configpolicy/group_vars
Dustin a1ca06a3c5 Move VPN server to dedicated VM
The VPN capability of the UniFi Security Gateway is extremely limited.
It does not support road-warrior IPsec/IKEv2 configuration, and its
OpenVPN configuration is inflexible. As with DHCP, the best solution is
to simply move service to another machine.

To that end, I created a new VM, *vpn0.pyrocufflink.blue*, to host both
strongSwan and OpenVPN. For this to work, the necessary TCP/UDP ports
need to be forwarded, of course, and all of the remote subnets need
static routes on the gateway, specifying this machine as the next hop.
Additionally, ICMP redirects need to be disabled, to prevent confusing
the routing tables of devices on the same subnet as the VPN gateway.
2018-10-07 21:42:18 -05:00
..
dch-gw Move DHCP service to dns1.p.b 2018-10-07 21:42:18 -05:00
pyrocufflink pyrocufflink: Ensure Samba security is correct 2018-08-01 22:05:18 -05:00
all.yml all: Set SMTP relay 2018-08-07 20:04:09 -05:00
aria2.yml aria2: Deploy aria2 download manager 2018-08-19 14:17:48 -05:00
burp-client.yml burp-{client,server}: PBs to deploy BURP 2018-08-08 20:14:25 -05:00
burp-server.yml burp-{client,server}: PBs to deploy BURP 2018-08-08 20:14:25 -05:00
gitea.yml gitea: Restrict SSH configuration 2018-06-06 21:45:36 -05:00
jenkins-slave.yml jenkins-slave: PB to deploy Jenkins slave 2018-04-08 12:04:03 -05:00
koji-hub.yml hosts: Add koji0.pyrocufflink.blue 2018-08-12 10:27:20 -05:00
koji.yml hosts: Add koji0.pyrocufflink.blue 2018-08-12 10:27:20 -05:00
pyrocufflink-dhcp.yml Move VPN server to dedicated VM 2018-10-07 21:42:18 -05:00
pyrocufflink-dns.yml pyrocufflink-dns: Split named_zones definition 2018-08-12 17:23:34 -05:00
radius.yml Move APs to Management network 2018-07-15 09:19:39 -05:00
samba-dc.yml samba-dc: Configure TLS 2018-05-28 15:24:34 -05:00
smtp-relay.yml smtp-relay: PB to deploy Postfix SMTP relay 2018-04-15 11:38:51 -05:00
vm-hosts.yml vmhost: PB to set up VM hosts 2018-07-23 17:35:10 -05:00
zabbix-server.yml zabbix-server: Force prefork Apache MPM 2018-06-04 20:03:52 -05:00
zabbix.yml hosts: Add hosts to zabbix group 2018-04-14 15:47:49 -05:00