Setup Network for remote Windows and Linux Workstations (Setup server, workstations and NAS)
Budget: £36 – £0 GBP
I'm looking for someone to configure the following, and document the process, so I can replicate it.
I need to build a system to allow remote workstations to access content in a secure fashion, my idea is to VPN all the traffic onto my server, and have the server then unlock the workstations, and allow the users to authenticate, and manage what they can and cannot see.
For storage I want to have a separate machine running TrueNAS, but using the same Authentication as the main server.
The clients are mostly Linux workstations, they connect to the server using a nano router that takes care of the VPN connection so that one is extant by the time the NBDE key is needed, and also to keep the traffic as secure as we can with minimum fuss.
I'm sure there is plenty of pitfalls I have not considered, that is why I need an expert to help me with this, while I still have some hair left.
I have physical access to the machines I need to test this on.
Server must handle:
VPN connections (from the remote workstations).
NBDE (to decrypt the remote workstations).
User Authentication using OTP and LDAP.
Firewall and traffic management, to limit what type of access the workstations have to internet services.
Supply licensing information to several bits of software the Workstations run.
TrueNAS:
Encrypted, unlocked by the NBDE server.
To serve the files, according to the permissions set out by the LDAP.
Duplication to secondary off-site TrueNAS.
Workstations:
(they connect to the internet via a nano router that establishes the VPN tunnel, so the VPN will be active from the get go)
Ubuntu 20.04 LTS.
LUKS encrypted, using NBDE key to unlock the machines.
Authenticate against the LDAP.
Migrate users home accounts if user logins on a different workstation.
Restrict USB access according to groups.
Lock the machine if it loses network connection.
Require OTP at login.
Windows Workstations:
(they connect to the internet via a nano router that establishes the VPN tunnel, so the VPN will be active from the get go)
Authenticate against the LDAP server.
Migrate user profiles if possible.
Workstations will be encrypted using local inputed key, if it can not be made to work with NBDE.
Mac clients:
Not much of a priority at this stage, but it will be nice to know how to deal with those, if required.
I need to build a system to allow remote workstations to access content in a secure fashion, my idea is to VPN all the traffic onto my server, and have the server then unlock the workstations, and allow the users to authenticate, and manage what they can and cannot see.
For storage I want to have a separate machine running TrueNAS, but using the same Authentication as the main server.
The clients are mostly Linux workstations, they connect to the server using a nano router that takes care of the VPN connection so that one is extant by the time the NBDE key is needed, and also to keep the traffic as secure as we can with minimum fuss.
I'm sure there is plenty of pitfalls I have not considered, that is why I need an expert to help me with this, while I still have some hair left.
I have physical access to the machines I need to test this on.
Server must handle:
VPN connections (from the remote workstations).
NBDE (to decrypt the remote workstations).
User Authentication using OTP and LDAP.
Firewall and traffic management, to limit what type of access the workstations have to internet services.
Supply licensing information to several bits of software the Workstations run.
TrueNAS:
Encrypted, unlocked by the NBDE server.
To serve the files, according to the permissions set out by the LDAP.
Duplication to secondary off-site TrueNAS.
Workstations:
(they connect to the internet via a nano router that establishes the VPN tunnel, so the VPN will be active from the get go)
Ubuntu 20.04 LTS.
LUKS encrypted, using NBDE key to unlock the machines.
Authenticate against the LDAP.
Migrate users home accounts if user logins on a different workstation.
Restrict USB access according to groups.
Lock the machine if it loses network connection.
Require OTP at login.
Windows Workstations:
(they connect to the internet via a nano router that establishes the VPN tunnel, so the VPN will be active from the get go)
Authenticate against the LDAP server.
Migrate user profiles if possible.
Workstations will be encrypted using local inputed key, if it can not be made to work with NBDE.
Mac clients:
Not much of a priority at this stage, but it will be nice to know how to deal with those, if required.