How To Setup A Transparent Bridge & Firewall With pfsense and Suricata

Поділитися
Вставка
  • Опубліковано 29 сер 2024
  • Amazon Affiliate Store
    ➡️ www.amazon.com...
    Gear we used on Kit (affiliate Links)
    ➡️ kit.co/lawrenc...
    Try ITProTV free of charge and get 30% off!
    ➡️ go.itpro.tv/lts
    Use OfferCode LTSERVICES to get 5% off your order at
    ➡️ lawrence.video...
    Tesla Referral Program Offer
    🚘 www.tesla.com/...
    Lawrence Systems Shirts and Swag
    👕 teespring.com/...
    Digital Ocean Offer Code
    ➡️ m.do.co/c/85de...
    HostiFi UniFi Cloud Hosting Service
    ➡️ hostifi.net/?v...
    Protect you privacy with a VPN from Private Internet Access
    ➡️ www.privateint...
    Google Fi Service Referral Code
    📱g.co/fi/r/TA02XR
    More Of Our Affiliates that help us out and can get you discounts!
    ➡️ www.lawrencesy...
    Twitter
    🐦 / tomlawrencetech
    Patreon
    🔗 / lawrencesystems
    Our Forums
    🔗 forums.lawrenc...
    GitHub
    🔗 github.com/law...
    Discord
    🔗 / discord
    Our Web Site
    🔗 www.lawrencesy...
    docs.netgate.c...
    Rackmount.IT Rack Mount Kit
    amzn.to/2Dctyog
    #pfsense #Firewalls
  • Наука та технологія

КОМЕНТАРІ • 48

  • @juniorst
    @juniorst 4 роки тому +3

    Hello from Brazil, Lawrence! I'm addicted in yours videos. Especially the ones about PfSense and Unify! Please, continue with this amazing "job".

  • @darrylmackay1204
    @darrylmackay1204 3 роки тому

    Hi Lawrence, thank you for the video tutorial. It has helped me to setup Suricata running on a separate pfSense device to monitor two LTE connections through bridging interfaces on a albeit primitive system. These two LTE connections then feed into a pfSense firewall with gateway failover and monitoring.

  • @kirksteinklauber260
    @kirksteinklauber260 4 роки тому +1

    Thanks for this guide!!! very useful.! One of the use cases that I am thinking to use this mode is to introduce it as Layer 2 IPS solution to complement and existing edge router / firewall that doesn't have these capabilities and the client doesn't want to replace this layer but we want enhanced security. It will be in an scenario like this: ISP Edge Router / Firewall PFSense Transparent Bridge L3 Core Switch(es) Access Switches and Wireless Access Points

    • @abhi991986
      @abhi991986 4 роки тому +1

      Hi Kirk, I am trying to achieve the similar kind of functionality in which i have my internet router-->checkpoint fw-->PFSENSE-->Core switch.. Dont know how to place this PFSENSE in L2 mode so that i dont have to make any routing changes.. Can you suggest something??

  • @distantanomaly9649
    @distantanomaly9649 4 роки тому +2

    I've been trying to successfully do this for a few months. Thank you so much Lawrence for the tutorial

    • @waynebruno7051
      @waynebruno7051 3 роки тому

      you all probably dont care at all but does someone know of a trick to get back into an instagram account?
      I somehow forgot the account password. I love any tricks you can offer me.

    • @waynebruno7051
      @waynebruno7051 3 роки тому

      @Curtis Preston Thanks for your reply. I found the site on google and Im trying it out now.
      Seems to take quite some time so I will get back to you later with my results.

    • @waynebruno7051
      @waynebruno7051 3 роки тому

      @Curtis Preston It worked and I finally got access to my account again. I'm so happy!
      Thanks so much, you saved my ass !

    • @curtispreston9895
      @curtispreston9895 3 роки тому

      @Wayne Bruno Happy to help :D

  • @jrequejo1
    @jrequejo1 4 роки тому +1

    Last time I set up a bridge in pfsense I had a lot of trouble routing packets between the member interfaces (as opposed to from another subnet to a member interface). I have found out that you need to add a rule on each member interface which basically allows routing from anywhere to everywhere for all protocols. Only then it worked.

