NethServer Version: 7.8.2003
Module: Active Directory
I’m experiencing this issue with the active directory support, which creates nsdc container.
STR:
- starting with clean install of 7.8.2003
- run initial wizard on old UI
- run updates on new UI
- reboot
- install active directory
- click users in new UI
- choose active directory
- choose create new
- set IP to free address in MGMT vlan.
- ping nethserver (expected ping / got ping)
- ping ad.domain.com (expected ping / no ping)
My system is virtualised (QEMU/KVM) and I have read the remarks about virtualising bridge and promisc mode in manual. However, I am using virtual ethernet devices as my host device has SR-IOV compliant network adaptors.
I have tried a multitude of configurations:
conf1: using libvirt to set the vlan tag of the virtual ethernet device given to nethserver causes failure on installation of active directory components (nsdc i think), because I think there’s an unhandled error when enabling vlan filtering.
conf2: remove libvirt vlan tag. before installation of active directory, create eth.100, create br0 on eth.100.
conf3: remove libvirt vlan tag. before installation of active directory, create br0, enable vlan filtering, install active directory, configure vb-nsdc with pvid and vlan 100.
conf4: set the hosts PF connection to switch from trunk to vlan100, no libvirt vlan tag, install from fresh again (no vlan anything - so purely managed in physical switch)
in conf2-4 the installation is successful and with slight exception to conf3 (which I really struggled to figure out) I could also ping the AD form nethserver, but have never been able to ping the AD from any other machine. I have other devices in MGMT vlan which I can ping, and I can ping nethserver so don’t believe it’s routing issue.
I suspect I either need to do nasty manipulation of the internal switch of the hosts SR-IOV network adaptor OR something wrong in nethserver/my configurtion?
Shorewall/Firewall - I have tried shorewall clear
to drop all rules and open everything - but no progress.
I’m not using nethserver as an edge/internet router. I would just like a domain controller/dns/dhcp/ntp running internally. I’m using untangle on the edge.
Any help would be greatly appreciated.