Skip to content
DnsLister Forum

Where domain hunters compare notes

INTEGRATING PFSENSE IN A ACTIVE DIRECTORY NETWORK

Hi everyone, how's it going? First, a bit of context. I'm not exactly an expert in network administration; all I have is a technical course in computer networking from high school that covered the basics—I learned the rest through trial and error. Recently, an acquaintance asked me to make some network improvements due to updates in Brazil's data protection laws (where I live). He owns a real estate registry office and wants me to implement a pfSense-based firewall on his network—and he's really set on this idea. His network setup is basically: PPPoE Link ---> DSL Modem ---> MikroTik ---> Switch ---> Hosts and an AD server. I've managed to configure everything in pfSense—rules, interfaces, DHCP, PPPoE—but that blasted AD server has been a huge headache for at least two weeks; no matter how much I research, I can't find a solution. This AD server acts as the local DNS, and I suspect it's set up as a forwarder rather than a resolver. Why am I unsure about the DNS type? Because I simply can't check the AD server directly. It was set up by someone else who holds the access credentials; for me to get access, my boss would have to pay, and he's incredibly stingy—so much so that the best computer here only has an 8th-gen i5 processor. My research suggests that a DNS resolver server is very expensive, at least where I live, and my boss claims he didn't pay for that—only for the AD setup. So far, my pfSense box connects to the internet and the domain; I can ping Cloudflare's 1.1.1.1, but I can't ping Google's 8.8.8.8, and DNS resolution isn't working either. I don't know if I should set pfSense as the resolver so the AD server forwards requests through it, or if that's already configured within Windows Server. Please help. Also, I apologize if this post is too long or contains unnecessary details; I just thought you needed context regarding the terrible conditions here :(Hi everyone, how's it going? First, a bit of context. I'm not exactly an expert in network administration; all I have is a technical course in computer networking from high school that covered the basics—I learned the rest through trial and error. Recently, an acquaintance asked me to make some network improvements due to updates in Brazil's data protection laws (where I live). He owns a real estate registry office and wants me to implement a pfSense-based firewall on his network—and he's really set on this idea. His network setup is basically: PPPoE Link ---> DSL Modem ---> MikroTik ---> Switch ---> Hosts and an AD server. I've managed to configure everything in pfSense—rules, interfaces, DHCP, PPPoE—but that blasted AD server has been a huge headache for at least two weeks; no matter how much I research, I can't find a solution. This AD server acts as the local DNS, and I suspect it's set up as a forwarder rather than a resolver. Why am I unsure about the DNS type? Because I simply can't check the AD server directly. It was set up by someone else who holds the access credentials; for me to get access, my boss would have to pay, and he's incredibly stingy—so much so that the best computer here only has an 8th-gen i5 processor. My research suggests that a DNS resolver server is very expensive, at least where I live, and my boss claims he didn't pay for that—only for the AD setup. So far, my pfSense box connects to the internet and the domain; I can ping Cloudflare's 1.1.1.1, but I can't ping Google's 8.8.8.8, and DNS resolution isn't working either. I don't know if I should set pfSense as the resolver so the AD server forwards requests through it, or if that's already configured within Windows Server. Please help. Also, I apologize if this post is too long or contains unnecessary details; I just thought you needed context regarding the terrible conditions here :( 

submitted by /u/Sensitive-Climate737 to r/PFSENSE
[link] [comments]

Source: r/PFSENSE · by /u/Sensitive-Climate737

Leave a Reply

Your email address will not be published. Required fields are marked *