ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Home Network Setup

    Scheduled Pinned Locked Moved IT Discussion
    xpdhcpdnshome labxenserverkvmubiquitivirtualizationsophoslinuxuntangle
    88 Posts 14 Posters 15.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • black3dynamiteB
      black3dynamite @scottalanmiller
      last edited by

      @scottalanmiller said in Home Network Setup:

      Here is the alternate.... on a non-Windows network, I don't want DNS listing random dynamic guests. That's the simplest solution. Windows does something I have no desire to have. Given that I don't know what purpose it serves, it's hard to figure out what you are actually looking to accomplish.

      Windows DNS can be set to only allow secure dynamic updates, non secure dynamic updates, none. I think the default is secure dynamic updates.

      DashrenderD scottalanmillerS 2 Replies Last reply Reply Quote 0
      • DashrenderD
        Dashrender @scottalanmiller
        last edited by

        @scottalanmiller said in Home Network Setup:

        Problem with the AD assumption:

        1. It is never mentioned, at all. Not even hinted at.
        2. Replacing DNS and DHCP alone don't fix the need to replace AD, so don't solve the CAL issue as asked.

        NO - that is an assumption now on your part - I'm talking about using Windows Server to provide DHCP and DNS. Now granted - why in the world would you do this if you don't have AD, you wouldn't, so the chances are great that AD is being used for the Windows machines, but still not really relevant to the question.

        scottalanmillerS 1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller
          last edited by

          So, in the real world, where we work from business goals, we have two basic things we would do. Neither matches what is asked.

          1. Non-AD Network (the one we are dealing with here.) There is no value or purpose to DDNS in this scenario. You have no problem to solve. Simply remove the Windows servers and go to normal, everyday DHCP and DNS. Ubiquiti, Linux VMs, everything already handle this perfectly well. There is nothing for the industry to improve here.

          2. AD Network (not the scenario we are discussing.) External DNS and DHCP cannot handle the updates for this, this is a limitation of the architecture and is not related to Windows or Linux. In this case, AD itself, not DHCP, has to update DNS and in both Windows and Linux cases, does so automatically as DNS must be part of AD. This is all transparent and cannot be handled by external DNS servers. Linux via Samba4, the only way to get AD apart from Windows own AD, has both the DNS server and the AD-pushed updates to it all included in the same package, all working out of the box as it has to by definition in being an AD replacement. So in this scenario, there is nothing to change or configure and would be handled automatically when needed by the nature of having implemented AD.

          DashrenderD 1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender @black3dynamite
            last edited by

            @black3dynamite said in Home Network Setup:

            @scottalanmiller said in Home Network Setup:

            Here is the alternate.... on a non-Windows network, I don't want DNS listing random dynamic guests. That's the simplest solution. Windows does something I have no desire to have. Given that I don't know what purpose it serves, it's hard to figure out what you are actually looking to accomplish.

            Windows DNS can be set to only allow secure dynamic updates, non secure dynamic updates, none. I think the default is secure dynamic updates.

            We've dropped the dynamic update/DDNS from the discussion at this point, since Scott is calling it a red herring.

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @Dashrender
              last edited by

              @dashrender said in Home Network Setup:

              @scottalanmiller said in Home Network Setup:

              Problem with the AD assumption:

              1. It is never mentioned, at all. Not even hinted at.
              2. Replacing DNS and DHCP alone don't fix the need to replace AD, so don't solve the CAL issue as asked.

              NO - that is an assumption now on your part - I'm talking about using Windows Server to provide DHCP and DNS.

              If you are talking about that, then you already know your answer. Stop using them. Problem solved. Your question makes no sense without AD. It serves no purpose.

              1 Reply Last reply Reply Quote 0
              • DashrenderD
                Dashrender @scottalanmiller
                last edited by

                @scottalanmiller said in Home Network Setup:

                So, in the real world, where we work from business goals, we have two basic things we would do. Neither matches what is asked.

                1. Non-AD Network (the one we are dealing with here.) There is no value or purpose to DDNS in this scenario. You have no problem to solve. Simply remove the Windows servers and go to normal, everyday DHCP and DNS. Ubiquiti, Linux VMs, everything already handle this perfectly well. There is nothing for the industry to improve here.

                Well DDNS could have value if you want to manage your devices by name, not IP address, but otherwise - fine.

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @Dashrender
                  last edited by

                  @dashrender said in Home Network Setup:

                  @scottalanmiller said in Home Network Setup:

                  In a normal network, with scanners on DHCP, that isn't a Windows network, there is no such need as this, the very idea sounds so silly. Given that avoiding the Windows CALs here is automatic and the default, do you see why it's confusing that there is nothing to answer other than "don't do that?"

                  So you're saying the scanners go on their own network, and the windows laptop is on a separate network - so non issue, since the scanner network can use some other DHCP/DNS service that has no licensing fee?

                  I have no idea what you are talking about now. I've said nothing of the sort. There is zero need for the things you are asking for, there is no need for "different networks" or anything like that. Just stop trying to use DDNS and everything is fixed instantly.

                  1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @Dashrender
                    last edited by

                    @dashrender said in Home Network Setup:

                    @scottalanmiller said in Home Network Setup:

                    So, in the real world, where we work from business goals, we have two basic things we would do. Neither matches what is asked.

                    1. Non-AD Network (the one we are dealing with here.) There is no value or purpose to DDNS in this scenario. You have no problem to solve. Simply remove the Windows servers and go to normal, everyday DHCP and DNS. Ubiquiti, Linux VMs, everything already handle this perfectly well. There is nothing for the industry to improve here.

                    Well DDNS could have value if you want to manage your devices by name, not IP address, but otherwise - fine.

                    How would that work? What use case is there for that?

                    DashrenderD 1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller
                      last edited by

                      All this said, of course you can do it. It's just a silly thing to want and doesn't, AFAIK, serve any purpose. But here is a quick guide if you really wanted DHCP to do these updates for you.

                      http://www.semicomplete.com/articles/dynamic-dns-with-dhcp/

                      1 Reply Last reply Reply Quote 0
                      • black3dynamiteB
                        black3dynamite
                        last edited by

                        Help me understand, are we talking about allowing untrusted clients to update to the DNS server or not allow any clients to update to the DNS server?

                        scottalanmillerS DashrenderD 2 Replies Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @black3dynamite
                          last edited by

                          @black3dynamite said in Home Network Setup:

                          @scottalanmiller said in Home Network Setup:

                          Here is the alternate.... on a non-Windows network, I don't want DNS listing random dynamic guests. That's the simplest solution. Windows does something I have no desire to have. Given that I don't know what purpose it serves, it's hard to figure out what you are actually looking to accomplish.

                          Windows DNS can be set to only allow secure dynamic updates, non secure dynamic updates, none. I think the default is secure dynamic updates.

                          That's the other way around. The point is to update non-Windows DNS, not to update Windows DNS. The plan here is to remove all Windows Servers so that no CALs are needed.

                          1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @black3dynamite
                            last edited by

                            @black3dynamite said in Home Network Setup:

                            Help me understand, are we talking about allowing untrusted clients to update to the DNS server or not allow any clients to update to the DNS server?

                            We are talking about some unknown clients updating either BIND or Samba DNS.

                            1 Reply Last reply Reply Quote 0
                            • DashrenderD
                              Dashrender @scottalanmiller
                              last edited by

                              @scottalanmiller said in Home Network Setup:

                              @dashrender said in Home Network Setup:

                              @scottalanmiller said in Home Network Setup:

                              So, in the real world, where we work from business goals, we have two basic things we would do. Neither matches what is asked.

                              1. Non-AD Network (the one we are dealing with here.) There is no value or purpose to DDNS in this scenario. You have no problem to solve. Simply remove the Windows servers and go to normal, everyday DHCP and DNS. Ubiquiti, Linux VMs, everything already handle this perfectly well. There is nothing for the industry to improve here.

                              Well DDNS could have value if you want to manage your devices by name, not IP address, but otherwise - fine.

                              How would that work? What use case is there for that?

                              When I look at my Unifi controller, I like to see host names of my devices, not the mac addresses, because the mac is meaningless to me. So having the controller get the DNS name would be nice.. you don't see that?

