Instead of messing about with subnets etc, is it easier to set up a secondary internal network with another router on secondary network cards.
IE:
Internet-router-switch- computer (network 1 for net access only)
Router-Nas/computers (network 2)
All machines have two network cards.
This ensures all internal data/Nas etc is not accessible via the internet connection and the Internet connection is solely for Internet.
IE:
Internet-router-switch- computer (network 1 for net access only)
Router-Nas/computers (network 2)
All machines have two network cards.
This ensures all internal data/Nas etc is not accessible via the internet connection and the Internet connection is solely for Internet.