Hi Dan
And welcome to the Nethserver community!
If another router / firewall is handling routing (Like I use for my clients) AND you have a seperate subnet for clients (Set on that “other” router), then there’s no way NethServer can “know” about that network, unless you set stuff like “Trusted Networks”.
In a typical SME environment, there are usually No subnets for clients, clients and servers are usually in the same subnet. And larger environments are not really the scope of NethServer, which is dedicated to SME environments.
With 35+ years in the business, and operating in SME and in enterprise classs environments, I tend to agree. If less than 20 clients, additional subnets for clients are overkill. Sure, some specialized “service” companies may need more, but then the know-how is usually available to handle these. A typical SME will not have a dedicated IT department, and usually the know how level is lower than in an enterprise environment, where such departments are available.
My typical environment for my clients:
- All servers virtualized under Proxmox.
- Backup to NAS, additionally most clients use PBS for Proxmox Backups.
- Backups (including PBS) are also available Offsite
- Routing / Firewalling is done by a dedicated OPNsense box (not virtualized).
- NethServer provides: AD, File, Print, Mail, Nextcloud, Zabbix Monitoring (and more, sometimes…)
- Additional servers, eg ERP systems, are usually “Member Servers” in NethServers AD.
Some examples of actual clients:
Another last tip:
Please avoid using stupid, outdated concepts like using .local or .lan as your local domain. Even Microsoft, which did suggest such stupid stuff before 2000(!) has for at least 10 years now suggested using a subdomain of a “real” DNS Internet Domain.
The big advantage: Using a LetsEncrypt “valid” certificate for your AD becomes really easy!
And this makes using certain JAVA or PHP apps with AD authentification easy.
If you have further questions, don’t hesitate to ask here, our motto here is:
The only stupid questions are the ones not asked…

My 2 cents
Andy