The server-workstation runs on 10.0.0.1 IP range. The 3 workstations that
have the 2nd network adapter communicate on the 192.168.0.1 IP range. The
gateway settings on the primary network adapter for these 3 workstations are
blank. Therefore it forces these computers to search for the internet via
the 2nd network adapter. Now that you have the whole picture let me ask a
few questions:
1) are the other workstations without a secondary network adapter safe from
internet associated risks? They can't directly access the internet but are
connected via the primary adapter to the 3 workstations that do access the
internet via their secondary adapter.
2)"internet sharing option" --- is this nothing more than a computer acting
as a server providing DHCP & DNS. If so, if this ICS host connects to 2
other computers via a router would I then have to disable the DHCP & DNS on
the router?
3)since the server and the ICS are on 2 different IP ranges will I still
have a conflict? Can the DHCP & DNS be disabled on the ICS host so the other
2 workstations would only point via gateway to the internet?
Thanks,
Mike
1) The other workstations can't be attacked directly from the
Internet, but they're not completely safe. If an Internet-connected
computer becomes infected with a worm, it could try to send that worm
to the other workstations via their primary network adapters. For
that reason, the other workstations need a firewall program.
2) Besides running DHCP and DNS servers, the ICS host also acts as a
NAT router to give Internet access to other computers. So it works
very much like a hardware router. In your setup, you should use the
hardware router as a network switch or access point only, not as a
router: disable DHCP and DNS, and connect the ICS host computer to one
of the hardware router's LAN ports.
3) There's no supported way to disable DHCP and DNS on the ICS host.
There's an un-supported way, but it might cause other networking
problems, and I don't recommend it: changing the ICS hosts' LAN
adapter to a subnet other than 192.168.0.x.
--
Best Wishes,
Steve Winograd, MS-MVP (Windows Desktop Experience)
Microsoft Most Valuable Professional Program
http://mvp.support.microsoft.com