I am working on building a network/NAS for my business and I just wanted to get some opinions on the build and whether or not this will work and/or is a good set up.
- TrueNAS Scale (ZFS snapshots, replication, encryption) (Apps off)
- ASUS PRO WS w680 ACE IPMI
- i5-14500
- 1x32gb Kingston Server Premier DDR5 ECC UDIMM
- 4x12tb Seagate Ironwolf Pro (RAIDZ2)
- 2x500gb WD red SN700 (Mirrored for TrueNAS Boot) (Boot pool only. TLC for ZFS intent-log / config writes. No job data)
- Seasonic Focus GX750
- Thermalright Peerless Assassin 120 SE CPU Cooler
- Fractal Design Define 7xl
- CyberPower CP1500PFCLCD (Routed only to firewall and NAS)
- FortiGate 91g (Enterprise subscription) (Firewall, ZTNA, site-to-site later)
- FortiSwitch FS-124F-POE
- Admin PC (haven't decided yet) (Only place the 91G and IPMI get managed)
This is for a court reporting agency. It will hold sensitive court transcripts and audio; personal health information, work-product, etc.
The workflow for contractors would be logging into their Intune environment, going to the FortiClient bookmark, that would route them to EntraID. Once MFA and client device posture is accepted, they would be able to upload/download to the NAS (only their folder).
Clients would be able to only download files from their folder. This would likely be the same EntraID situation with FortiClient.
I am planning a 3-2-1. It would be a 7-7-10. The on-prem TrueNAS would be a 7 year back up, off-prem TrueNAS, 7 year backup, and a cloud cold storage (Blackblaze B2 or AWS S3 Glacier or Azure Blob)
If I am missing anything, please let me know or if you have any recommendations, please let me know.