# LAN Security Question- Switches, Routers, & Modems (oh my)

**URL:** <https://boards.straightdope.com/t/lan-security-question-switches-routers-modems-oh-my/291067>\
**Category:** Factual Questions\
**Created:** [February 20, 2005, 9:40pm UTC](https://boards.straightdope.com/t/lan-security-question-switches-routers-modems-oh-my/291067 "2005-02-20T21:40:05Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![PatriotX](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@PatriotX](https://boards.straightdope.com/u/PatriotX)\
**Post date:** [February 20, 2005, 9:40pm UTC](https://boards.straightdope.com/t/lan-security-question-switches-routers-modems-oh-my/291067/1 "2005-02-20T21:40:05Z")

</div>

Is there any practical security difference _for computers **A** _ between these set ups?

**First Set Up**  
modem -\> router 0 -\> router 1 -\> comps A  
[INDENT]router 0 -\> comps B[/INDENT]  
The modem connects to router 0. Router 0 connects to comps B _and_ router 1. Router 1 connects to comps A

**Second Set Up**  
modem -\> switch -\> router 0 -\> comps B  
[INDENT]switch -\> router 1 -\> comps A[/INDENT]  
The modem connects to the switch. The switch connects to router0 and router1. Router0 connects to comps B. Router1 connects to comps A.  
In case it makes a difference:

**switch** :  
[NetGear FS105](http://www.netgear.com/products/details/FS105.php)  
**router 0** :  
[Linksys WRT54G](http://www.linksys.com/products/product.asp?grid=33&scid=35&prid=601)  
**router 1** :  
[Linksys BEFSR41](http://www.linksys.com/products/product.asp?grid=34&scid=29&prid=561)

---

<div class="post-metadata">

**Author:** ![PatriotX](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@PatriotX](https://boards.straightdope.com/u/PatriotX)\
**Post date:** [February 20, 2005, 10:07pm UTC](https://boards.straightdope.com/t/lan-security-question-switches-routers-modems-oh-my/291067/2 "2005-02-20T22:07:00Z")

</div>

I should’ve said:

For comps A from troubles (infections etc) in comps B.

If comps B get something nasty like a trojan, virus or other which set up (if either) is more secure for comps A?

---

<div class="post-metadata">

**Author:** ![Cleophus](https://avatars.discourse-cdn.com/v4/letter/c/a88e57/32.png) [@Cleophus](https://boards.straightdope.com/u/Cleophus)\
**Post date:** [February 20, 2005, 10:27pm UTC](https://boards.straightdope.com/t/lan-security-question-switches-routers-modems-oh-my/291067/3 "2005-02-20T22:27:10Z")

</div>

Cascading the routers like that is likely to lead to more trouble than it’s worth. It’s better to run ZoneAlarm on each machine if you’re worried that one machine may attack the other. That said, Setup 2 is likely to piss off your ISP and generally won’t work, as you’ll be attempting to request 2 IP addresses from your ISP. Also, in configuration 1 computer A will still be able to attack computer B.

---

<div class="post-metadata">

**Author:** ![PatriotX](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@PatriotX](https://boards.straightdope.com/u/PatriotX)\
**Post date:** [February 20, 2005, 11:07pm UTC](https://boards.straightdope.com/t/lan-security-question-switches-routers-modems-oh-my/291067/4 "2005-02-20T23:07:17Z")

</div>

> [@Cleophus](#):
>
> Cascading the routers like that is likely to lead to more trouble than it’s worth.

Quantity of comps -7- means that something has to be done.

> [@Cleophus](#):
>
> That said, Setup 2 is likely to piss off your ISP and generally won’t work, as you’ll be attempting to request 2 IP addresses from your ISP.

What if the switch were replaced by a router? That woudl eliminate the dual IP requests?

> [@Cleophus](#):
>
> Also, in configuration 1 computer A will still be able to attack computer B.

That’s what I’m afraid of. I don’t think that the comp **s** B are well secured, and I trying to decide if it’s worth my trouble to monkey with them and maintain this security. As difficult as it’ll be (for interpersonal, human reasons), if it’s the best way to reduce _my_ machines’ exposure, then that’s what I’ll do.

---

<div class="post-metadata">

**Author:** ![PatriotX](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@PatriotX](https://boards.straightdope.com/u/PatriotX)\
**Post date:** [February 20, 2005, 11:09pm UTC](https://boards.straightdope.com/t/lan-security-question-switches-routers-modems-oh-my/291067/5 "2005-02-20T23:09:21Z")

</div>

> [@PatriotX](#):
>
> What if the switch were replaced by a router? That would eliminate the dual IP requests?

