Secure your Networks with the Opensource Firewall pfSense
hagen.bauer@rusticus-consulting.de
Secure your Networks with the Opensource Firewall pfSense - - PowerPoint PPT Presentation
Secure your Networks with the Opensource Firewall pfSense hagen.bauer@rusticus-consulting.de Agenda About me Why something new? My provider gave me a fjrewall. What exactly is pfSense? Its an easy start More complex
hagen.bauer@rusticus-consulting.de
– 10 PCs, 4 Server, 8 mobile devices, – Home automatjon, Freifunk, Sonos, Asterisk – 2 Tor Nodes – 4 VLANs – Dual WAN
– $$$$
– Cheap – Simple but growing set of functjons – Bad track record in regards of security updates
– Logging – Site to site connectjons / VPN – Bandwidth limitjng – Network segmentatjon – Multj WAN – Outgoing block of traffjc
LAN DMZ IOT VOIP LAN
– Popular OS plaform for network- and security
– Juniper Junos, NetApp, NetASQ, Cisco IronPort,
– Min CPU - 500 Mhz RAM - 512 MB
– Preconfjgured and optjmized – With or without support
– Microsofu Azure / Amazon Cloud
Head office LAN 172.17.1.0/24 172.17.1.100 10.17.1.100 172.17.1.1
Head office LAN 172.17.1.0/24 172.17.1.100 10.17.1.100 172.17.1.1
– IP addresses – Networks – Hostnames – Ports
– Standard clients on OS X, iOS, Android – Interoperable
– Clients behind NAT – Very easy client confjguratjon
Headquarter LAN 172.17.1.0/24 172.17.1.100 10.17.1.100 172.17.1.1 LAN 172.18.1.0/24 172.18.1.100 172.18.1.1 10.18.1.100
– Defjnitjon of the VPN server – Open fjrewall for OpenVPN – Defjne network traffjc for VPN tunnel
– Defjnitjon VPN client
Headquarter LAN 172.17.1.0/24 172.17.1.100 10.17.1.100 172.17.1.1 LAN 172.18.1.0/24 172.18.1.100 172.18.1.1 10.18.1.100
Headquarter LAN 172.17.1.0/24 172.17.1.100 10.17.1.100 172.17.1.1 DMZ 172.17.2.0/24 172.17.2.10 LAN 172.18.1.0/24 172.18.1.100 172.18.1.1 10.18.1.100
– HQ LAN → DMZ => OK – DMZ → HQ Intranet => Error – DMZ → Internet => Error – Branch → DMZ Server => NA
– Branch → DMZ Server => OK
Headquarter LAN 172.17.1.0/24 172.17.1.100 10.17.1.100 172.17.1.1 DMZ 172.17.2.0/24 172.17.2.10 LAN 172.18.1.0/24 172.18.1.100 172.18.1.1 10.18.1.100
– Limiter: hard boundary – Traffjc Shaper (ALTQ)
– Low / no pre-investments – Enterprise level feature set – Enterprise support if needed – No running license fees of individual capabilitjes (ports / user)
– Small and medium companies – High end home offjce – Domestjc home
hagen.bauer@rusticus-consulting.de