Couple of best practice questions for hyperconverged setup

jochen.korge

Member
Apr 13, 2021
10
1
8
36
Hi,
I was given the task to explore the possibilities for a brand new IT-Infrastructure for a customer of ours. Its industry with ~150 employees. The company's infrastructure belongs to the former parent company so we´ll start on a green field.

My current take on the subject would be to run everything virtualized on a Proxmox/Ceph Cluster. That is:

Domaincontroller
Exchange stub for m365 management
Firewall
DNS
DHCP
NAS
Radius
ERP System (not specified yet)
Print-Server
Mail gateway
MobileDeviceManagement
WSUS
several industry-specific tools, machine to machine communication, licence server

24/7 is not required, so we´re able to take services down for Updates/Maintenance at night/during weekends. It needs to be rock-solid during working hours though!
The network will be heavily (vlan) segregated. We´ll run a out of band Management-Network with separate internet access.

So here are the Questions:
  1. Networking
    1. Ceph and Proxmox Documentations suggests up to 4 Networks. Proposed Servers spec dual SFP28 and dual 10GBase-T (each in MLAG/Lag to stacked switch).
      1. Ceph Private (Heartbeat and Replication)
      2. Ceph Frontend (mainly to Proxmox VMs)
      3. Proxmox Private (Heartbeat and Replication)
      4. Guest Frontend
    2. Which of those should be bound on which NIC?
    3. Which should/could be separated by VLan?
    4. Does the above order reflect the importance? Are QoS rules on those VLans the way to go?
  2. Firewall(s) should be used for WAN Access and inter-VLan/Subnet Routing/NATing. Less than 10 concurrent VPN-Users.
    1. One or multiple FWs?
    2. Hardware or Virtualized?
    3. pfSense/OPNsense or Proxmox IPTables? Something completely different?
  3. What Software to use?
    1. what NAS/Cloud Software does pair well with Proxmox/Ceph? We need:
      1. SMB-Share with easy, GUI/Web-based User and Permissions Management (AD/LDAP integration)
      2. User-Manageable sync tool like Dropbox, Google-Drive, Synology Drive... you name it
      3. Versioning of synced files
      4. Easy sharing of files and folders with external users (I don´t like it but Management)
    2. Are TurnKey CTs "Production Ready" or only for Lab-Environments?
  4. Is a secondary Ceph pool with erasure coding for NAS- and cold-Storage appropriate?

Thanks in Advance :)
 
Thanks for posting here but PLEASE ask simple questions regarding Proxmox VE.

Your topic is really interesting but asking so many questions in one thread - most are not related to Proxmox VE - are most times not that useful here and the majority of the Proxmox experts will not answer due to this.
 
Yeah, I thougth so but there aren´t that many subforums to ask specific questions. So I asked all in one go.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!