In this post we are going to cover:
How to install pfsense firewall
How to configure and add VLAN on firewall to connect different network
We are going to install this virtual pfsense firewall in NUC2. One of the purpose of this firewall is to provide internet to all of the virtual machines in militarized zones and database zone via LAN segment as their network is different.
Start writing or type / to choose a block
Open chrome browser, search for pfsense firewall iso download and click on the second result
Start writing or type / to choose a block
Click download
Start writing or type / to choose a block
Decompressed the downloaded file
Start writing or type / to choose a block
Click create a new virtual machines
Start writing or type / to choose a block
Click next
Start writing or type / to choose a block
Tick I will install the operating system and click next
Start writing or type / to choose a block
Tick other for guest operating system, choose FreeBSD 11 64bit and click next
Start writing or type / to choose a block
Renamed the virtual machine and click next
Start writing or type / to choose a block
Key in 20GB for disk disk size, tick store virtual disk as single file and click next
Start writing or type / to choose a block
Click customize hardware
Start writing or type / to choose a block
Key in 2GB for memory (2048MB in binary)
Start writing or type / to choose a block
Configure number of processor as above
Start writing or type / to choose a block
change to bridge and tick replicate physical network
Start writing or type / to choose a block
Click add, tick network adapter and click finish
Start writing or type / to choose a block
Tick LAN segment and click LAN segment next to advanced
Start writing or type / to choose a block
Click add and named the new LAN segment FIREWALL
Start writing or type / to choose a block
Choose the newly added adapter
Start writing or type / to choose a block
Tick use ISO image file and click browse to locate the pfsense firewall ISO image that we download earlier then click ok
Start writing or type / to choose a block
Click finish
Start writing or type / to choose a block
Click power on this virtual machine
Start writing or type / to choose a block
Press enter to accept
Start writing or type / to choose a block
Press enter
Start writing or type / to choose a block
Press enter
Start writing or type / to choose a block
Press OK to auto partition
Start writing or type / to choose a block
Move to no and press enter
Start writing or type / to choose a block
Move to reboot and press reboot
Start writing or type / to choose a block
Start writing or type / to choose a block
Start writing or type / to choose a block
Start writing or type / to choose a block
On all Virtual machine in Militarized zone and database zone, add a new LAN segment network adapter and named it FIREWALL:
Click edit virtual machine settings
Click add
Choose network adapter and click finish
Tick LAN segment and choose FIREWALL LAN segment from the drop down list
lick edit virtual machine settings
Click add
Choose network adapter and click finish
Tick LAN segment and choose FIREWALL LAN segment from the drop down list
Click edit virtual machine settings
Click add, choose network adapter and click finish
Tick LAN segment and choose FIREWALL LAN segment from the drop down list
Click edit virtual machine settings
Click add
choose network adapter and click finish
Tick LAN segment and choose FIREWALL LAN segment from the drop down list
Click edit virtual machine settings
Click add
choose network adapter and click finish
Tick LAN segment and choose FIREWALL LAN segment from the drop down list
Click edit virtual machine settings
Click Add
choose network adapter and click finish
Tick LAN segment and choose FIREWALL LAN segment from the drop down list
How to add VLAN on pfsense firewall:
On any virtual machines that is running on NUC2 and connect to pfsense via FIREWALL LAN segment network adapter
open chrome browser
type IP address of 192.168.1.1 in searchbox
Key in default username and password which is admin and pfsesne to login
Click next
Click next
Click next
Change timezone to asia/Kuala_Lumpur
click next
Click next
You can choose to change admin account password here
Click reload
Click finish
click accept
How to setup VLAN:
Under interfaces, click assignments
Click on VLANs tab and click add
Configure as shown above and click save
Repeat the progress, press add to add a new vlan and configure as above then click yes
Go to interface assignments and click add to add the two VLAN that has been created
Click save after two vlan interfaces has been added
Back to pfsense terminal, Enter 2
Configure as shown above
Repeat the same step for second VLAN
After this restart all virtual machines on militarized zone and database zone, it should get an IP from pfsense DHCP server and internet access.
Comments