Yahoo Answers is shutting down on May 4th, 2021 (Eastern Time) and beginning April 20th, 2021 (Eastern Time) the Yahoo Answers website will be in read-only mode. There will be no changes to other Yahoo properties or services, or your Yahoo account. You can find more information about the Yahoo Answers shutdown and how to download your data on this help page.
Trending News
I need suggestions on how to REDO my home Network.?
BTW I'm a network administrator who deals with Cisco ASA, Cisco Switches, etc Linux, XP, Win 7, Domain, Active Directory, and the like. I am very experienced just want to know what some other network admins do for their home networks using equipment that is either middle size business class or maybe even lower end Enterprise level. My budget is probably going to be around 300 total.
Currently this is my setup: I have a 20MB synchronous WAN connection to the internet. This is a Fiber to the Home setup, my ISP's external box drops the connection to a 100MB speed for LAN. This comes into my home to a WRT54GL (original Linux Firmware), I have G wireless setup on the router with a hidden SSID authenticating with WPA2, this provides for my numerous wireless devices and a few hard wired items: one printer, 2 phones, 4 mac's, 3 windows laptops, 2 desktops, XBOX, Sony BlueRay Player, 2 apple TVS, and 1 linux server. the Linux server is hardwired as is the XBOX. In my bonus room of my home I have a port which is split with a switch, this is where i run my side business of computer repair so i can connect multiple computers for repair work. In the router I have qos setup for the XBOX for MW3, everything else can tier behind that, although im considering tiering my server as second. I have dyndns setup on the current router for server access, and port 22 is open for ssh. I also have my mac pro in the application/port forward nat, but it is turned off, when i need access to my mac outside i tunnel video over port 22 to my server and turn on the nat option through the browser on my server just while im using it then turn it off. I have been searching and hesitant for the past year because all my mac's support N wireless and I also wanted to be able to use the speed of G networking for copying of large movie files across the network, but haven't because none have met my standards. then research ive done indicated even if i have an N router it will drop to the speed of the slowest device on your network. I do have a gig card to install in my linux box which i have not yet done. I also plan on moving my dnydns login info away from the router and instead to the linux server via the dyndns daemon since the new GAMER N routers have issues with dyndns because of their faster processors and horrible quality control and testing before releasing these devices to the public. What I would like to do is get a GIG managed router(non wireless) and setup natting for my different devices. Then Im going to plug the G router into that, and buy an N router and plug into it as well, then Ill have a G network and an N network with different SSID's to seperate them. So what devices can you guys suggest for N routers acting as stated above, and a managed gigabit switch which has dhcp, qos and nat'ing support., since my server and xbox will directly attach to this router I would like for it to have a (gaming processor or something comparable to like the Linksys e4500 or so) and needs to be backwards compatible to 100mbps since the XBOX is 100mb only.
I should also note, yes 22 is open to the internet. I do however have Parental controls setup to block internet to the server from about 11:30 pm until 7 am. then it opens back up. I occasionally do get hack attempts but reviewing all my ssh logs no one has ever gotten in, my password is very long and is a mix of upper, and lower alpha, numbers, and symbols, not that it is fool proof, now with gpu scanners, passwords have been obsolete for the past 15 years yet no one wants to change anything. anyway i digress, I had tried playing around with iptables to try and get my linux box to auto black after 3 unsuccessful ssh attempts but i never got it to work correctly im not an iptables expert. What i was saying was that my wrt54gl is the router/dhcp for my network now. So what you are saying is i need to purchase a router and a switch to accomplish what i want to do. I dont want to use the wrt54gl to be the link between my ISP and other devices because i want my XBOX to have less lag. curre
Well i think i have decided I am going to do what i suggested above with buying an N with gig ports and just adding my G router to it. I have decided on a Zyxel NBG5715
1 Answer
- AdrianLv 79 years agoFavorite Answer
Wow, that is a mouthful...
First of all, I would suggest closing port 22 if it is open to the internet. Use some form of PAT. That is, use a user selected port on the WAN side, like 22122 (or whatever), and translate that to an internal port 22. There are so many hackers probing port 22....
As for switch, I use the Netgear 24 port gigabit switch (GS724T). While it has Qos, SNMP and NTP services, it does not have a DHCP server - it can't since it is a switch not a router. Your router should assign IP anyway. Same for NAT - if you have routers, they should be doing NAT (at least for home systems)
This switch is "semi-managed", so it sells for less than $200. It also supports link aggregation, its own VLAN between ports, CoS (variant of QoS) and DoS controls. Read the manual and decide for yourself...
As for the rest I'll let others answer. I use a Linux firewall at the front end, and split a subnet from that into various other routers (various wireless) and subsequent subnets. The Linux firewall does all the NAT, PAT and content filtering (hacker probes) with automatic blacklisting of detected hack attempts (including port 22 attempts)