Secure setup needed for home business in infancy stage

CanadianEagle

New Member
Joined
Feb 20, 2008
Messages
2
Reaction score
0
Hello everyone,

I've done some reading on security, and hope to get some input here. We work with very sensitive client data, which we retain for several years.

I have:
1 modem (cable - switching to ADSL soon)
2 laptops
2 desktops
which all share the same work files.
I am using a linksys wrt54g with the wireless disabled, but feel that I need a more secure network now.

I plan to setup an old pc and using it as a dedicated file server. Is this an effective / cost-efficient approach?

After reading, I also thing that getting an older pc and setting up smoothwall on it would be a good idea. The machine I have has 3 pci slots.
This might sound like a stupid question, but does my smoothwall machine replace my linksys router completely?
Is there another program that I should look into?

My friend is writing me some custom file management/encryption software. And we use log-on passwords.
Is there anything else that I need to do to ensure that my data is as safe as possible, in a cost-efficient manner?

Other non-business equipment that need internet connection are:
1 pc for the kids
1 xbox 360
1 xbox original.
 
Smoothwall/ipcop/etc etc... I personally use pfSense (it supports multiple WAN interfaces) - an old P3 box, running pfSense would do exactly what you need - three network cards installed: One for DSL, one for internal lan, one for "wireless" - then you stick your wrt54g on this card!

This box would replace your linksys router (from a routing perspective) - but you would obviously need to retain the wrt54g on the network in order to serve your wireless laptops.

pfSense is quite popular on Jawug (due to the multiple wan interface option) - we are able to seperate our wireless networks, from our personal / internet systems

/me waits for The_Librarian to come and punt Smoothwall :D
 
Last edited:
If your familiar with linux you can install a linux firewall with iptables, otherwise you can use ipcop/pfsense - both work well.

A few questions to help you on the way:

Do you require internet clients to connect your servers? If so they should connect to servers which you can setup in a DMZ (You can use ipcop or pfsense) If you require this it requires a whole new set of security considerations - vulnerability testing, closing non used ports/services etc etc

Otherwise to keep data secure I would suggest using truecrypt. Its a open source file encryption program. Supports AES/3DES/Blowfish. You don't get much more secure than that. The new version also supports full disk encryption (windows only)
If the data is real sensative I would suggest backing up encrypted files as well and then storing in a secure location (not in your garage)

Also be very carefull about setting up the wireless connection. Again if the data is extremely secret I wouldn't use wireless. WAP/WEP are insecure. Use WPA2 or 802.1x if your laptops support it.
 
Last edited:
CanadianEagle said:
Is there anything else that I need to do to ensure that my data is as safe as possible
Yeah, stay away from shady sites and don't install random software on the PC.
 
My friend is writing me some custom file management/encryption software.
Not to diss your friend, but is he (alone?) better at it than the man-years of work put in by the likes of the people that develop TrueCrypt, et al?

And we use log-on passwords.
...which a keylogger would sniff and, conceivably, transmit to the bad guys anyhow :rolleyes:

Is there anything else that I need to do to ensure that my data is as safe as possible, in a cost-efficient manner?
Off-site backup, mosey (sorry, I had to!) on over for an idea of what's out there.
 
Thanks everyone. I will check out Truecrypt.

My buddy is writing me some file management software, and was going to include encryption as icing on the cake. I could always ask him to omit that part.

As for the log-on passwords, I know that they are not fool proof. (for instance, my wife showed me that you can open windows in safe mode, and delete all user passwords as the admin). But I suppose that it is better than nothing.

We are shying away from setting up remote access or client log-on, as well as online backup systems, because of the additional security concerns.

We disable the wireless too for security reasons, but is it possible to have a personal wan with wireless, and still have the seperate busienss network "safe?"

Between smoothwall, iptables, ipcop, pfsense, which is the most user friendly? The most advanced thing I have setup here at home is the wrt54g....
 
I'd go with ipcop - its pretty easy to use. Also use truecrypt for encryption - unless your friend is a crypto expert I wouldnt bother writing and encryption algorithm. Its likely to be weak - rather use a tried and tested one.

Logon passwords while notfoolproof are a nessessity. Sure they can be bypassed but if you don't have physical security someone can also walk away with your machine. Thats why you need encryption. Also choose strong passwords - not your wife's or dogs name.

Normally the best way to remember these is to not choose a password like "E4$#ft" but rather something easier to remeber - password phrases like "thisisalongpassword" and you can even put in 0,1,$ in place of letters.

You can with extra network cards in the ipcop box create a seperate network which then you can create rules for so that they have minimal access to the rest of the network.
 
Secure setup for home business

Hi,

When you are having a home business ,your computer and internet connection are the vital assets for providing service.your computer need to have a firewall programs to restrict unauthorised entry.There many firewalls available for your computer.you can surf through internet for the latest firewalls and for their user manual.
 
I would set up your network with you kids pc etc completely detached from the network with your business pc's. You don't want the kiddies installing some software inadvertently that lets a hacker etc access your network. You could still share the internet connection and achieve this using one of the firewalls mentioned.

In addition to that look at using whole disk encryption with your fileserver. TrueCrypt can achieve this. There are some products for the other computers and laptops that can encrypt the whole disk and require a password to unlock - to help in the event the laptops/pcs are stolen.

If you can avoid wireless, at least on the "business" side of the network then do. If you can't make sure you use WPA/WAP-2 etc encryption on it.

Otherwise just some common sense like get a good antivirus, do all your windows updates, keep off dodgy sites on business pcs, etc...
 
I plan to setup an old pc and using it as a dedicated file server. Is this an effective / cost-efficient approach?

In a word. No. Old PC's break and your files will be down untill you replace the hardware, I would treat the PC as a temporary solution for later budgets when you look into NAS storage with RAID.
 
Top
Sign up to the MyBroadband newsletter
X