A NethSecurity 8 Installation Attempt

Hi everyone,

As always a very interesting discussion.

I’ve been a loyal NethServer user for many years and I really liked the old integration in NS7 (and previous versions), VPN’s/Firewall/Mail/Web all in one server.

I’ve been using the NethSecurity software for almost a year, and overall it’s “okay”.
WAN fall-over recovery is still a bit hit and miss, especially with 4G modems. OpenVPN works well, CrowdSec causes me quite a bit of grief as many NZ sites get blacklisted, so I have to run it in a very dumb down way (and white list a lot of sites). I really miss my fail2ban.

Andy was nice enough to chat to me regarding his setup at 1am in the morning (his time) and show me his setup via AnyDesk .Overall I was very impressed at how unifi has become an enterprise ready product. One of the biggest issues I have is the NethSecurity AD paid integration. As this is in euros, it’s actually cheaper for me to move to a unifi gateway controller/cloud gateway configuration than pay a yearly subscription for the open source NethSecurity. I can purchase a new Ubiquiti UDM-Pro 1U Rackmount 10Gbps UniFi Multi-Application System for the same price as the hardware cost and one year license of NethSecurity, and then the cloud gateways are priced at around half the cost of the yearly subscription (and I don’t have to spend four hours setting up each box, with VPN tunnels/manually adding VPN users etc).

A big plus with unifi is that everything meshes (as Andy demonstrated with his setup) and central control of multiple locations is really simple. I know unifi are the big boys, but as they don’t charge for AD integration on a yearly subscription, it’s actually more reliable,easier for users, and cheaper for me to move away from NethSecurity (plus I get real time network traffic monitoring/device status). I’ll still keep an eye out to see where NethSecurity ends up, but right now it’s no longer a “good” solution for the businesses I look after.

Have a great day and thanks for reading :slight_smile:

Another over fifty IT geek.

4 Likes

Salut @Turbond

As a firewall, I have a UniFi UCG Ultra and very happy with it.
At $150 USD, I bought 2: one to install and one for testing all the possible parameters.

UniFi OS is out since quite a few years and very stable.
No subscription and no strings attached.
It just works.

Thank you @Capote and @Andy_Wismer

Server => Proxmox VE, ISPconfig running on a Debian VM.
It has all what NS-7.9 had and even more…

The very best thing about NethServer is this forum and its people.

Michel-André

3 Likes

Thanks for this feedback my colleagues will take it into account

I have also been using Unifi Cloud Gateway Ultra for some time now and have taken my OPNsense out of service.

Besides the acquisition costs of 99 EUR, I had maybe 2-3 hours of real administration work.

  • Configuring the DHCP server

  • Setting up LAN with 2 vlans

  • Setting up 2 Wifis

  • AD integration

  • Setting up WireGurad-VPN

The rest of the time, I kept an almost childlike eye out for anything to do and watched the data stream.

There is simply nothing to do.

In the meantime, I replaced my access points and switches out of pure enthusiasm.

Plug it in, wait (for the automatic setup) , use.

It’s almost too good to be true.

3 Likes