OpenLabsHackerspace / infracenter

A repo to collaborate on setting up a community datacenter @ OLH
1 stars 0 forks source link

Pfsense install #3

Open Klesti8701 opened 2 years ago

Klesti8701 commented 2 years ago

convert from the router provided by the ISP to a Pfsense router and manage the network.

kominoshja commented 2 years ago

pfsense is installed, but our modem didn't support bridge mode. I exchanged it at the ISP, and new one does. So far it's unauthenticated, going to OL tonight to check if it's fixed and leave it setup for @Klesti8701 to do LAN networking setup

kominoshja commented 2 years ago

I moved our new router to bridge mode and setup pfsense as the gateway on 192.168.1.1 (klesti will change, i propose 10.10.0.1/16)

Currently, the old white router (not from current ISP) is serving as an access point. We should add more pfsenses, preferably from thinkcenters (with wifi passthrough), so we can have HA

IMG_20220801_235316

As for DNS, right now we only use 1.1.1.1, but should use pfsense rules, then pihole, then 1.1.1.1

Klesti8701 commented 2 years ago

as something temporary i set it up to be like this image but as soon as we have all components in place we will configure specific Vlan's with dedicated ports for each network jan krijuar Vlans dhe config perkatese per to por duke qene se paisjet nuk jan vlan aware nuk po arrijm dot te marrim IP ose mund dhe te jete gabim i joni ne configs butt to be reviewed @Klesti8701 && @notaprodev

kominoshja commented 2 years ago

pls also setup: pfblocker-ng thinkcenter ap ha with pve3

Klesti8701 commented 2 years ago

this week we will set all this up since we got an other donation from @notaprodev a mikrotik that we will be using as a L3 switch and set up the VLans for the guest users and infra management VLan to be isolated form each other

kominoshja commented 2 years ago

Updatw: we're still having some issues on vlan setup. @Klesti8701 pls update here

Klesti8701 commented 2 years ago

Updatw: we're still having some issues on vlan setup. @Klesti8701 pls update here

in addition to the issue i set up the vlans in the mikrotik router on the interface eth1 (vlan infra {id 1} and vlan guest {id 2}) and bridged the interfaces 1(vlan ifra --eth3),2(vlan guest --eth4) once the mikrotik was setup it was time to make changes to pfsese and to connect the pfsense port (trunk) with mikrotik eth1 i set up the the vlans on the pfsese , crated 'opt' interfaces and linked them with the vlans but i was not getting connections .

kominoshja commented 2 years ago

For swtting up more APs: https://pimylifeup.com/raspberry-pi-wireless-access-point/