Home Network Setup
-
@black3dynamite said in Home Network Setup:
@scottalanmiller said in Home Network Setup:
Here is the alternate.... on a non-Windows network, I don't want DNS listing random dynamic guests. That's the simplest solution. Windows does something I have no desire to have. Given that I don't know what purpose it serves, it's hard to figure out what you are actually looking to accomplish.
Windows DNS can be set to only allow secure dynamic updates, non secure dynamic updates, none. I think the default is secure dynamic updates.
We've dropped the dynamic update/DDNS from the discussion at this point, since Scott is calling it a red herring.
-
@dashrender said in Home Network Setup:
@scottalanmiller said in Home Network Setup:
Problem with the AD assumption:
- It is never mentioned, at all. Not even hinted at.
- Replacing DNS and DHCP alone don't fix the need to replace AD, so don't solve the CAL issue as asked.
NO - that is an assumption now on your part - I'm talking about using Windows Server to provide DHCP and DNS.
If you are talking about that, then you already know your answer. Stop using them. Problem solved. Your question makes no sense without AD. It serves no purpose.
-
@scottalanmiller said in Home Network Setup:
So, in the real world, where we work from business goals, we have two basic things we would do. Neither matches what is asked.
- Non-AD Network (the one we are dealing with here.) There is no value or purpose to DDNS in this scenario. You have no problem to solve. Simply remove the Windows servers and go to normal, everyday DHCP and DNS. Ubiquiti, Linux VMs, everything already handle this perfectly well. There is nothing for the industry to improve here.
Well DDNS could have value if you want to manage your devices by name, not IP address, but otherwise - fine.
-
@dashrender said in Home Network Setup:
@scottalanmiller said in Home Network Setup:
In a normal network, with scanners on DHCP, that isn't a Windows network, there is no such need as this, the very idea sounds so silly. Given that avoiding the Windows CALs here is automatic and the default, do you see why it's confusing that there is nothing to answer other than "don't do that?"
So you're saying the scanners go on their own network, and the windows laptop is on a separate network - so non issue, since the scanner network can use some other DHCP/DNS service that has no licensing fee?
I have no idea what you are talking about now. I've said nothing of the sort. There is zero need for the things you are asking for, there is no need for "different networks" or anything like that. Just stop trying to use DDNS and everything is fixed instantly.
-
@dashrender said in Home Network Setup:
@scottalanmiller said in Home Network Setup:
So, in the real world, where we work from business goals, we have two basic things we would do. Neither matches what is asked.
- Non-AD Network (the one we are dealing with here.) There is no value or purpose to DDNS in this scenario. You have no problem to solve. Simply remove the Windows servers and go to normal, everyday DHCP and DNS. Ubiquiti, Linux VMs, everything already handle this perfectly well. There is nothing for the industry to improve here.
Well DDNS could have value if you want to manage your devices by name, not IP address, but otherwise - fine.
How would that work? What use case is there for that?
-
All this said, of course you can do it. It's just a silly thing to want and doesn't, AFAIK, serve any purpose. But here is a quick guide if you really wanted DHCP to do these updates for you.
-
Help me understand, are we talking about allowing untrusted clients to update to the DNS server or not allow any clients to update to the DNS server?
-
@black3dynamite said in Home Network Setup:
@scottalanmiller said in Home Network Setup:
Here is the alternate.... on a non-Windows network, I don't want DNS listing random dynamic guests. That's the simplest solution. Windows does something I have no desire to have. Given that I don't know what purpose it serves, it's hard to figure out what you are actually looking to accomplish.
Windows DNS can be set to only allow secure dynamic updates, non secure dynamic updates, none. I think the default is secure dynamic updates.
That's the other way around. The point is to update non-Windows DNS, not to update Windows DNS. The plan here is to remove all Windows Servers so that no CALs are needed.
-
@black3dynamite said in Home Network Setup:
Help me understand, are we talking about allowing untrusted clients to update to the DNS server or not allow any clients to update to the DNS server?
We are talking about some unknown clients updating either BIND or Samba DNS.
-
@scottalanmiller said in Home Network Setup:
@dashrender said in Home Network Setup:
@scottalanmiller said in Home Network Setup:
So, in the real world, where we work from business goals, we have two basic things we would do. Neither matches what is asked.
- Non-AD Network (the one we are dealing with here.) There is no value or purpose to DDNS in this scenario. You have no problem to solve. Simply remove the Windows servers and go to normal, everyday DHCP and DNS. Ubiquiti, Linux VMs, everything already handle this perfectly well. There is nothing for the industry to improve here.
