Link to home
Start Free TrialLog in
Avatar of rastafaray
rastafarayFlag for United States of America

asked on

how to isolate an admin access to only 1 server

we have 1 win 2003 server that is not a part of the domain.  but its in the same IP range.
DMZ is not an option for us, but we would prefer it that when the user (a/local admin previligdes) logs in, that they do not see any other node on the same network, wether its thru shares (private or otherwsie) or even ping the other nodes.

in a nut-shell we want this 1 server to be isolated.

is this possible?
Avatar of ByteSleuth
ByteSleuth
Flag of Germany image

Hello,

you can use W2k8 for this, disallow network browsing via policy . I dont now exactly if this works for W2k3 too.

bytesleuth
Hello,

What is this server doing? Disabling File and Printer Sharing would take care of that, but it would also disable all shares too.

Disabling NetBIOS over TCP/IP will make the server difficult to find on the LAN.
Placing the server in a different WORKGROUP will stop casual browsing through My Network Places/Network Neighborhood.
Firewall exceptions, or the lack therof, will have the machine not respond to PING packets.
ASKER CERTIFIED SOLUTION
Avatar of aleghart
aleghart
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of rastafaray

ASKER

thank you for the diagram