Book Image

pfSense 2.x Cookbook - Second Edition

By : David Zientara
Book Image

pfSense 2.x Cookbook - Second Edition

By: David Zientara

Overview of this book

pfSense is an open source distribution of the FreeBSD-based firewall that provides a platform for ?exible and powerful routing and firewalling. The versatility of pfSense presents us with a wide array of configuration options, which makes determining requirements a little more difficult and a lot more important compared to other offerings. pfSense 2.x Cookbook – Second Edition starts by providing you with an understanding of how to complete the basic steps needed to render a pfSense firewall operational. It starts by showing you how to set up different forms of NAT entries and firewall rules and use aliases and scheduling in firewall rules. Moving on, you will learn how to implement a captive portal set up in different ways (no authentication, user manager authentication, and RADIUS authentication), as well as NTP and SNMP configuration. You will then learn how to set up a VPN tunnel with pfSense. The book then focuses on setting up traffic shaping with pfSense, using either the built-in traffic shaping wizard, custom ?oating rules, or Snort. Toward the end, you will set up multiple WAN interfaces, load balancing and failover groups, and a CARP failover group. You will also learn how to bridge interfaces, add static routing entries, and use dynamic routing protocols via third-party packages.
Table of Contents (18 chapters)
Title Page
Copyright and Credits
About Packt
Contributors
Preface
Index

Configuring optional interfaces from the console


This recipe describes how to configure optionalinterfaces from the console menu.

Getting ready

In order to complete this recipe,at least one optional interfacemust have previously been assigned to one of the available network interfaces.

How to do it...

  1. On the console menu, type2and pressEnter.
  2. pfSense will prompt you for the number of the interface you want to configure.Type the appropriate number and pressEnter.
  3. pfSense will prompt you for the new LAN IPv4 address. Enter the new address and press Enter.
  4. pfSense will prompt you for the subnet bit count (the CIDR). Enter the bit count and pressEnter.
  5. pfSense will prompt you for the new LAN IPv4 upstream gateway address. You don’t need to specify an upstream gateway, so just pressEnter.
  6. pfSense will prompt you for the new LAN IPv6 address. If you want to specify an IPv6 address, type it here; otherwise, just pressEnter.
  7. If you entered an IPv6 address, pfSense will prompt you for the subnet bit count (CIDR). Enter the bit count and pressEnter.
  8. If you entered an IPv6 address,pfSense will prompt you for the new LAN IPv6upstream gateway address. You don’t need to specify an upstream gateway, so just pressEnter.
  9. pfSense will ask whether you want to enable the DHCP server on LAN. If you entery, you will then be prompted for the start and end addresses of the IPv4 client address range. You can enteryand type the start and end addresses, or just enternand set up DHCP later on (recommended).
  1. If you entered an IPv6 address,pfSense will ask whether you want to enable the DHCP6server on LAN. If you entery, you will then be prompted for the start and end addresses of the IPv6client address range. You can enteryand type the start and end addresses, or just enternand set up DHCP6later on (recommended).
  2. pfSense will ask you if you want to revert to HTTP for the webConfigurator protocol. Unless you have a reason for not using HTTPS for the web GUI, typenand pressEnter.
  3. The configuration process is now complete. The settings will be saved and pfSense will reload them.Repeat the process for as many optional interfaces as you wish to configure.

How it works...

This recipe describes how to set up interfaces such as an interface for a DMZ.

See also

  • TheAssigning interfaces from the consolerecipe
  • TheConfiguring a WAN interface from the consolerecipe
  • TheConfiguring a LAN interface from the consolerecipe
  • TheConfiguring VLANs from the consolerecipe
  • TheConfiguringoptional interfacesrecipe