Well DDNS could have value if you want to manage your devices by name, not IP address, but otherwise - fine.
How would that work? What use case is there for that?
When I look at my Unifi controller, I like to see host names of my devices, not the mac addresses, because the mac is meaningless to me. So having the controller get the DNS name would be nice.. you don't see that?
-
@black3dynamite said in Home Network Setup:
Help me understand, are we talking about allowing untrusted clients to update to the DNS server or not allow any clients to update to the DNS server?
OMG NO - we dropped the dymanic portion of this conversation 10 mins ago!
-
@dashrender said in Home Network Setup:
@scottalanmiller said in Home Network Setup:
@dashrender said in Home Network Setup:
@scottalanmiller said in Home Network Setup:
So, in the real world, where we work from business goals, we have two basic things we would do. Neither matches what is asked.
- Non-AD Network (the one we are dealing with here.) There is no value or purpose to DDNS in this scenario. You have no problem to solve. Simply remove the Windows servers and go to normal, everyday DHCP and DNS. Ubiquiti, Linux VMs, everything already handle this perfectly well. There is nothing for the industry to improve here.
Well DDNS could have value if you want to manage your devices by name, not IP address, but otherwise - fine.
How would that work? What use case is there for that?
When I look at my Unifi controller, I like to see host names of my devices, not the mac addresses, because the mac is meaningless to me. So having the controller get the DNS name would be nice.. you don't see that?
Sort of, but it's a really trivial way to send false info.
-
The whole crux of my ask was - the desire to buy as few Windows Server CALs as possible.
As has been stated here before - if a device uses any Windows Server Service, it must have a CAL. So if you use DHCP - you need a CAL, if you use DNS you need a CAL. - assuming that still holdsThe assumption - for Scott's sake - is you have Active Directory.
My question is - you have a network of both windows clients and non windows clients. The non windows clients will never touch the Windows servers - go.
So I can answer this myself - Scott will now say - put them on separate networks - done. Why done? because you need Windows CALs for all of the Windows users already, so you're covered.. and the non windows devices/users will use a non license requiring DHCP/DNS solution on it's own network.
Yes damn that was a journey.
-
But, if you have a specific goal like this, when I ask for a goal, this is what you should say: "I spend enough time managing devices in Ubiquiti DHCP that I want to see hostnames there."
Then I might question that goal, because that seems like a weird problem to want to solve, but you are talking about an actual goal in allowing you to see hostnames listed. Do you see, it's a final thing, it's something that you as a person want out of the system. Not a means to an end, it's an end. A weird end worth inviestigating, but an end.
All of the questions to this point, all of them, were about "means" not "ends". They were all solutions to problems that weren't mentioned.
-
@dashrender said in Home Network Setup:
The whole crux of my ask was - the desire to buy as few Windows Server CALs as possible.
This is unrelated to the question asked, though.
-
@dashrender said in Home Network Setup:
My question is - you have a network of both windows clients and non windows clients. The non windows clients will never touch the Windows servers - go.
Why would there be anything touching Windows Servers?
-
@dashrender said in Home Network Setup:
So I can answer this myself - Scott will now say - put them on separate networks - done. Why done? because you need Windows CALs for all of the Windows users already, so you're covered.. and the non windows devices/users will use a non license requiring DHCP/DNS solution on it's own network.
If you really have a need for Windows servers for some things and not for others, then yes, this works. You can also do things like not use DHCP for those devices. DHCP and DNS, while often nice, are anything but required. There are cases, rare as the may be, to just skip them.
But two networks might be better. Keep in mind that two networks might mean physically separate (like VLAN) for DHCP reasons, or overlapping on one with non-Windows DHCP and nothing else shared, or two subnets on one physical LAN.
-
But if the goal is to eliminate all Windows CALs, you could remove the Windows servers entirely. Just identify the goal level services (rather than services that only work to support those goals, those would be proximate services) and make sure that your non-Windows devices can supply those.
-
@scottalanmiller said in Home Network Setup:
@dashrender said in Home Network Setup:
The whole crux of my ask was - the desire to buy as few Windows Server CALs as possible.
This is unrelated to the question asked, though.
Correct - it is not related to the first question - but when pressed - I did state it as much.
-
@scottalanmiller said in Home Network Setup:
But if the goal is to eliminate all Windows CALs, you could remove the Windows servers entirely. Just identify the goal level services (rather than services that only work to support those goals, those would be proximate services) and make sure that your non-Windows devices can supply those.
The goal was never to eliminate Windows CALs, but to buy as few as possible.