created instruction files for my home OSCP labs
This commit is contained in:
449
docs/02-pfsense.md
Normal file
449
docs/02-pfsense.md
Normal file
@@ -0,0 +1,449 @@
|
||||
# Chapter 2 - pfSense Configuration
|
||||
|
||||
> This chapter covers the deployment and configuration of pfSense as the virtual firewall and router for the cyber range.
|
||||
|
||||
---
|
||||
|
||||
# Objectives
|
||||
|
||||
After completing this chapter you should have:
|
||||
|
||||
* A functioning pfSense firewall
|
||||
* Four virtual interfaces
|
||||
* Internet access for every lab network
|
||||
* Network isolation between lab segments
|
||||
* DHCP configured (optional)
|
||||
* Static addressing plan
|
||||
* Firewall rules documented
|
||||
* A secure foundation for the remainder of the lab
|
||||
|
||||
---
|
||||
|
||||
# Why pfSense?
|
||||
|
||||
Rather than allowing Proxmox to route traffic directly, pfSense simulates what you would find in a real enterprise:
|
||||
|
||||
* Stateful firewall
|
||||
* Router
|
||||
* DHCP server
|
||||
* DNS resolver
|
||||
* NAT gateway
|
||||
* VPN support
|
||||
* Traffic monitoring
|
||||
|
||||
Every packet in the lab will flow through pfSense.
|
||||
|
||||
---
|
||||
|
||||
# Network Topology
|
||||
|
||||
```text
|
||||
Internet
|
||||
|
|
||||
Home Router
|
||||
|
|
||||
vmbr0
|
||||
|
|
||||
pfSense
|
||||
+----------------+----------------+
|
||||
| | |
|
||||
vmbr1 vmbr2 vmbr3
|
||||
Attack LAN Corporate LAN DMZ
|
||||
10.10.10.0 10.10.20.0 10.10.30.0
|
||||
```
|
||||
|
||||
Only **vmbr0** is connected to a physical network adapter.
|
||||
|
||||
Everything else is virtual.
|
||||
|
||||
---
|
||||
|
||||
# Creating the pfSense VM
|
||||
|
||||
Recommended hardware:
|
||||
|
||||
| Resource | Value |
|
||||
| -------- | ----------: |
|
||||
| CPU | 2 vCPU |
|
||||
| Memory | 2–4 GB |
|
||||
| Disk | 20 GB |
|
||||
| BIOS | OVMF (UEFI) |
|
||||
| Machine | q35 |
|
||||
|
||||
---
|
||||
|
||||
# Network Adapters
|
||||
|
||||
Before installation, add four network adapters.
|
||||
|
||||
| Adapter | Bridge |
|
||||
| ------- | ------ |
|
||||
| NIC 1 | vmbr0 |
|
||||
| NIC 2 | vmbr1 |
|
||||
| NIC 3 | vmbr2 |
|
||||
| NIC 4 | vmbr3 |
|
||||
|
||||
Use the **VirtIO** model for all adapters.
|
||||
|
||||
---
|
||||
|
||||
# Interface Assignment
|
||||
|
||||
During installation, assign the interfaces:
|
||||
|
||||
| Interface | Purpose |
|
||||
| --------- | ------- |
|
||||
| WAN | vmbr0 |
|
||||
| LAN | vmbr1 |
|
||||
| OPT1 | vmbr2 |
|
||||
| OPT2 | vmbr3 |
|
||||
|
||||
After installation, rename the interfaces if desired:
|
||||
|
||||
* WAN
|
||||
* ATTACK
|
||||
* INTERNAL
|
||||
* DMZ
|
||||
|
||||
Using descriptive names makes firewall rules much easier to understand.
|
||||
|
||||
---
|
||||
|
||||
# IP Addressing
|
||||
|
||||
## WAN
|
||||
|
||||
Obtain an address from your home router using DHCP.
