PF Sense Setup
-
@jsmiddleton4 Yes the location that has the most, hard-wired connections running to it is the main floor, where the modem/router is at because originally all of those were connected to the back of the modem. Id prefer to leave the pfsense box and netgear in the basment that was part of the whole putting my main IT equipment in the basement.
Realistically the only thing I am seeing that is the simplest solution is running another cable up from the basement (plugged into netgear), plugged into a switch in the main floor to then plug in the main fl rm 1, upstairs rm1 & upstairs rm2 devices to get those hardwired devices talking to each other. I do not know if there is another solution that is simpler and I dont know if this would be required to get the wireless devices to talk to each other (as phones are always wireless and chrome casts are wireless as well).
EDIT: i would prefer to get the wireless devics somehow setup this weekend so I can finally have this done but i dont know what my next steps are as far as all the information I gave in the above post. Once i get this done then I can start installing PF Sense packages for bandwidth monitoring and other things, etc.
EDIT: Realistically, idk if i will be able to actually run the cable this weekend as my 'fish sticks' are still on there way, said to be delivered monday and as far as cable, im not sure how long of a cable i'll actually need. I may just purchase a pre-crimped one instead of trying to end it myself because i suck at that. I have my hotspot, if needed for wireless till I can get this whole thing resolved.
-
@travelmore
Getting the wireless stuff up and running being they're AP's won't be difficult.The Belkin when in AP mode it still has LAN ports that work like a switch?
For now would you be okay with getting stuff setup and running the easiest way possible and then later run ethernet cable?
For now the easiest way to get you up and running is put the PFSense box where the most ethernet cables exist already.
In doing and learning "IT" stuff in your lab having the PFSense box right there isn't all that necessary. Once you pull cables have it there, on its own monitor, etc., would be nice.
I was serious about sending you switches I have in my garage. At least 2 of them are "managed", although just barely managed. What that means is you can create VLANS and bond ethernet ports together so a pair acts as one. Learning how to create VLANS would be valuable. Get that sorted and then do real or live VLANS in PFSense. You can get very fancy with VLANS. You'd have a practice platform with the switches.
https://www.netgear.com/support/product/GSS108E.aspx
For now IF you want to, move the PFSense box to the main floor, connect the one ethernet cable already there, main floor to basement, to the switch that is in the basement. You're done with the basement. Anything else you want to connect in the basement you plug into the switch.
On the main floor, use a short ethernet cable to connect the modem's WAN port to the PFSense box WAN port.
Connect a switch to the PFSense LAN port.
Connect everything else including the cable running downstairs to the PFsense connected switch.
If you need more ports, connect the switch coming off the PFSense LAN port to another switch.
Use the existing ethernet cables to other rooms and attach the AP's.
IF you need the POE adapter for the Uni AP's, that'd be a switch on the main floor by the PFSense box. Then your Uni ap's connect to the POE capable switch. The POE capable switch to the PFSense box.
IF where you need an AP and its wired and you also need a switch, use the Belkin there. It'd be both a wireless AP and an wired switch.
That is what I'd recommend for now. Over time? You have time to pull some cables and change the topology of where stuff is placed.
Also over time can tackle the existing MoCA wireless extender use/setup.
Edit:
"pre-crimped one"
If you know how to put low voltage existing construction box in your sheet rock no need to buy pre-crimped. The network plates/pop in receptacles are a piece of cake. Color coded to get pairs matched correctly, etc.
-
Just an example.
https://www.amazon.com/BUPLDET-Port-Ethernet-Punch-Plate/dp/B08LDNT2KS/ref=sr_1_7?crid=2E54G6GJFRFT8&keywords=ethernet+cover+plate+jack&qid=1641657943&sprefix=ethernet+cover+plats+jacks%2Caps%2C88&sr=8-7
-
@jsmiddleton4 As always, thank you for your help! Hello, what a day! So, I did as you suggested and moved the PF Sense box in the main floor near the router, then grabbed an old 3Com 24port super stack switch I had to plug everything into. Wired devices are reachable from a wireless PC...so SUCCESS!!!!!!!!!!!
What I didnt mention above was I had a MIL-S2400S switch, that I tried to use to connect the modem and pf sense and realized some ports were bad on the switch but some were good...so i plugged everything in to the good ports, only to realize about half an hr later the switch kept dropping issues, so i removed it and plugged in the old 3Com I had (mentioned above) and its been working great since. Needless to say I am throwing that MIL-S2400S switch out! That whole process took a while because I went through and tested every port only to find out later it was rubbish from the start lol.
