Thank you for your reply.
I'm aiming for the setup described here
http://en.wikipedia.org/wiki/Demilitarized_zone_%28computing%29 . The
XP PC is the web layer while the Windows 7 PC is the application
layer. Both have firewalls. Also, the XP PC is supposed to only
access files on the shared folder of the Windows 7 PC. Those files
are less sensitive and call files on unshared folders on the Windows 7
PC.
I'm new to this so maybe setting the HW firewall up properly is the
trick. I told Mr. Rabbit what I have on my router. That is:
The PCs are connected through a Linksys router with an SPI firewall.
The available Internet filters are
- Filter anonymous Internet requests
- Filter multicast
- Filter Internet NA redirection
- Filter Indet (Port 113)
It can also block the following applications: NDS, ping, gttp, https,
ftp, pop, imap, nntp, telnet, shmp, tftp and IKE.
Would the correct settings there work?
I've been reading about VPNs. They seem to be mainly for tunneling to
remote locations but could conceivably be used between computers. The
important thing is that I want the web server to be accessible from
the Internet and to be able to call php and html scripts from the app.
server. But I do not want hackers to be able to access code on the
app. server. If they could access code on the shared folders, that
would not necessarily be a problem. But if they could access files in
the unshared folders it definitely would.
Seems VPNs need ceritficates and/or passwords to access the target
site. If they could be sent from the web server then it seems that
hackers could get them from the web server.
Thanks,
Peter.
Yep, its all or nothing with windows :)
> That
> does not seem very secure. I'm not so much worried about hackers
> getting access to the shared directory as long as they cannot access
> unshared directories on the same PC.
>
> Thanks,
> Peter.
>
Encrypt any files you dont want shared. One other idea: try a p2p program
to share files.
<http://compnetworking.about.com/od/p2ppeertopeer/tp/p2pfilesharing.htm>
--
http://www.skepticalscience.com/
Thank you for your help. At this point I have installed Ubuntu on
both PCs and am trying that route.