  • @ronhenry2025
    @ronhenry2025 3 роки тому

    Thank you Jedi Master Guru Sensei, this is exactly what I was looking for!

  • @MrDarkDragone
    @MrDarkDragone 3 роки тому +2

    In setting pfsense up this way I see you mention you can setup rules and packet sniffing. Would you also be able to do traffic shaping like limiting bandwidth to certain devices? or at the very least see what is in real-time using bandwidth.

  • @robintodd3901
    @robintodd3901 3 роки тому

    Can I use this idea to bridge the wan to opt1 for example so that I can use a second pfsense router and there for there won’t be double natting issues on the second router while leaving a lan on the first which would act normal. I ask this for point to point use. Thanx Tom. Your videos have been so useful and real help in the past.

  • @alienJIZ1990
    @alienJIZ1990 2 роки тому

    I think a similar comparison to using pfsense as a software switch/bridge would be emulating a video game console via software vs using FPGA hardware. Always best to cut the extra software emulation layer if possible and rely only on the hardware

  • @d_must4309
    @d_must4309 4 роки тому

    I'd really appreciate it if you did a proper guide on how to set up an IPSEc tunnel between Pfsense and Draytek Vigor router. There seems to be so little documentation out there.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 роки тому

      There is plenty of pfsense documentation, not sure about Draytek as I never used one.

  • @ZainalNetworkTutoriaL
    @ZainalNetworkTutoriaL Рік тому

    I have tried it and for the WAN and LAN ports I made it a bridge but the results are not maximal, does it really have to be done on the OPT port so that it can work optimally ??

  • @justbored3.14
    @justbored3.14 2 роки тому

    what do you recommend for a firewall only solution for a regular home ? i was thinking about a blue plus firewalla ?

  • @bhangepatilakhilesh
    @bhangepatilakhilesh 2 роки тому

    Hi Lawrence- Really like your pFsense videos (I switched over a few years ago after watching your videos).
    Question: How do you configure VLANS over a bridge? I have VLANS for various segments and have 2 managed switches connecting to the pfsense appliance but I get VLANS only on 1 port of pfsense.

  • @SirWhatthefuckever
    @SirWhatthefuckever 3 роки тому

    Thanks for an awesome video!
    Is it possible to use PfSense in bridge mode as a transparent ad blocker?
    I'd like to build a device that provides Pi-hole-like functionality but without it having to be the DNS server for the network. It would need a minimum of three ports: 2 for the bridge (internal and external) + 1 for management.
    In a "router on a stick" topology, it could be plugged in, on layer 2, between the router and the switch and sniff (and selectively drop) DNS queries based on the common advertiser blacklists used in Pi-hole and PfBlockerNG.
    Seems like PFsense is - again - the best tool for that job?

  • @pooley999
    @pooley999 4 роки тому

    Great tutorial. However, My Pfsense is the most frontal point of my network with the PUBlic IP assigned to it. It handles my DHCP and routing etc. I have Suricata running on the firewall, writing locally to a JSON file and use filebeat to export those IDS logs to an elastic stack. Besides seeing the states (Which would see anyway) Whats the real advantage of this against my setup?

  • @stephenmaryland7939
    @stephenmaryland7939 8 місяців тому

    I assume this is what I would do if I have a UDM Pro managing my network and put this between the WAN Modem and the UDM Pro to have better firewall IDS features?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  8 місяців тому

      The UDM Pro DOES NOT have better firewall IDS features.

  • @Rickety3263
    @Rickety3263 3 роки тому

    I'd like to bridge a 10Gbe SFP+ Port and a 1Gb Base-T together as my LAN, so that all the devices share the same address space. Each port will connect to a 10Gbe and 1Gb switch respectively. Will I experience any sort of performance hits?
    Am I better off just daisy chaining the 1Gbit switch off of the 10Gb switch?
    The NIC's are Intel chipsets, and properly configured, and the pfsense hardware is a Dell optiplex with a quad core i5-3470 with 8gb ram and AES-NI on-chip.

