Book Image

OPNsense Beginner to Professional

By : Julio Cesar Bueno de Camargo
5 (1)
Book Image

OPNsense Beginner to Professional

5 (1)
By: Julio Cesar Bueno de Camargo

Overview of this book

OPNsense is one of the most powerful open source firewalls and routing platforms available. With OPNsense, you can now protect networks using features that were only previously available to closed source commercial firewalls. This book is a practical guide to building a comprehensive network defense strategy using OPNsense. You’ll start with the basics, understanding how to install, configure, and protect network resources using native features and additional OPNsense plugins. Next, you’ll explore real-world examples to gain in-depth knowledge of firewalls and network defense. You’ll then focus on boosting your network defense, preventing cyber threats, and improving your knowledge of firewalling using this open source security platform. By the end of this OPNsense book, you’ll be able to install, configure, and manage the OPNsense firewall by making the most of its features.
Table of Contents (25 chapters)
1
Section 1: Initial Configuration
6
Section 2: Securing the Network
13
Section 3: Going beyond the Firewall

High availability concepts

Let's introduce this topic with an aviation example. At the beginning of heavier-than-air history, airplanes had just one engine to fly from one location to another. As aviation grew, the demand for long-range flights increased, and new projects that used two or more engines began. Nowadays, it is possible to cross the oceans with a twin-engine plane thanks to reliable engine technology and the Extended-range Twin-engine Operations Performance Standards (ETOPS). But even with all this technology, two engines are required to keep a long-haul flight within safety standards. Developments similar to the aviation industry also happened in the IT world – redundancy standards/protocols were created to keep the availability of the systems at acceptable levels for the business.

In OPNsense, the Common Address Redundancy Protocol (CARP) is a protocol that ensures that the network interfaces of two or more firewalls keep operating in case of a hardware...