Hello everyone,
I am looking to do exactly what kmm12115 asked about, but no one answered. Is this too hard to do? Or too easy, so no one bothered to reply?
I want to keep the Windows Server 2003 completely off the web, while every work station attached to it can go freely online.
The solution we are trying now is to have the server on a stand-alone router which is not connected to the web. There are two network cards in all the work stations, with one card connected to the server's router, and the other connected to the internet access router. But this has introduced a problem: the work stations have ended up with intermittent access to the web. This is happening even though each router does assign a non-conflicting set of IP's (Server router range is from 192.168.2.100 to 192.168.2.125, and the internet router from 192.168.1.100 to 192.168.1.125).
Because this method introduced the problem of intermittent web access, I'm looking for a simpler answer.
Some ideas I've considered include going back to one router, setting a fixed IP for the server, and then blocking web access through the web router. I've also thought about going back to one router and using a firewall program to block all internet traffic on the server.
One other idea I have to fix this would be to downgrade the stand-alone router the server is connected to, installing a stand-alone network switch instead, and assigning each network card attached to it a fixed IP address.
But would doing that perhaps make the server accessible to hacking through a work station? And maybe all of these ideas do that? At least the stand-alone router has a firewall, but having two routers where one does not have internet access is interfering with the web connection somehow. I had expected Windows to be a little smarter about recognizing which LAN card has internet access, and to automatically use that, but no ...
By the way, the work stations all have either Windows XP Home Edition or Vista Home Premium, all up-to-date with the latest Service Packs, etc.
Anyway, help! What is the best way to go?