ATTN: Leythos - Hardware Firewall Solution

I'm working on wiring up a small condo association and they want to share an internet connection. Of course they are all seniors, so they are terrified of the net.

I can't spend an arm and a leg, but I want to make sure they are sufficiently protected.

Have you any experience with the D-Link DFL-210, D-Link DFL-700, and the Firebox X10E.

Thanks to you, or anybody else, willing to render an educated opinion.

Reply to
Spender
Loading thread data ...

I have used all of them.

The X10e will not handle very many nodes, 10, max of 15. You want the device to handle at least double the number you have expected because each device will register (so if each of them have a computer, then they add wireless to their home, then they have a couple grandkids visit with laptops.... that's one for each of those).

The DFL-700 will do what you want, but you have to understand that every user will be on a joined network, all on the same LAN - so one person being compromised will spread it to all others.

We did a small building with 16 office companies in it - came in to a 24 Port network switch from the ISP device, setup 16 Linksys BEFSR41 NAT routers on a fixed IP each, so that each company had their own public IP, and then we set each of the Linksys lans to a different Subnet:

LOC PUBLIC IP PRIVATE IP

CO1 X.Y.Z.1 192.168.101.1/24 CO2 X.Y.Z.2 192.168.102.1/24 CO3 X.Y.Z.3 192.168.103.1/24 CO4 X.Y.Z.4 192.168.104.1/24 CO5 X.Y.Z.4 192.168.105.1/24

This means that each office company has their own LAN, they can't compromise the other LAN's in the building, and they are entitled to their own port forwarding, etc....

You could get a Firebox X550 series, in Drop-In mode, so that you have the same IP on the WAN and then LAN, then you could put in the routers like I show above and give then all public IP's. You could use the DMZ port for free wireless coverage - locking it down to DNS, HTTP, HTTPS for guess access....

If you put them all on one network you will regret it and they will grow to hate you.

Reply to
Leythos

Hey, wait a minute - I'm what you lot across the pond call a 'senior', and I'm not 'terrified of the net'!

8^(

Jim Ford

Reply to
Jim Ford

Most seniors know more about the "Net" than most younger people give them credit for - I know I was really surprised about what my Mother and Mother inlaw actually do on the Internet.

Reply to
Leythos

I'm glad you said 'surprised' and not 'shocked'! ;^)

Jim Ford

Reply to
Jim Ford

The only time I've been "Shocked" was when I first started doing work for Sororities - the things that todays young adult women have on their PC's, not to mention in their dorm rooms....

Reply to
Leythos

Do tell! ;^)

Jim Ford

Reply to
Jim Ford

LOL - Can't, NDA and all :)

It's funny, when we get a call it's almost like a fight to see who will provide service - but I never let anyone else handle it - I've had a number of sexual harassment training classes and always ask (require) and escort from a house mother if we have to go anywhere other than the common areas.

Reply to
Leythos

I apologize for the generalization. But the fact is that the residents of this condo project are afraid of their television remotes.

Reply to
Spender

He was kidding, in case it didn't come across that way.

Reply to
Leythos

It's mobile 'phones I hate. The only time I ever want to use mine, when I'm backpacking in the Scottish Mountains and want to reassure my wife that I'm OK, the damn thing doesn't work because it can't acquire a signal!

Jim Ford

Reply to
Jim Ford

What, me kidding that I'm not afraid of the net? ;^)

Jim Ford

Reply to
Jim Ford

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.