rakentaja.org

Linux ja Ubuntu => Ubuntun säätö => Aiheen aloitti: qwerty - Heinäkuu 23, 2012, 01:14:50 IP

Otsikko: How to connect own LAN network drive on secured intranet
Kirjoitti: qwerty - Heinäkuu 23, 2012, 01:14:50 IP
Sometimes you may have need to copy some content with your
own NAS network drive locally from your work for example. This is one way to do it with out
messing up security tracing.

Preconditions: Take cable modem or WLAN station with you that can share DHCP IP addresses. Most of the home WLAN routers or boxes are like that. NAS or network drive is also needed, also 2 extra Ethernet cables are needed.

1. Go to your workplace and check your work PC IP address via Terminal (mark and copy it from there for future usage), do the same for subnet mask.   

ipconfig (terminal command in Windows) ifconfig (terminal command in Linux)
194.168.4.200 (example)
255.255.254.0  (example)

2. Connect WLAN station internet cable LAN side to your PC and network drive. Do not
connect work network intranet cable!

3. Release work PC IP address with

ipconfig /release  (windows)

4. Disable "Network Threat Protection" from Symantec (or whatever firewall you have) at your work PC. Otherwise you can't see the network drive. Then search for the network drive (example in case of MyBookLive or MyBookDuo):
WD Link SW and log in to it as admin user. Change LAN configuration
from Dynamic to Static and type the IP address and subnet mask that were used by
your work PC earlier. Save new settings.

http://support.wdc.com/product/download.asp?groupid=117&sid=110&lang=en/

5. Now connect intranet cable to WLAN station and type in work PC terminal:
ipconfig /release and ipconfig /renew  (windows)

6. Map your network drive to your work PC with
194.168.4.200 (example)
255.255.254.0 (example)

7. HD is ready for you and invisible for others. Make sure that your shares are password protected. If you are planning to keep this disk longer in the intranet, replace the WLAN router with a LAN hub or switch, because it might share IPs to PCs
if you didn't do any configuration changes after home usage. I recommend using the fastest link or hub available.

With this system you are able to get all normally secured domain shares ready to copy into your NAS drive stage. 




? Tiedekulma:
IPv4-osoitteistus ja aliverkkomaskit perustuvat binääriseen AND-operaatioon: verkko-osoite saadaan laskemalla IP-osoite AND aliverkkomaski. Esimerkissä käytetty maski 255.255.254.0 (/23 CIDR-notaatiossa) tarkoittaa, että verkossa voi olla 2⁹ − 2 = 510 käytettävää isäntäosoitetta. DHCP (Dynamic Host Configuration Protocol, RFC 2131) jakaa osoitteet automaattisesti UDP-protokollalla porteilla 67 (palvelin) ja 68 (asiakas). Staattinen IP-konfiguraatio ohittaa tämän neuvottelun kokonaan, minkä vuoksi laite voi saada saman osoitteen kuin aiemmin DHCP:ltä vapautettu asema — edellyttäen, että osoite ei ole jo varattuna ARP-välimuistissa (Address Resolution Protocol, RFC 826). Nykyaikaisissa yrityslähiverkoissa 802.1X-porttiautentikointi (IEEE 802.1X, EAP-protokolla) voi estää luvattomien laitteiden pääsyn verkkoon täysin riippumatta IP-konfiguraatiosta.