ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Where do I start with replacing the whole MS AD stack

    Water Closet
    microsoft active directory ad dhcp dns
    8
    104
    8.8k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • black3dynamiteB
      black3dynamite @JaredBusch
      last edited by black3dynamite

      @JaredBusch said in Where do I start with replacing the whole MS AD stack:

      @Donahue said in Where do I start with replacing the whole MS AD stack:

      Apparently Fortigate wont let me create reservations outside of the lease pool. I even tried setting an excluded range, but it simply will not allow me to do it.

      I can either:

      • Get a different DHCP server
      • Abandon using reservations
      • Open the lease pool to the entire scope and live with the mixed results
      • Open the lease pool to the entire scope and create 254 dummy reservations to be edited later.

      My plan was to have 10.0.0.1/22 as my network, with the lease pool of 10.0.1.0 thru 10.0.3.254 and 10.0.0.2 thru 10.0.0.255 reserved for all these devices using reservations.

      • replace fortigate

      @Donahue Setup a DHCP/DNS VM and use VyOS, there is a awesome user guide for setting up DHCP and DNS.

      1 Reply Last reply Reply Quote 0
      • Emad RE
        Emad R @JaredBusch
        last edited by

        @JaredBusch

        For me this works and it is simple and not tied to anything but single Linux VM machine:

        https://docs.saltstack.com/en/latest/ref/states/all/salt.states.win_lgpo.html

        You dont even need to backup the VM, just remeber its IP cause if it fails, recreate a new one and it will receive requests on the same IP, you can make setting to auto accept keys and back it will accept all those clients and you can start controlling them again.

        1 Reply Last reply Reply Quote 0
        • DonahueD
          Donahue
          last edited by

          thanks for the info guys, I will take a look. I like the idea of using a VM.

          1 Reply Last reply Reply Quote 1
          • Emad RE
            Emad R @Donahue
            last edited by

            @Donahue said in Where do I start with replacing the whole MS AD stack:

            sing reservations.

            I think your knowledge of FG is not allowing you to do this, just create a new interface with the desired subnet and leave or tick DHCP option. And they you can do it what you want with it. Create an IPv4 policy to give access to internet to the new interface.

            1 Reply Last reply Reply Quote 0
            • 1
            • 2
            • 3
            • 4
            • 5
            • 6
            • 6 / 6
            • First post
              Last post