Current solution in place:
A proxy server filters http/https requests - there is no way for a xls|doc|exe|zip|jar|cab to be downloaded from the Internet via web browsers (unless someone edits their network settings *1)
Each computer has a software firewall, such as WinXP firewall or something equally user-friendly. I do not want user-error to risk disrupting the use of 'critical' networked software.
There is one broadband connection, currently on the proxy, but not all computers have a physical connection to it which is why I want to swap to WiFi.
If I have a WiFi NAT router, with broadband on one side, and the proxy on the other then it looks like this:
NAT <--> Proxy <--> Workgroup #1
NAT <--> Workgroup #2
*1) I tried NT/2K/XP port forwarding but it does not seem to do anything - at all! How can I
force ?:80 connections to go through
*2) What about POP3 downloads: maybe I should block them and insist on using webmail?
*3) Putting ICS on the proxy works..
Internet <--> NAT + Proxy <--> WiFi <--> Workgroups
.. but, that is not a hardware firewall and putting a complete PC so close to the
user errors = risk
--Glen
Memoria mihi benigna erit qui eam perscribam