I assumed that nethsecurity has AD users for vpn
OPNsense can do AD and has the bells & whistles he requires, which it seems NethSecurity does not.
Like you, Iām not yet capable of mind reading, and much less over distancesā¦
And as @Gordo hasnāt replied, all of this is pure speculationā¦
My 2 cents
Andy
Read my original post.
Hi @Gordo
Reading your original post, I do not see WHAT will not work with just NS8 and OPNsense.
AFAIK, your list is fulfilled. (Iāve added to your list with the components NS8 or OPNsense which can do the trick).
- Gateway (OPNsense)
- Firewall with Intrusion detecting and Packet Inspection (OPNsense)
- Mail Server (NS8)
- Samba Server (NS8)
- Samba Domain Controller (NS8)
- VPN Server (Openvpn) (Authenticates against Samba DC) (OPNxense)
- NextCloud Server (Authenticates against Samba DC) (NS8)
- Web Proxy Server (OPNsense)
Yes, OpenVPN and Squid can both run on OPNsense and BOTH can support using AD users from NS8.
(In case youāre not aware of it, OPNsense can use AD - AD in NS7 or NS8 just needs a valid SSL cert, easily doable with LE.)
Reading this, I would assume you have the necessary capabilities / know-how:
but this statement
speaks the contrary.
I can not speak (yet) for NethSecurity, as I do not use / needed the firewall component of NS7 (I use OPNsense) and I have not yet tested NethSecurity, as this was not something urgent I needed.
Reading this, If youāre prepared to use three boxes instead of one or two means that the one box criteria is not that importantā¦
If you would like to discuss anything of the above and actually get to see a route to get your system using NS8, feel free to contact me with a PM (or Telegram) and Iāll see you up to speed. You wonāt be the first Iāve helpedā¦
But of course youāre still free to use the platform so badly concepted that they are already changeing their platform base - moving from FreeBSD to Linux, after championing BSD for so long. Yes, I do mean TrueNAS. (I was a longtime user of FreeNAS).
My offer stands.
My 2 cents
Andy
Note:
Iām assuming the following:
- our level of know-how are fairly similar
- we both speak english (I can also speak German and French, if that helps)
- We have less than 10 years age difference.
Iām confidant we can find a solutionā¦
Sorry I have been unable to answer up until now.
The day after my last post I lost my Internet, I finally got it back day before yesterday. There was a āfaultā in the āOld Telephone Cableā that forms the last 600Metres of my connection. I wont go into why the system is like it is, but it was a change in policy after a change of Government.
So, now I can around to building my Opnsense Gateway, and getting that configured and up and running.
Then I can make the choice of which way I go behind that Gateway, whether itās NS8 ot TrueNas (and I do know the history behind the move from FreeNas to TrueNas. From a Modified OS Distro to a Docker Style Server which can be Hosted on virtually ant flavor of Linux).
I have yet to catch up with the latest improvements in NS8.
Will probably look at that tomorrow.