|
||||
|
||||
Example:
|
||||
|
||||
```text
|
||||
192.168.1.150/24
|
||||
Gateway: 192.168.1.1
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Attack Network
|
||||
|
||||
Interface:
|
||||
|
||||
ATTACK
|
||||
|
||||
Address:
|
||||
|
||||
```text
|
||||
10.10.10.1/24
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Corporate Network
|
||||
|
||||
Interface:
|
||||
|
||||
INTERNAL
|
||||
|
||||
Address:
|
||||
|
||||
```text
|
||||
10.10.20.1/24
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## DMZ
|
||||
|
||||
Interface:
|
||||
|
||||
DMZ
|
||||
|
||||
Address:
|
||||
|
||||
```text
|
||||
10.10.30.1/24
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# DHCP
|
||||
|
||||
You can either use DHCP or assign static IPs.
|
||||
|
||||
For learning purposes, static addresses are recommended for infrastructure servers.
|
||||
|
||||
If DHCP is enabled:
|
||||
|
||||
Attack LAN
|
||||
|
||||
```
|
||||
10.10.10.100
|
||||
to
|
||||
10.10.10.199
|
||||
```
|
||||
|
||||
Corporate
|
||||
|
||||
```
|
||||
10.10.20.100
|
||||
to
|
||||
10.10.20.199
|
||||
```
|
||||
|
||||
DMZ
|
||||
|
||||
```
|
||||
10.10.30.100
|
||||
to
|
||||
10.10.30.199
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# DNS
|
||||
|
||||
Initially use the pfSense DNS Resolver.
|
||||
|
||||
Later, after deploying Active Directory:
|
||||
|
||||
Corporate clients should use
|
||||
|
||||
```
|
||||
10.10.20.10
|
||||
```
|
||||
|
||||
(the Domain Controller)
|
||||
|
||||
This allows Active Directory to manage DNS.
|
||||
|
||||
---
|
||||
|
||||
# NAT
|
||||
|
||||
Navigate to
|
||||
|
||||
```
|
||||
Firewall
|
||||
→ NAT
|
||||
→ Outbound
|
||||
```
|
||||
|
||||
Leave NAT in **Automatic** mode initially.
|
||||
|
||||
This allows every internal network to access the Internet.
|
||||
|
||||
Later, if desired, experiment with Hybrid or Manual NAT.
|
||||
|
||||
---
|
||||
|
||||
# Firewall Rules
|
||||
|
||||
By default, only the LAN interface has an allow rule.
|
||||
|
||||
You must create rules for the other interfaces.
|
||||
|
||||
## ATTACK
|
||||
|
||||
Allow:
|
||||
|
||||
```
|
||||
Source:
|
||||
ATTACK net
|
||||
|
||||
Destination:
|
||||
Any
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## INTERNAL
|
||||
|
||||
Allow:
|
||||
|
||||
```
|
||||
Source:
|
||||
INTERNAL net
|
||||
|
||||
Destination:
|
||||
Any
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## DMZ
|
||||
|
||||
Initially allow:
|
||||
|
||||
```
|
||||
DMZ net
|
||||
→
|
||||
Any
|
||||
```
|
||||
|
||||
Later, harden the rules by restricting access.
|
||||
|
||||
---
|
||||
|
||||
# Future Hardening
|
||||
|
||||
Once the lab is working, tighten the rules.
|
||||
|
||||
Example:
|
||||
|
||||
* DMZ cannot initiate connections to INTERNAL.
|
||||
* INTERNAL cannot access ATTACK except for specific services.
|
||||
* ATTACK can scan all networks.
|
||||
|
||||
This creates realistic segmentation.
|
||||
|
||||
---
|
||||
|
||||
# Static Mappings
|
||||
|
||||
Infrastructure servers should always use static addresses.
