6.2 KiB
Chapter 2 - pfSense Configuration
This chapter covers the deployment and configuration of pfSense as the virtual firewall and router for the cyber range.
Objectives
After completing this chapter you should have:
- A functioning pfSense firewall
- Four virtual interfaces
- Internet access for every lab network
- Network isolation between lab segments
- DHCP configured (optional)
- Static addressing plan
- Firewall rules documented
- A secure foundation for the remainder of the lab
Why pfSense?
Rather than allowing Proxmox to route traffic directly, pfSense simulates what you would find in a real enterprise:
- Stateful firewall
- Router
- DHCP server
- DNS resolver
- NAT gateway
- VPN support
- Traffic monitoring
Every packet in the lab will flow through pfSense.
Network Topology
Internet
|
Home Router
|
vmbr0
|
pfSense
+----------------+----------------+
| | |
vmbr1 vmbr2 vmbr3
Attack LAN Corporate LAN DMZ
10.10.10.0 10.10.20.0 10.10.30.0
Only vmbr0 is connected to a physical network adapter.
Everything else is virtual.
Creating the pfSense VM
Recommended hardware:
| Resource | Value |
|---|---|
| CPU | 2 vCPU |
| Memory | 2–4 GB |
| Disk | 20 GB |
| BIOS | OVMF (UEFI) |
| Machine | q35 |
Network Adapters
Before installation, add four network adapters.
| Adapter | Bridge |
|---|---|
| NIC 1 | vmbr0 |
| NIC 2 | vmbr1 |
| NIC 3 | vmbr2 |
| NIC 4 | vmbr3 |
Use the VirtIO model for all adapters.
Interface Assignment
During installation, assign the interfaces:
| Interface | Purpose |
|---|---|
| WAN | vmbr0 |
| LAN | vmbr1 |
| OPT1 | vmbr2 |
| OPT2 | vmbr3 |
After installation, rename the interfaces if desired:
- WAN
- ATTACK
- INTERNAL
- DMZ
Using descriptive names makes firewall rules much easier to understand.
IP Addressing
WAN
Obtain an address from your home router using DHCP.
Example:
192.168.1.150/24
Gateway: 192.168.1.1
Attack Network
Interface:
ATTACK
Address:
10.10.10.1/24
Corporate Network
Interface:
INTERNAL
Address:
10.10.20.1/24
DMZ
Interface:
DMZ
Address:
10.10.30.1/24
DHCP
You can either use DHCP or assign static IPs.
For learning purposes, static addresses are recommended for infrastructure servers.
If DHCP is enabled:
Attack LAN
10.10.10.100
to
10.10.10.199
Corporate
10.10.20.100
to
10.10.20.199
DMZ
10.10.30.100
to
10.10.30.199
DNS
Initially use the pfSense DNS Resolver.
Later, after deploying Active Directory:
Corporate clients should use
10.10.20.10
(the Domain Controller)
This allows Active Directory to manage DNS.
NAT
Navigate to
Firewall
→ NAT
→ Outbound
Leave NAT in Automatic mode initially.
This allows every internal network to access the Internet.
Later, if desired, experiment with Hybrid or Manual NAT.
Firewall Rules
By default, only the LAN interface has an allow rule.
You must create rules for the other interfaces.
ATTACK
Allow:
Source:
ATTACK net
Destination:
Any
INTERNAL
Allow:
Source:
INTERNAL net
Destination:
Any
DMZ
Initially allow:
DMZ net
→
Any
Later, harden the rules by restricting access.
Future Hardening
Once the lab is working, tighten the rules.
Example:
- DMZ cannot initiate connections to INTERNAL.
- INTERNAL cannot access ATTACK except for specific services.
- ATTACK can scan all networks.
This creates realistic segmentation.
Static Mappings
Infrastructure servers should always use static addresses.
Recommended:
| Machine | Address |
|---|---|
| pfSense | 10.10.10.1 |
| DC01 | 10.10.20.10 |
| FILE01 | 10.10.20.70 |
| SQL01 | 10.10.20.80 |
| WEB01 | 10.10.30.10 |
| Kali | 10.10.10.10 |
Testing Connectivity
From Kali:
ping 10.10.10.1
ping 10.10.20.10
ping 10.10.30.10
Internet connectivity:
ping 1.1.1.1
DNS:
nslookup google.com
Useful pfSense Features
As the lab grows, explore:
- OpenVPN
- WireGuard
- HAProxy
- ACME (Let's Encrypt)
- Traffic Graphs
- Packet Capture
- Diagnostics
- States Table
- ARP Table
These tools are valuable for both administration and troubleshooting.
Backup Strategy
After completing the configuration:
Navigate to:
Diagnostics
→ Backup & Restore
Export the configuration file.
Store it in your Gitea repository or a secure backup location.
This allows rapid recovery of the firewall configuration.
Troubleshooting
No Internet Access
- Verify WAN received an IP address.
- Check the default gateway.
- Ensure Automatic Outbound NAT is enabled.
Cannot Reach Another Subnet
- Verify the VM is connected to the correct Proxmox bridge.
- Confirm the gateway points to pfSense.
- Check firewall rules on the source interface.
DNS Fails
- Test with:
ping 1.1.1.1
If this works but domain names fail, review DNS settings.
VM Cannot Reach pfSense
Verify:
- Bridge assignment in Proxmox
- Static IP configuration
- Default gateway
- Firewall rules
Validation Checklist
Before continuing:
- pfSense installed
- Four interfaces configured
- WAN has Internet access
- ATTACK network operational
- INTERNAL network operational
- DMZ operational
- NAT working
- DNS working
- Firewall rules created
- Configuration backup exported
Next Chapter
The next chapter focuses on networking concepts used throughout the lab, including:
- IP addressing strategy
- Static vs DHCP
- Routing
- VLANs vs Linux bridges
- Dual-homed hosts
- Pivoting concepts
- Traffic flow between networks
- Preparing the environment for Active Directory