occsean
Active Member
- Reaction score
- 127
- Location
- Oregon City, OR
I posted in here a few months ago to get some ground rule ideas and got some great feedback. I have a small accounting firm I support that will be moving to a new office next month and I am charged with setting up the network. A very very long time ago I used to do this kind of work but it has been many years so I've had to do a ton of reading, asking questions, etc. It's been great to learn new stuff. I think I have it dialed in for this set up but wanted to take this opportunity to present it to my more knowledgeable peers and see if my thought process makes sense and passes the litmus test.
There will be a total for now of 7 users. 2 of them are partner members and 5 are staffers. There is no server. Light file sharing is being done via a 2TB RAID 1 NAS which also houses full image backups of the partner machines. The NAS has an external 2.5" 2TB USB drive backing it up and is rotated weekly offsite
ISP--Comcast 50/15 modem purchased by me. Arris SB6183
UTM--NexGen NG-Mini with Untangle FW Complete 25 devices..UTM will have static IP on exernal interface
Unifi 24 port POE managed switch (US-24-250w) which will have two VLANS for the AP
Unfi Lite AP connected via POE
24 port patch panel already in place--18 drops throughout office
NAS into switch on same LAN
Rest of network will be workstations and shared wired printers/MFD's
Unifi cloud controller connected directly to switch
AP will have two LAN's:
One for employees personal devices with no access to network resources like NAS or workstations
One for guests on a different subnet than other LAN's
OPEN VPN module on UTM will be used to provide RDP for partners to work from home
All equipment mounted in a Navepoint 9U Deluxe IT wall-mount locking rack
I haven't completely decided which of the modules of the UTM I will utilize but for certain the anti spam, virus blocker (in addition to workstation AV), intrusion detection, and ad blocker. I am up in the air about content and application blocking as it is such a small office and I don't really feel the need to block 7 adults as if they were children when they have never demonstrated childish behavior to me.
I know this is pretty basic stuff at it's core. But it really has been quite some time since I have worked with even SMB level networking equipment. Last time I was involved at this level we barely had stacking switches, used Windows Proxy Server at the edge, and fast internet was a T1 circuit.
In any event, I very much appreciate any one who takes the time to read through this and leaves any insight, comments, or suggestions that my customer would benefit from.
Thanks!!
There will be a total for now of 7 users. 2 of them are partner members and 5 are staffers. There is no server. Light file sharing is being done via a 2TB RAID 1 NAS which also houses full image backups of the partner machines. The NAS has an external 2.5" 2TB USB drive backing it up and is rotated weekly offsite
ISP--Comcast 50/15 modem purchased by me. Arris SB6183
UTM--NexGen NG-Mini with Untangle FW Complete 25 devices..UTM will have static IP on exernal interface
Unifi 24 port POE managed switch (US-24-250w) which will have two VLANS for the AP
Unfi Lite AP connected via POE
24 port patch panel already in place--18 drops throughout office
NAS into switch on same LAN
Rest of network will be workstations and shared wired printers/MFD's
Unifi cloud controller connected directly to switch
AP will have two LAN's:
One for employees personal devices with no access to network resources like NAS or workstations
One for guests on a different subnet than other LAN's
OPEN VPN module on UTM will be used to provide RDP for partners to work from home
All equipment mounted in a Navepoint 9U Deluxe IT wall-mount locking rack
I haven't completely decided which of the modules of the UTM I will utilize but for certain the anti spam, virus blocker (in addition to workstation AV), intrusion detection, and ad blocker. I am up in the air about content and application blocking as it is such a small office and I don't really feel the need to block 7 adults as if they were children when they have never demonstrated childish behavior to me.
I know this is pretty basic stuff at it's core. But it really has been quite some time since I have worked with even SMB level networking equipment. Last time I was involved at this level we barely had stacking switches, used Windows Proxy Server at the edge, and fast internet was a T1 circuit.
In any event, I very much appreciate any one who takes the time to read through this and leaves any insight, comments, or suggestions that my customer would benefit from.
Thanks!!