DMZ and File Sharing

Networking and broadband talkabout. Need help with that new router or setting up a network?
Post Reply
User avatar
Busby
Golden Member
Posts: 1890
Joined: Tue Nov 28, 2000 6:25 pm
Location: Atlanta Area, GA, USA
Contact:

DMZ and File Sharing

Post by Busby »

I know DMZ exposes you to the internet but would it still be ok to use file sharing across the LAN? I'm thinking not and I just need to manually forward the ports for BT but I'm not sure.
<a href="mailto:busby1218@charter.net">
<img src="http://justinbusby.com:8080/signature.gif" border="0"></a>
User avatar
FlyingPenguin
Flightless Bird
Posts: 33161
Joined: Wed Nov 22, 2000 11:13 am
Location: Central Florida
Contact:

Post by FlyingPenguin »

What kind of file sharing are you trying to do? You said "File Sharing Across the LAN" which doesn't make sense. If you're sharing files on the LAN, the DMZ will have nothing to do with that. The DMZ exposes your computer to the WAN not the LAN. You're already on the LAN.

You don't want to use DMZ unless you need to expose a computer to the Internet without the protection of a NAT router. If you do, you'll need to use a software firewall.

What exactly are you trying to do?
---
“The Government of Spain will not applaud those who set the world on fire just because they show up with a bucket.” - Prime Minister of Spain, Pedro Sánchez

Image
User avatar
Busby
Golden Member
Posts: 1890
Joined: Tue Nov 28, 2000 6:25 pm
Location: Atlanta Area, GA, USA
Contact:

Post by Busby »

I got ZA Integrity Desktop (through GA Tech).

By file sharing I mean WIndows File and Printer Sharing.

Basically I have a router hooked up to my net connection and my desktop and laptop on my router's LAN side. If my desktop is turned to be DMZ, will file sharing to my laptop be exposed to the net also?
<a href="mailto:busby1218@charter.net">
<img src="http://justinbusby.com:8080/signature.gif" border="0"></a>
User avatar
FlyingPenguin
Flightless Bird
Posts: 33161
Joined: Wed Nov 22, 2000 11:13 am
Location: Central Florida
Contact:

Post by FlyingPenguin »

If all your computers are connected to the LAN side of the router, then you can share files on the LAN - nothing to stop you.

Yes, if you put the desktop on the DMZ then someone could hack in via NETBIOS. As I said before it's not a good idea to put a computer on the DMZ unless you have to. If you do you want to use a firewall and configure it to block NETBIOS. You also want to password protect all network shared with strong passwords.

I still don't understand why you want to enable DMZ. You don't need it for local file sharing on the LAN.

If you're trying to share files across the WAN you can't easily do that over NETBIOS, and it certainly wouldn't be secure. You're better off using Remote Desktop, a VPN, or FTP Server.
---
“The Government of Spain will not applaud those who set the world on fire just because they show up with a bucket.” - Prime Minister of Spain, Pedro Sánchez

Image
User avatar
Busby
Golden Member
Posts: 1890
Joined: Tue Nov 28, 2000 6:25 pm
Location: Atlanta Area, GA, USA
Contact:

Post by Busby »

DMZ was for BT. But I figured out I can do port ranges on my port forwarding page so it's all good.
<a href="mailto:busby1218@charter.net">
<img src="http://justinbusby.com:8080/signature.gif" border="0"></a>
User avatar
ShibasScotch
Senior Member
Posts: 413
Joined: Mon Mar 11, 2002 12:44 am
Contact:

Post by ShibasScotch »

for BT i just set myself as DMZ when I use them, I tried to open the ports, but BT uses a range of like 100 or so, and it still didnt work nearly as well as when I was set to DMZ... Just dont leave it on !
Stupid people do stupid things, smart people outsmart each other, then themselves.
User avatar
Busby
Golden Member
Posts: 1890
Joined: Tue Nov 28, 2000 6:25 pm
Location: Atlanta Area, GA, USA
Contact:

Post by Busby »

I customize my ports to allow for a non-default operation. I personally think it's safer than going default.

It's working nicely now too (BT and File and Printer Sharing)
<a href="mailto:busby1218@charter.net">
<img src="http://justinbusby.com:8080/signature.gif" border="0"></a>
Post Reply