote Originally Posted by peterb View Post
    Yes, it's down to key loggers and a proxy server logging all the sites...
    I'm fairly certain a determined individual can see adult content without needing to type anything more than " ". The rest is all mouse clicks. Key loggers are not necessarily the answer. And it depends how good the listing of the proxy server is at interpreting long search site strings such as all the hashing the sites like bing etc produce as to whether you can check what they were actually viewing...

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •