• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Active Directory server in cloud with clients and pFsense on prem?

Scheduled Pinned Locked Moved DHCP and DNS
activedirectorydomaindns
2 Posts 2 Posters 630 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    jgq85
    last edited by May 22, 2021, 11:38 PM

    Some employees in office are having to move to different buildings so I’m trying to plan how they can still remain in Active Directory. Current building a Domain Controller is on prem on the same network as them. The site the employees are moving to doesn’t have a DC but does have a pFsense.
    My thinking is, if I have a DC hosted as a VM in Azure already, then could I just have an IPSec tunnel from the pFsense to Azure, and the clients point to the IP of the DC in Azure, would that work? If so would I have to put in a DNS host override for the “company.AD.domain.com” to also point to the same IP? And as far as DHCP, pFsense would be employees DHCP server?

    K 1 Reply Last reply May 23, 2021, 3:20 PM Reply Quote 0
    • K
      KOM @jgq85
      last edited by May 23, 2021, 3:20 PM

      @jgq85 I think that will work but it's always best to have Windows do your DNS and DHCP if your clients are using AD. Just use pfSense as a routing firewall and VPN remote site. Are you looking to move the existing building DC somewhere else? Otherwise I don't know why you wouldn't just connect the new building to the old one and the clients use the same old DC they always did with the least amount of disruption.

      1 Reply Last reply Reply Quote 0
      2 out of 2
      • First post
        2/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received