                              scottalanmillerS 1 Reply Last reply Reply Quote 0
                              • DashrenderD
                                Dashrender @black3dynamite
                                last edited by

                                @black3dynamite said in Home Network Setup:

                                Help me understand, are we talking about allowing untrusted clients to update to the DNS server or not allow any clients to update to the DNS server?

                                OMG NO - we dropped the dymanic portion of this conversation 10 mins ago!

                                1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller @Dashrender
                                  last edited by

                                  @dashrender said in Home Network Setup:

                                  @scottalanmiller said in Home Network Setup:

                                  @dashrender said in Home Network Setup:

                                  @scottalanmiller said in Home Network Setup:

                                  So, in the real world, where we work from business goals, we have two basic things we would do. Neither matches what is asked.

                                  1. Non-AD Network (the one we are dealing with here.) There is no value or purpose to DDNS in this scenario. You have no problem to solve. Simply remove the Windows servers and go to normal, everyday DHCP and DNS. Ubiquiti, Linux VMs, everything already handle this perfectly well. There is nothing for the industry to improve here.

                                  Well DDNS could have value if you want to manage your devices by name, not IP address, but otherwise - fine.

                                  How would that work? What use case is there for that?

                                  When I look at my Unifi controller, I like to see host names of my devices, not the mac addresses, because the mac is meaningless to me. So having the controller get the DNS name would be nice.. you don't see that?

                                  Sort of, but it's a really trivial way to send false info.

                                  1 Reply Last reply Reply Quote 0
                                  • DashrenderD
                                    Dashrender
                                    last edited by

                                    The whole crux of my ask was - the desire to buy as few Windows Server CALs as possible.
                                    As has been stated here before - if a device uses any Windows Server Service, it must have a CAL. So if you use DHCP - you need a CAL, if you use DNS you need a CAL. - assuming that still holds

                                    The assumption - for Scott's sake - is you have Active Directory.

                                    My question is - you have a network of both windows clients and non windows clients. The non windows clients will never touch the Windows servers - go.

                                    So I can answer this myself - Scott will now say - put them on separate networks - done. Why done? because you need Windows CALs for all of the Windows users already, so you're covered.. and the non windows devices/users will use a non license requiring DHCP/DNS solution on it's own network.

                                    Yes damn that was a journey.

                                    scottalanmillerS 3 Replies Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller
                                      last edited by

                                      But, if you have a specific goal like this, when I ask for a goal, this is what you should say: "I spend enough time managing devices in Ubiquiti DHCP that I want to see hostnames there."

                                      Then I might question that goal, because that seems like a weird problem to want to solve, but you are talking about an actual goal in allowing you to see hostnames listed. Do you see, it's a final thing, it's something that you as a person want out of the system. Not a means to an end, it's an end. A weird end worth inviestigating, but an end.

                                      All of the questions to this point, all of them, were about "means" not "ends". They were all solutions to problems that weren't mentioned.

                                      1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @Dashrender
                                        last edited by

                                        @dashrender said in Home Network Setup:

                                        The whole crux of my ask was - the desire to buy as few Windows Server CALs as possible.

                                        This is unrelated to the question asked, though.

                                        DashrenderD jmooreJ 2 Replies Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller @Dashrender
                                          last edited by

                                          @dashrender said in Home Network Setup:

                                          My question is - you have a network of both windows clients and non windows clients. The non windows clients will never touch the Windows servers - go.

                                          Why would there be anything touching Windows Servers?

                                          1 Reply Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller @Dashrender
                                            last edited by

                                            @dashrender said in Home Network Setup:

                                            So I can answer this myself - Scott will now say - put them on separate networks - done. Why done? because you need Windows CALs for all of the Windows users already, so you're covered.. and the non windows devices/users will use a non license requiring DHCP/DNS solution on it's own network.

                                            If you really have a need for Windows servers for some things and not for others, then yes, this works. You can also do things like not use DHCP for those devices. DHCP and DNS, while often nice, are anything but required. There are cases, rare as the may be, to just skip them.

                                            But two networks might be better. Keep in mind that two networks might mean physically separate (like VLAN) for DHCP reasons, or overlapping on one with non-Windows DHCP and nothing else shared, or two subnets on one physical LAN.

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 3 / 5
                                            • First post
                                              Last post