|
||||
|
||||
Recommended:
|
||||
|
||||
| Machine | Address |
|
||||
| ------- | ----------- |
|
||||
| pfSense | 10.10.10.1 |
|
||||
| DC01 | 10.10.20.10 |
|
||||
| FILE01 | 10.10.20.70 |
|
||||
| SQL01 | 10.10.20.80 |
|
||||
| WEB01 | 10.10.30.10 |
|
||||
| Kali | 10.10.10.10 |
|
||||
|
||||
---
|
||||
|
||||
# Testing Connectivity
|
||||
|
||||
From Kali:
|
||||
|
||||
```bash
|
||||
ping 10.10.10.1
|
||||
```
|
||||
|
||||
```bash
|
||||
ping 10.10.20.10
|
||||
```
|
||||
|
||||
```bash
|
||||
ping 10.10.30.10
|
||||
```
|
||||
|
||||
Internet connectivity:
|
||||
|
||||
```bash
|
||||
ping 1.1.1.1
|
||||
```
|
||||
|
||||
DNS:
|
||||
|
||||
```bash
|
||||
nslookup google.com
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# Useful pfSense Features
|
||||
|
||||
As the lab grows, explore:
|
||||
|
||||
* OpenVPN
|
||||
* WireGuard
|
||||
* HAProxy
|
||||
* ACME (Let's Encrypt)
|
||||
* Traffic Graphs
|
||||
* Packet Capture
|
||||
* Diagnostics
|
||||
* States Table
|
||||
* ARP Table
|
||||
|
||||
These tools are valuable for both administration and troubleshooting.
|
||||
|
||||
---
|
||||
|
||||
# Backup Strategy
|
||||
|
||||
After completing the configuration:
|
||||
|
||||
Navigate to:
|
||||
|
||||
```
|
||||
Diagnostics
|
||||
→ Backup & Restore
|
||||
```
|
||||
|
||||
Export the configuration file.
|
||||
|
||||
Store it in your Gitea repository or a secure backup location.
|
||||
|
||||
This allows rapid recovery of the firewall configuration.
|
||||
|
||||
---
|
||||
|
||||
# Troubleshooting
|
||||
|
||||
### No Internet Access
|
||||
|
||||
* Verify WAN received an IP address.
|
||||
* Check the default gateway.
|
||||
* Ensure Automatic Outbound NAT is enabled.
|
||||
|
||||
### Cannot Reach Another Subnet
|
||||
|
||||
* Verify the VM is connected to the correct Proxmox bridge.
|
||||
* Confirm the gateway points to pfSense.
|
||||
* Check firewall rules on the source interface.
|
||||
|
||||
### DNS Fails
|
||||
|
||||
* Test with:
|
||||
|
||||
```bash
|
||||
ping 1.1.1.1
|
||||
```
|
||||
|
||||
If this works but domain names fail, review DNS settings.
|
||||
|
||||
### VM Cannot Reach pfSense
|
||||
|
||||
Verify:
|
||||
|
||||
* Bridge assignment in Proxmox
|
||||
* Static IP configuration
|
||||
* Default gateway
|
||||
* Firewall rules
|
||||
|
||||
---
|
||||
|
||||
# Validation Checklist
|
||||
|
||||
Before continuing:
|
||||
|
||||
* [ ] pfSense installed
|
||||
* [ ] Four interfaces configured
|
||||
* [ ] WAN has Internet access
|
||||
* [ ] ATTACK network operational
|
||||
* [ ] INTERNAL network operational
|
||||
* [ ] DMZ operational
|
||||
* [ ] NAT working
|
||||
* [ ] DNS working
|
||||
* [ ] Firewall rules created
|
||||
* [ ] Configuration backup exported
|
||||
|
||||
---
|
||||
|
||||
# Next Chapter
|
||||
|
||||
The next chapter focuses on networking concepts used throughout the lab, including:
|
||||
|
||||
* IP addressing strategy
|
||||
* Static vs DHCP
|
||||
* Routing
|
||||
* VLANs vs Linux bridges
|
||||
* Dual-homed hosts
|
||||
* Pivoting concepts
|
||||
* Traffic flow between networks
|
||||
* Preparing the environment for Active Directory
|
||||
|
||||
Reference in New Issue
Block a user