450 lines
6.2 KiB
Markdown
450 lines
6.2 KiB
Markdown
# Chapter 2 - pfSense Configuration
|
||
|
||
> This chapter covers the deployment and configuration of pfSense as the virtual firewall and router for the cyber range.
|
||
|
||
---
|
||
|
||
# Objectives
|
||
|
||
After completing this chapter you should have:
|
||
|
||
* A functioning pfSense firewall
|
||
* Four virtual interfaces
|
||
* Internet access for every lab network
|
||
* Network isolation between lab segments
|
||
* DHCP configured (optional)
|
||
* Static addressing plan
|
||
* Firewall rules documented
|
||
* A secure foundation for the remainder of the lab
|
||
|
||
---
|
||
|
||
# Why pfSense?
|
||
|
||
Rather than allowing Proxmox to route traffic directly, pfSense simulates what you would find in a real enterprise:
|
||
|
||
* Stateful firewall
|
||
* Router
|
||
* DHCP server
|
||
* DNS resolver
|
||
* NAT gateway
|
||
* VPN support
|
||
* Traffic monitoring
|
||
|
||
Every packet in the lab will flow through pfSense.
|
||
|
||
---
|
||
|
||
# Network Topology
|
||
|
||
```text
|
||
Internet
|
||
|
|
||
Home Router
|
||
|
|
||
vmbr0
|
||
|
|
||
pfSense
|
||
+----------------+----------------+
|
||
| | |
|
||
vmbr1 vmbr2 vmbr3
|
||
Attack LAN Corporate LAN DMZ
|
||
10.10.10.0 10.10.20.0 10.10.30.0
|
||
```
|
||
|
||
Only **vmbr0** is connected to a physical network adapter.
|
||
|
||
Everything else is virtual.
|
||
|
||
---
|
||
|
||
# Creating the pfSense VM
|
||
|
||
Recommended hardware:
|
||
|
||
| Resource | Value |
|
||
| -------- | ----------: |
|
||
| CPU | 2 vCPU |
|
||
| Memory | 2–4 GB |
|
||
| Disk | 20 GB |
|
||
| BIOS | OVMF (UEFI) |
|
||
| Machine | q35 |
|
||
|
||
---
|
||
|
||
# Network Adapters
|
||
|
||
Before installation, add four network adapters.
|
||
|
||
| Adapter | Bridge |
|
||
| ------- | ------ |
|
||
| NIC 1 | vmbr0 |
|
||
| NIC 2 | vmbr1 |
|
||
| NIC 3 | vmbr2 |
|
||
| NIC 4 | vmbr3 |
|
||
|
||
Use the **VirtIO** model for all adapters.
|
||
|
||
---
|
||
|
||
# Interface Assignment
|
||
|
||
During installation, assign the interfaces:
|
||
|
||
| Interface | Purpose |
|
||
| --------- | ------- |
|
||
| WAN | vmbr0 |
|
||
| LAN | vmbr1 |
|
||
| OPT1 | vmbr2 |
|
||
| OPT2 | vmbr3 |
|
||
|
||
After installation, rename the interfaces if desired:
|
||
|
||
* WAN
|
||
* ATTACK
|
||
* INTERNAL
|
||
* DMZ
|
||
|
||
Using descriptive names makes firewall rules much easier to understand.
|
||
|
||
---
|
||
|
||
# IP Addressing
|
||
|
||
## WAN
|
||
|
||
Obtain an address from your home router using DHCP.
|
||
|
||
Example:
|
||
|
||
```text
|
||
192.168.1.150/24
|
||
Gateway: 192.168.1.1
|
||
```
|
||
|
||
---
|
||
|
||
## Attack Network
|
||
|
||
Interface:
|
||
|
||
ATTACK
|
||
|
||
Address:
|
||
|
||
```text
|
||
10.10.10.1/24
|
||
```
|
||
|
||
---
|
||
|
||
## Corporate Network
|
||
|
||
Interface:
|
||
|
||
INTERNAL
|
||
|
||
Address:
|
||
|
||
```text
|
||
10.10.20.1/24
|
||
```
|
||
|
||
---
|
||
|
||
## DMZ
|
||
|
||
Interface:
|
||
|
||
DMZ
|
||
|
||
Address:
|
||
|
||
```text
|
||
10.10.30.1/24
|
||
```
|
||
|
||
---
|
||
|
||
# DHCP
|
||
|
||
You can either use DHCP or assign static IPs.
|
||
|
||
For learning purposes, static addresses are recommended for infrastructure servers.
|
||
|
||
If DHCP is enabled:
|
||
|
||
Attack LAN
|
||
|
||
```
|
||
10.10.10.100
|
||
to
|
||
10.10.10.199
|
||
```
|
||
|
||
Corporate
|
||
|
||
```
|
||
10.10.20.100
|
||
to
|
||
10.10.20.199
|
||
```
|
||
|
||
DMZ
|
||
|
||
```
|
||
10.10.30.100
|
||
to
|
||
10.10.30.199
|
||
```
|
||
|
||
---
|
||
|
||
# DNS
|
||
|
||
Initially use the pfSense DNS Resolver.
|
||
|
||
Later, after deploying Active Directory:
|
||
|
||
Corporate clients should use
|
||
|
||
```
|
||
10.10.20.10
|
||
```
|
||
|
||
(the Domain Controller)
|
||
|
||
This allows Active Directory to manage DNS.
|
||
|
||
---
|
||
|
||
# NAT
|
||
|
||
Navigate to
|
||
|
||
```
|
||
Firewall
|
||
→ NAT
|
||
→ Outbound
|
||
```
|
||
|
||
Leave NAT in **Automatic** mode initially.
