Overview and question: Replacing current Netgate 6100 with Netgate 8200, fresh setup. Asking for clarification on our DNS setup with an added Active Directory network segment.
Packages Installed:
- All device updates
- PfblockerNG
- ARPWatch
- Patches
- Traffic Totals
- OpenVPN
Current Setup:
- Pretty much mirrors the 6100
- 4 VLAN Networks – Guest, VOIP, Camera, Main (Active Directory)
- DNS Resolver – General DNS setting pointing to Quad9
- DHCP Server – All DHCP configs have no explicit DNS setting with the exception of Main(Active Directory) network pointing to the domain controller.
- All VLAN traffic flow thru WAN4 (10G) interface
Firewall Rules:
- All non Main(Active Directory) networks have an Any rule, a DNS(53) rule and network blocking rules to stay contained
- Active Directory network only had an Any rule right now
Not sure to configure:
- DNS Resolver – Do I need Host or Domain override entries?
- DNS firewall rule on Main(Active Directory) network?
Pretty sure needs configured:
- DHCP Main(Active Directory) add DNS IP entry to point to domain controller server
- Domain Controller DNS Forwarder needs to point to PFSense
So basically since the 6100 was setup 2-3 years ago the only addition was the domain server and I made no changes to the 6100 so name resolution on the active directory isn’t working so want that corrected before I ship to them. If I missed something or not on the right track, let me know. Thanks