As in  
modem -\> router 0 -\> routers 1&2

---

<div class="post-metadata">

**Author:** ![Cleophus](https://avatars.discourse-cdn.com/v4/letter/c/a88e57/32.png) [@Cleophus](https://boards.straightdope.com/u/Cleophus)\
**Post date:** [February 21, 2005, 1:17am UTC](https://boards.straightdope.com/t/lan-security-question-switches-routers-modems-oh-my/291067/6 "2005-02-21T01:17:12Z")

</div>

> [@PatriotX](#):
>
> Quantity of comps -7- means that something has to be done.

Are you saying you don’t have enough switch ports for all the computers? You can just add another switch or hub to the existing switch.

What environment will these computers be used in? Why do you feel software firewalls on each machine are insufficient? ZoneAlarm is free and quite effective at intercepting both incoming and outgoing malicious traffic. Plus, focusing entirely on one aspect of your network’s security will leave you vulnerable. A combination of effective anti-virus software, keeping up with the latest security updates, and avoidance of insecure software and unsafe downloads will do far more for your network’s overall security than firewalling all of the computers from each other.

---

<div class="post-metadata">

**Author:** ![PatriotX](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@PatriotX](https://boards.straightdope.com/u/PatriotX)\
**Post date:** [February 21, 2005, 1:55am UTC](https://boards.straightdope.com/t/lan-security-question-switches-routers-modems-oh-my/291067/7 "2005-02-21T01:55:41Z")

</div>

> [@Cleophus](#):
>
> Are you saying you don’t have enough switch ports for all the computers? You can just add another switch or hub to the existing switch.
> 
> What environment will these computers be used in? Why do you feel software firewalls on each machine are insufficient? ZoneAlarm is free and quite effective at intercepting both incoming and outgoing malicious traffic. Plus, focusing entirely on one aspect of your network’s security will leave you vulnerable. A combination of effective anti-virus software, keeping up with the latest security updates, and avoidance of insecure software and unsafe downloads will do far more for your network’s overall security than firewalling all of the computers from each other.

I’m responsible for only three of the machines. _I_ keep up with the Windows updates and patches. _I_ run Zone alram and Sygate firewalls. _I_ use NAV & AVG. _I_ have a battery of anti-spyware programs.

HOWEVER, the other computers are not under my care.

They have not had up to date virus definitions for more than a year.  
They have no firewalls (xpt one has XP’s built-in firewall).  
They have no anti-spyware prgrams whatsoever.  
Their OSes have not been updated and patched for some indefinite amount of time.  
An eleven year old surfs unsupervised on one of them.  
Because of the aforementioned factors, I suspect that these machines may be rife with malware of numerous sorts.

These conditions are not under my control.

I’m mostly worried about someone using a trojan from one of those machines gaining access to my machines.  
I don’t want to shut down the useful connectivity among my systems.

---

<div class="post-metadata">

**Author:** ![Cleophus](https://avatars.discourse-cdn.com/v4/letter/c/a88e57/32.png) [@Cleophus](https://boards.straightdope.com/u/Cleophus)\
**Post date:** [February 21, 2005, 3:11am UTC](https://boards.straightdope.com/t/lan-security-question-switches-routers-modems-oh-my/291067/8 "2005-02-21T03:11:20Z")

</div>

Since you have firewall software and up-to-date software, you should be protected. However, if you really want hardware protection I’d recommend a true firewall device like this [Netgear model](http://www.netgear.com/products/details/FR114P.php). It has a router, but firewall-only devices tend to be high-end enterprise hardware. Basic NAT devices usually aren’t true firewalls, as they don’t analyze traffic. Though, since you’ll still be running a NAT behind a NAT you may run into initial connectivity issues, like DNS server access (Try manually specifying the DNS servers to be the ones given by your ISP). And, if you do anything that requires inbound connections, like online gaming, you’ll have to make sure both routers are configured correctly. Finally, whatever you end up doing, make sure that wireless router is properly secured with 128-bit WEP and a non-dictionary password, and if you do use cascaded NAT, that it’s the upstream router.

---

<div class="post-metadata">

**Author:** ![Cleophus](https://avatars.discourse-cdn.com/v4/letter/c/a88e57/32.png) [@Cleophus](https://boards.straightdope.com/u/Cleophus)\
**Post date:** [February 21, 2005, 3:15am UTC](https://boards.straightdope.com/t/lan-security-question-switches-routers-modems-oh-my/291067/9 "2005-02-21T03:15:17Z")

</div>

Oh, and if you cascade the routers you need to make sure one router uses a 192.168.1.x internal address and the other a 192.168.0.x internal address. If the first three quads of the IP address are the same the routers will become confused and won’t route traffic properly.

---

<div class="post-metadata">

**Author:** ![PatriotX](https://avatars.discourse-cdn.com/v4/letter/p/c4cdca/32.png) [@PatriotX](https://boards.straightdope.com/u/PatriotX)\
**Post date:** [February 21, 2005, 4:17am UTC](https://boards.straightdope.com/t/lan-security-question-switches-routers-modems-oh-my/291067/10 "2005-02-21T04:17:53Z")

</div>

Thanks for the advice.
