protecting home network from users (and users from themselves)

ReelConfuzed

Distinguished
Jan 26, 2012
4
0
18,510
I am looking to increase my home network security. while I am very cautious, my sister seems to always have a virus on her system, without having any clue as to the severity/risk presented. The multitude of wifi devices which only makes matters worse.

I am looking for a way to protect myself from them, and I am also hoping I can find a way to guard the network to prevent them from downloading bogus software & malware, or at least make sure virus scans/etc. are up to date. going to each individual pc is not something I have time for.

current topology: modem-->wifi router-->network

the modem only has one port. I may be able to use a secondary router as a bridge for the wifi traffic, but I don't think this buys me anything. it would be nice to be able to share media across the network without worrying.
my router is a fairly new tp-link model.

a hardware firewall is probably out of range at this point.
we basically have 4 users on 6 pc's, 4 phones, several ipods, 2 wifi printers.

thank you to all who can reply and give some insight!
 
Solution
First...your sister apparently has admin rights on that PC, which allows her to install stuff, including viruses. Change that.
Given admin/install rights, there is not much you can do besides fix the user....;)

But...A hardware firewall can be done for $50 + brain power + 24/7 electricity. Seriously.

A semi-broken PC from craigslist, a Linux firewall appliance, a little understanding, and off you go.
Currently (and for the last few years), I'm running untangle on my border protection box. Sitting on a derelict Compaq box I got from some dude on craigslist. Add a cheap 10/100/1000 ethernet card, and all is well. Does not have to be a uber-powerful machine.

Play with it, and you can tweak the settings as much as you like. If you...

USAFRet

Titan
Moderator
First...your sister apparently has admin rights on that PC, which allows her to install stuff, including viruses. Change that.
Given admin/install rights, there is not much you can do besides fix the user....;)

But...A hardware firewall can be done for $50 + brain power + 24/7 electricity. Seriously.

A semi-broken PC from craigslist, a Linux firewall appliance, a little understanding, and off you go.
Currently (and for the last few years), I'm running untangle on my border protection box. Sitting on a derelict Compaq box I got from some dude on craigslist. Add a cheap 10/100/1000 ethernet card, and all is well. Does not have to be a uber-powerful machine.

Play with it, and you can tweak the settings as much as you like. If you select a site or download it doesn't like...you cannot pass unless you give it the password.

My network is thus:
Modem/router -> untangle box -> switches -> devices.
Everything gets run through the firewall box. If it doesn't like it....too bad. No soup for you.
Running WiFi through that would be a bit harder, but not extremely so.
 
Solution