I want to add a Orange network to my Nethserver for different public services in the future.
If i add an Orange Network in pfsense where I will put the services ?
If the services are going to run on NethServer, you don’t need another (orange) network.
Even with only one NIC, no specifically installed firewall - NethServer always has a firewall up and running, and is well capable of protecting itself - out of the box, I must add!
IMVHO (and maybe you don’t agree with my opinion, it’s fine) ORANGE zone is used in NethServer only if you are using the Nethserver installation as gateway/firewall, and you put into ORANGE zone some other servers which should be accessed by internet and by GREEN/LAN following the firewall rules written into nethserver.
If you want to expose to internet Nethserver’s future and different services… you should add to NethServer a RED interface. Which will be connected to the ORANGE interface of your PFSense.
This will allow you to have different firewall zones to manage, and you can tune different rules on PFSense to stratify protecion and rules, if necessary.
NethServer will use its RED(ORANGE) interface to connect to internet, instead of the gateway of the GREEN interface.
IMVHO this solution could work for your request, and due to your current arrangement, connection between PFSense and NethServer could be routed via virtual adapters and switches (by ProxMox perspective).
Of course, there are more ways to do the same thing… hope that this one at least makes sense to you, even you won’t realize like that
I now understand what you meant and I agree with you.
I thought about it last night and came across the same solution.
Thank you for explaining it to me. I tick it as solution.
Hello Andy
Now I don’t know what to choose. Maybe " Pluralitas non est ponenda sine necessitate" as said Frater Occam.
good day, I have a doubt; in the orange interface I connect my mikrotik firewall but from that interface I can connect to the domain to authenticate users and shared folders from other networks that my mikrotik firewall manages