  • @Xotty
    @Xotty 2 роки тому

    The moment I create the bridge my Pfsense goes crazy and CPU shoots up to 100% I have not configured anything else yet. Nothing is plugged in to any of the bridged interfaces only to WAN. Any tips why this could be? Cheers

  • @paraffin79
    @paraffin79 4 роки тому +2

    Why do you use Suricata vs Snort Plugin, is one better or easier to setup?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 роки тому +2

      resources.infosecinstitute.com/open-source-ids-snort-suricata/

    • @paraffin79
      @paraffin79 4 роки тому

      Thanks, will look into it as we use Snort mainly just because it had a good setup guide online

  • @zach115th
    @zach115th 3 роки тому +1

    Do I need to setup a vlan on the transparent pfsense for every vlan that will be passing through it?

  • @ne0dam
    @ne0dam 4 роки тому

    Thanks for the video. Could this bridge be made with LAN and OpenVPN interfaces to, for example, give DHCP reply by a LAN DHCP Server to OpenVPN Client Request??

  • @yashar6909
    @yashar6909 4 роки тому

    Could you route packets, to create a mitm as transparent as possible? So say, you want to send port 80 or 443 to a burpsuite box on a different address listening on 0.0.0.0:8080. The idea, is dropping a Raspberry Pi, and modifying requests and responses for a red team scenario

    • @yashar6909
      @yashar6909 4 роки тому

      on a side note, the box you want to test has a static IP and no DHCP server is possible.

  • @danieleperera6788
    @danieleperera6788 3 роки тому

    Can I do a transparent bridge with sg-2100?

  • @mohsinalibhatti7072
    @mohsinalibhatti7072 4 роки тому

    How can we check previous days browsing data? Ntop only shows the current flows

    • @firebladek3r1
      @firebladek3r1 4 роки тому +1

      Im also looking for monthly reports

    • @mohsinalibhatti7072
      @mohsinalibhatti7072 4 роки тому

      We can see monthly data downloads but we can't see what he was browsing on internet.

  • @jasonevenson3392
    @jasonevenson3392 4 роки тому

    Could you use pfblockerNG with pfsense in transparent mode?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  4 роки тому

      you could do the IP blocking, but the DNS filtering would not be able to route to the internal 1x1 pixel sinkhole

    • @jasonevenson3392
      @jasonevenson3392 4 роки тому

      @@LAWRENCESYSTEMS and being in transparent you couldn't have the pfsense box be the DNS for the router correct?

  • @davidg4512
    @davidg4512 4 роки тому

    I saw that tesla truck when you were switching windows. I think it looks pretty dumb. What you're opinion on it?

    • @AndrewJamison79
      @AndrewJamison79 4 роки тому

      Elon did say it was going to be one of those things you either love or hate

  • @shafiqurrehman
    @shafiqurrehman 4 роки тому +3

    Awesome videos but please try to stay on one topic and don't just start explaining other topics in a setup. a newbie gets confused while following you.

  • @edbouhl3100
    @edbouhl3100 2 роки тому

    Edit: Nevermind, found your video ua-cam.com/video/VULKulpXBYU/v-deo.html. VERY helpful, thank you very much for making it!
    Can a bridge be used to increase connection speed? For example, could I combine three 1 Gb wired connections between my pfSense server and main switch into a named virtual bridge and use this as my LAN connection at 3 Gb? If you’ve already covered this elsewhere I wasn’t able to find it, apologies again.
    Edit: To others, the answer is yes, sort of. One transaction won’t see an increase since it wont be split between connections But simultaneously transactions would. See also ua-cam.com/video/JxuYj5jw8y8/v-deo.html, and ua-cam.com/video/RgXiQlUguec/v-deo.html.

  • @paraffin79
    @paraffin79 4 роки тому

    I watched this video ua-cam.com/video/-_8x7_9DKxs/v-deo.html from Battle Nonsense and as you are interested in your son's gaming experience wondered if you knew how to get this working properly on the pfsense