Currently, my Omnia is exposing Samba shares meant for the interface lan (192.168.1.1) on work-lan (192.168.2.1).
I’ve modified smb.conf.template to make it listen only on 192.168.1.1 but that doesn’t help, since someone like 192.168.2.100 can still access 192.168.1.1 and all its ports.
Is there a way to wall off everything except the necessary minimum on work-lan? Perhaps a custom firewall rule?
Thanks. While that’ll work for samba, I’m really looking for a more general mechanism that bars access to 192.168.1.1 from 192.168.2/24. Then I can stop relying on the security mechanisms of each service.