• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Segmenting network

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    Segmenting network

    I need to segment my network for security reasons (PCI compliance).

    I have an adsl incoming connection.

    A chip and pin card machine which uses a LAN port

    A couple of desktop pcs with LAN cards

    A couple of laptops using wireless

    An android tablet using wireless

    An iphone and ipad.

    I just need to separate the chip n pin machine from everything else.


    Any suggestions as to kit to buy? I'm not a numpty, but I'm also not a network specialist.

    (FYI I've currently been using a juniper netscreen, but I've hit problems, first the ios devices will not connect through it, and now the latest software update to my chip n pin machine has stopped it working through the juniper. I can't update the juniper firmware as I don't have a contract with them. Replacement juniper kit looks ruinously expensive and very complicated to program)

    Thanks
    Last edited by Archangel; 15 October 2014, 20:09.

    #2
    I have an Asus Dark Night (RT-N66) which can do a guest wifi network on a separate SSID. All hosts on the guest network are isolated from local systems but can still access the internet. So you could get one of those, stick the chip & pin machine on the guest network and everything else on the normal wifi.

    Not sure how it goes for PCI compliance as I think the guest wifi is on the same subnet as the rest but it uses Linux ebtables (layer 2 firewalling) to segregate the guest hosts. Not entirely clear what you need for chip & pin machines.

    Comment


      #3
      Thanks smatty, but the chip n pin is via a LAN cable, not wireless.

      Perhaps a router which can isolate one LAN port from all others would do it, but don't know where to start searching

      Comment


        #4
        Which sort of Juniper do you have. I am using an SSG5 to segment my home network. I previously used an 5GT ADSL to run two different segments.
        SUFTUM

        May life give you what you need, rather than what you want....

        Comment


          #5
          There are a few SOHO DSL routers with VLAN support which would let you segregate wired ports. Something like a Draytek Vigor, Cisco small business router (e.g. 107), Billion make a few, so do Netgear.

          Comment


            #6
            Originally posted by Netraider View Post
            Which sort of Juniper do you have. I am using an SSG5 to segment my home network. I previously used an 5GT ADSL to run two different segments.
            It's a netscreen 5gt

            I'll look into the ssg5, thanks

            Comment


              #7
              Originally posted by smatty View Post
              There are a few SOHO DSL routers with VLAN support which would let you segregate wired ports. Something like a Draytek Vigor, Cisco small business router (e.g. 107), Billion make a few, so do Netgear.
              I'll have a google for those thanks

              Comment


                #8
                we have just had to do a roll out of chip n pin devices across our whole estate and we went with 2g/3g type devices.

                where there was no coverage we put a dedicated bt line in.

                The idea behind all this was that none of the card payment data went through any of our wan/lan/networks and so we got around any PCI compliance things

                So, I think, even if you separate the traffic from the rest of your network because it is still using your network pci compliance is still an issue.

                I am aware though that the pci compliance challenges are different depending on the size of your business etc so as a small outfit you may find it is quite easy to ensure you are compliant.

                Comment


                  #9
                  Update: I bought a billion 7800dxl. Installed in 5 mins, segmented using vlans. Fab bit of kit for £135.

                  Comment

                  Working...
                  X