pfSense is an open source distribution of FreeBSD-based firewall which provides a platform for flexible and powerful routing and firewalling. The versatility of pfSense presents us with a wide array of configuration options which, compared to other offerings, makes determining requirements a little more difficult and a lot more important. Through this book, you will see that pfSense offers numerous other alternatives to fit any environment's security needs.
This book follows a cookbook style to teach you how to use the features available with pfSense after determining your environment's security requirements. It covers everything from initial configuration of your network interfaces and pfSense services such as DHCP and Dynamic DNS to complex techniques to enable failover and load-balancing.
Chapter 1, Initial Configuration covers the settings needed for almost every pfSense deployment including those for a firewall, router, and wireless access point. Through the recipes in this chapter, you will learn how to install and configure pfSense with a fully-operational firewall and router.
Chapter 2, Essential Services explains how to configure the essential networking services provided by pfSense such as the DHCP server and dynamic DNS services.
Chapter 3, General Configuration describes how to configure NAT and firewall rules and the features associated with them.
Chapter 4, Virtual Private Networking describes how to configure pfSense to serve any or all of the four major VPN implementations—IPSec, L2TP, OpenVPN, and PPTP.
Chapter 5, Advanced Configuration covers advanced networking features such as configuring different types of virtual IP, creating gateways, and bridging interfaces.
Chapter 6, Redundancy, Load Balancing, and Failover contains recipes explaining how to load-balance or failover the multi-WAN interfaces to protect large and sensitive systems.
Chapter 7, Services and Maintenance describes all the networking services and features offered in pfSense such as configuring external logging (syslog server), enabling Wake On LAN (WOL), and configuring automatic configuration file backup.
Appendix A, Monitoring and Logging includes the features available in pfSense to help you monitor your system and also covers how to use different logging tools built into pfSense.
Appendix B, Determining our Hardware Requirements will show you how to choose the best pfSense configuration after you determine your firewall requirements. You will even learn how and where to deploy pfSense to fit your environment's security needs.
A working installation of pfSense 2.0 is the only requirement for the recipes in this book. Readers who are new to pfSense can follow the recipes in the appendices for instructions on how to determine what type of hardware they should install pfSense on. The minimum requirements for a pfSense installation are 500Mhz, 128MB RAM, and 1GB hard disk space. PfSense can also be installed as a virtual machine, and for convenience a VMWare image is available from the Downloads section of the pfSense website.
This book is intended for all levels of network administrators. If you are an advanced user of pfSense, then you can flip to a particular recipe and quickly accomplish the task at hand, while if you are new to pfSense, you can read chapter-by-chapter and learn all of the features of the system from the ground-up.
In this book, you will find a number of styles of text that distinguish between different kinds of information. Here are some examples of these styles, and an explanation of their meaning.
Code words in text are shown as follows: "Our public key is now located at /home/user/.ssh/id_rsa.pub
."
Any command-line input or output is written as follows:
ssh -i /home/matt/key/id_rsa [email protected]
New terms and important words are shown in bold. Words that you see on the screen, in menus or dialog boxes for example, appear in the text like this: "On the Virtual IPs tab, click the "plus" button to add a new virtual IP Address".
Feedback from our readers is always welcome. Let us know what you think about this book—what you liked or may have disliked. Reader feedback is important for us to develop titles that you really get the most out of.
To send us general feedback, simply send an e-mail to <[email protected]>
, and mention the book title via the subject of your message.
If there is a book that you need and would like to see us publish, please send us a note in the SUGGEST A TITLE form on www.packtpub.com or e-mail <[email protected]>
.
If there is a topic that you have expertise in and you are interested in either writing or contributing to a book, see our author guide on www.packtpub.com/authors.
Now that you are the proud owner of a Packt book, we have a number of things to help you to get the most from your purchase.
Although we have taken every care to ensure the accuracy of our content, mistakes do happen. If you find a mistake in one of our books—maybe a mistake in the text or the code—we would be grateful if you would report this to us. By doing so, you can save other readers from frustration and help us improve subsequent versions of this book. If you find any errata, please report them by visiting http://www.packtpub.com/support, selecting your book, clicking on the errata submission form link, and entering the details of your errata. Once your errata are verified, your submission will be accepted and the errata will be uploaded on our website, or added to any list of existing errata, under the Errata section of that title. Any existing errata can be viewed by selecting your title from http://www.packtpub.com/support.
Piracy of copyright material on the Internet is an ongoing problem across all media. At Packt, we take the protection of our copyright and licenses very seriously. If you come across any illegal copies of our works, in any form, on the Internet, please provide us with the location address or website name immediately so that we can pursue a remedy.
Please contact us at <[email protected]>
with a link to the suspected pirated material.
We appreciate your help in protecting our authors, and our ability to bring you valuable content.
You can contact us at <[email protected]>
if you are having a problem with any aspect of the book, and we will do our best to address it.