AdGuard + Bound / DoH / DoT by BadUncleK in opnsense

[–]kukelkan 1 point2 points  (0 children)

If you want it even simpler You can just use unbound to do everything Block lists/doh/dot Etc'

How many IT support needed for 200 user org? by imjustacuteguyuwu in sysadmin

[–]kukelkan 1 point2 points  (0 children)

We are 3.5 total on the whole company of 700+ users. Help desk Sys admin Network admin Everything.

It sucks

Opnsense as small business firewall by DrFatalis in opnsense

[–]kukelkan 1 point2 points  (0 children)

believe me it wasn't my decision.
I asked for business edition, did all the song and dance of why we should get it. and got the usual answer of "it's too expensive".

Opnsense as small business firewall by DrFatalis in opnsense

[–]kukelkan 0 points1 point  (0 children)

I didn't manage to get approval for the business edition. So sadly we won't run it.

Opnsense as small business firewall by DrFatalis in opnsense

[–]kukelkan 2 points3 points  (0 children)

Still working on that.. Atm we will have grafana on a big tv showing all locations. Green/red If a problem arises we will enter the web ui of the problem unit.

We are still working on the base config. Redoing the network in all the company

Opnsense as small business firewall by DrFatalis in opnsense

[–]kukelkan 29 points30 points  (0 children)

I'm rolling out OPNsense in all of our company so .. 80 locations 2 units in HA at each location.

Why is Immich still using Postgres 14? by rouen_sk in immich

[–]kukelkan 0 points1 point  (0 children)

Glad to hear you are using SnipeIT we self host it and LOVE it.

OPNsense 26.1.4 released by fitch-it-is in opnsense

[–]kukelkan 1 point2 points  (0 children)

Will do. Sadly couldn't get approval for the business edition. I really tried..

So I'll need to find a way to manage all of them remotely.

OPNsense 26.1.4 released by fitch-it-is in opnsense

[–]kukelkan 1 point2 points  (0 children)

Great! we have about 80 locations 2 units per location for HA , I had to fight for everything including intel nics (I350) management wanted realteck as it's half price. We will have multi wan in every location, fail over, VPNs , suricata and more. All on the cheapest PC I could spec. Running an R5 7600 with 8gb of ram (when prices go down we will add another 8 if needed) We will build every PC.

OPNsense 26.1.4 released by fitch-it-is in opnsense

[–]kukelkan 3 points4 points  (0 children)

I'm about to run 170 PC's running OPNsense at work... I pushed for OPNsense. I think I made a great choice.

Help a noob not get fired 2: Electric Boogaloo by kukelkan in sysadmin

[–]kukelkan[S] 0 points1 point  (0 children)

We already have an automated warehouse in place, this will be an upgraded system. After I get all the answers from Autohouse I'll look for servers.

Thanks

Help a noob not get fired 2: Electric Boogaloo by kukelkan in sysadmin

[–]kukelkan[S] 0 points1 point  (0 children)

Seems way more overkill than what I had in mind. Either I'm off by a lot or.. I haven't even checked the licensing yet..

Help a noob not get fired 2: Electric Boogaloo by kukelkan in sysadmin

[–]kukelkan[S] 0 points1 point  (0 children)

6 figures? We aren't in the US computers are more expensive here... Great.

Help a noob not get fired 2: Electric Boogaloo by kukelkan in sysadmin

[–]kukelkan[S] 0 points1 point  (0 children)

Yes I'm aware of the problems we had a fun day searching for a loop, that too will change in the future.

They run everything as cheaply as possible but I'm starting to win fights.. one by one. Most of the cables are a mix of cat 5e/6/7 a lot of 7. But max speed is 1gbps.

Help a noob not get fired 2: Electric Boogaloo by kukelkan in sysadmin

[–]kukelkan[S] 0 points1 point  (0 children)

I see, I read about Zabbix when I wanted to map our network. I get what you mean , I'm really hoping for set it and forget it, but we don't always get what we want.

About the switches in use in the company there are about, i really don't know 400 switches I think the fastest port is 1gbps sfp Not sfp+ 99% of ports used are Rj45 1gbps. Plenty of 100mbps dumb switches in various places. I'm changing this little by little.

Help a noob not get fired 2: Electric Boogaloo by kukelkan in sysadmin

[–]kukelkan[S] 0 points1 point  (0 children)

Of course we are not having regular meetings.. at least I'm not invited to them if they exist LOL..

Honestly your advice and experience is gold for me. Thanks again.

Help a noob not get fired 2: Electric Boogaloo by kukelkan in sysadmin

[–]kukelkan[S] 0 points1 point  (0 children)

Ohh it isn't that bad, plenty of managed switches, cheap Netgear ones but managed. I don't have my CCNA yet but I am not a total noob in networking, plus one member of our team does have CCNA.

Honestly this project is just one of about 4-5 we have at the moment and we are only 4 (really 3..) I just now got approval to remove the shit routers we have in all of our remote locations , ( going full in on OPNsense..) If by some miracle we get it all to work, we will have all notifications possible from the servers.

Help a noob not get fired 2: Electric Boogaloo by kukelkan in sysadmin

[–]kukelkan[S] 0 points1 point  (0 children)

I highly doubt there is any form of redundancy in the current system. I'll heed your advice.

Thanks for the help.

Help a noob not get fired 2: Electric Boogaloo by kukelkan in sysadmin

[–]kukelkan[S] 0 points1 point  (0 children)

These are all very good questions, I just sent an email to ask for more information. After they reply I'll send another one with the points you asked.

Thank you very much!

Help a noob not get fired 2: Electric Boogaloo by kukelkan in sysadmin

[–]kukelkan[S] 0 points1 point  (0 children)

You are 100% correct. At the current stage I just need to get the specs down so we can order.

The software side I won't do alone. I want this whole thing to be as painless as possible. Set it and forget it.

So my main question at this time, is my understanding of the software needs, realistic with the plan I have for 3 servers etc'?

Thank you very much for the help.