|
||
|
||
This allows every internal network to access the Internet.
|
||
|
||
Later, if desired, experiment with Hybrid or Manual NAT.
|
||
|
||
---
|
||
|
||
# Firewall Rules
|
||
|
||
By default, only the LAN interface has an allow rule.
|
||
|
||
You must create rules for the other interfaces.
|
||
|
||
## ATTACK
|
||
|
||
Allow:
|
||
|
||
```
|
||
Source:
|
||
ATTACK net
|
||
|
||
Destination:
|
||
Any
|
||
```
|
||
|
||
---
|
||
|
||
## INTERNAL
|
||
|
||
Allow:
|
||
|
||
```
|
||
Source:
|
||
INTERNAL net
|
||
|
||
Destination:
|
||
Any
|
||
```
|
||
|
||
---
|
||
|
||
## DMZ
|
||
|
||
Initially allow:
|
||
|
||
```
|
||
DMZ net
|
||
→
|
||
Any
|
||
```
|
||
|
||
Later, harden the rules by restricting access.
|
||
|
||
---
|
||
|
||
# Future Hardening
|
||
|
||
Once the lab is working, tighten the rules.
|
||
|
||
Example:
|
||
|
||
* DMZ cannot initiate connections to INTERNAL.
|
||
* INTERNAL cannot access ATTACK except for specific services.
|
||
* ATTACK can scan all networks.
|
||
|
||
This creates realistic segmentation.
|
||
|
||
---
|
||
|
||
# Static Mappings
|
||
|
||
Infrastructure servers should always use static addresses.
|
||
|
||
Recommended:
|
||
|
||
| Machine | Address |
|
||
| ------- | ----------- |
|
||
| pfSense | 10.10.10.1 |
|
||
| DC01 | 10.10.20.10 |
|
||
| FILE01 | 10.10.20.70 |
|
||
| SQL01 | 10.10.20.80 |
|
||
| WEB01 | 10.10.30.10 |
|
||
| Kali | 10.10.10.10 |
|
||
|
||
---
|
||
|
||
# Testing Connectivity
|
||
|
||
From Kali:
|
||
|
||
```bash
|
||
ping 10.10.10.1
|
||
```
|
||
|
||
```bash
|
||
ping 10.10.20.10
|
||
```
|
||
|
||
```bash
|
||
ping 10.10.30.10
|
||
```
|
||
|
||
Internet connectivity:
|
||
|
||
```bash
|
||
ping 1.1.1.1
|
||
```
|
||
|
||
DNS:
|
||
|
||
```bash
|
||
nslookup google.com
|
||
```
|
||
|
||
---
|
||
|
||
# Useful pfSense Features
|
||
|
||
As the lab grows, explore:
|
||
|
||
* OpenVPN
|
||
* WireGuard
|
||
* HAProxy
|
||
* ACME (Let's Encrypt)
|
||
* Traffic Graphs
|
||
* Packet Capture
|
||
* Diagnostics
|
||
* States Table
|
||
* ARP Table
|
||
|
||
These tools are valuable for both administration and troubleshooting.
|
||
|
||
---
|
||
|
||
# Backup Strategy
|
||
|
||
After completing the configuration:
|
||
|
||
Navigate to:
|
||
|
||
```
|
||
Diagnostics
|
||
→ Backup & Restore
|
||
```
|
||
|
||
Export the configuration file.
|
||
|
||
Store it in your Gitea repository or a secure backup location.
|
||
|
||
This allows rapid recovery of the firewall configuration.
|
||
|
||
---
|
||
|
||
# Troubleshooting
|
||
|
||
### No Internet Access
|
||
|
||
* Verify WAN received an IP address.
|
||
* Check the default gateway.
|
||
* Ensure Automatic Outbound NAT is enabled.
|
||
|
||
### Cannot Reach Another Subnet
|
||
|
||
* Verify the VM is connected to the correct Proxmox bridge.
|
||
* Confirm the gateway points to pfSense.
|
||
* Check firewall rules on the source interface.
|
||
|
||
### DNS Fails
|
||
|
||
* Test with:
|
||
|
||
```bash
|
||
ping 1.1.1.1
|
||
```
|
||
|
||
If this works but domain names fail, review DNS settings.
|
||
|
||
### VM Cannot Reach pfSense
|
||
|
||
Verify:
|
||
|
||
* Bridge assignment in Proxmox
|
||
* Static IP configuration
|
||
* Default gateway
|
||
* Firewall rules
|
||
|
||
---
|
||
|
||
# Validation Checklist
|
||
|
||
Before continuing:
|
||
|
||
* [ ] pfSense installed
|
||
* [ ] Four interfaces configured
|
||
* [ ] WAN has Internet access
|
||
* [ ] ATTACK network operational
|
||
* [ ] INTERNAL network operational
|
||
* [ ] DMZ operational
|
||
* [ ] NAT working
|
||
* [ ] DNS working
|
||
* [ ] Firewall rules created
|
||
* [ ] Configuration backup exported
|
||
|
||
---
|
||
|
||
# Next Chapter
|
||
|
||
The next chapter focuses on networking concepts used throughout the lab, including:
|
||
|
||
* IP addressing strategy
|
||
* Static vs DHCP
|
||
* Routing
|
||
* VLANs vs Linux bridges
|
||
* Dual-homed hosts
|
||
* Pivoting concepts
|
||
* Traffic flow between networks
|
||
* Preparing the environment for Active Directory
|
||
|