At least for the time being until I can run that cable then move things but I feel like that will be simple now that the main bulk of everything is working. I added my old belkin router as an AP to replace the Hitron coax extender.
I messed around w/that hitron extender and logged in and couldnt change anything, everything w/old settings was greyed out (which i expect that due to the modem being in bridge). I reset the hitron extender to fac. def. settings and still everything was greyed out and I couldnt make changes to it (even though it did have the facto ssid). That is fine so I unplugged that and put it off to the side and as mentioned setup my belkin router to be an AP. (and if needed it should suffice as a dumb switch to because there are a few ports on the back of it).
All that being said, here is the current setup that is allowing my wired devices to talk to wired.
That being said, I have no plugins installed in PF Sense and I was looking at this article, https://forum.netgate.com/topic/150293/view-all-connected-devices/2
to see how I can view all devices in PF Sense now that everything is talking to each other but im unclear on that article.Currently, in PF Sense these are what is displayed:
SERVICES/dhcp server/ lan, this is the only thing checked on that page and I have my subnet, subnet mask, and avaliable range set.
further down on the DNS Resolver/Gen. settings page:
I dont know if there is anything else to put on the DNS settings, everything is left as default from when PF Sense is originally installed. The only thing I ever did was the general basic setup of setting the range and enabling DHCP.
Note: I did not do anything w/the firewall settings, everything is literally default and as is which I hope is fine for now.
Now, its a matter of:
- How do I see all the devices connected (wired and wireless)?
- What packages should I install, to monitor bandwidth and devices, etc?
- I am curious, is there any alert that can tell you when a new device has tried to access your network?
- This concerns me, why am I getting this message when going to my PFSense box (hardwired) from my wireless pc?
I have also noticed this error when going to some sites from my wireless pc:
The part where it says 'not secure', as well as that warning in the center of the page is what I find concerning. I am guessing it's just a setting in PFSense but not sure and wanted to ask here since it only started once I got all this setup today.
-
The cert error when connecting to pfSense is expected because it's a self signed cert.
The second error looks like that site actually has an expired cert.Steve
-
Congrats again! Way to stick with it.
There’s some stuff that has to be right for DHCP6 to work so not surprised if its not working right off the bat.
Look at you… network topology expert!
Yes when the bulk is setup in a way that its as easy or straightforward as possible it is WAY easier to tweak things later on.
I don’t use DNSSEC by the way. Would at least be worth asking someone who would know, not me, if DNSSEC is triggering those alerts. I have several devices I have to tell Firefox its gonna be okay, go ahead and access the device. Only do so for stuff on my own network. I’d never do that if I was accessing a web site.
The firewall log tells you what is knocking on your door.
There are several packages which can tell you all sorts of stuff about your PFSense box, clients, usage, etc.
You ready to tackle DHCP6?
The Netgate doc is clear and easy to follow. The only thing is some ISP’s you have to pick some of the misc. options which are not on the step by step.
Edit: There’s a ton of video tutorials fro DHCP6 and pfsense too.
-
@stephenw10 Thank you!
-
@jsmiddleton4 Thanks! Not ready to tackle DHCP 6 yet. Id like to get plugins installed and some things configured first so I can actually see whats on my network and what devices are pulling bandwidth. Then tackle DHCP 6. I'll check out the firewall log.
-
-
It looks to me the only way to see if you can use your existing MoCA wireless extender is get another Ethernet to MoCA adapter, hook em up and see.
-
@jsmiddleton4 yeah i gave up on that extender. i just setup another AP instead.
Did you mean ntopng plugin or pfBlocker-NG Package plugin? -
Pf blocker Dev version.
It’d drive nuts so I’d probably order an adapter off Amazon, if didn’t work, send it back.
Reads like all the MoCA stuff is automatic. Only set up is for wireless options.
There are MoCA pairs that are designed to use a coax run like yours. Not too expensive but still there’s a cost.
If you can run Ethernet cabling always a better idea.
-
It’ll be better when you run into issues now to post a dedicated thread. As you WILL run into issues.
Glad to help with getting the hardware sorted and I’m confident in that regards. With PFSense stuff though, others will have to help. I’ve got some of it down but just skimming the surface myself.
If you ever want to update your 3020 much of it can be easily. Only goofy thing Dell did with it is the power supply connections on the motherboard.
-
@jsmiddleton4 I might look into the MoCA wireless extender, we'll see how a few weeks go with this setup. Currently, everything seems to be going pretty smoothly (even though some of my Unifi APs are no longer supported, they still hold up okay). Though my head is screaming security issue throw them away since they aren't supported for updates & patches anymore. Though, I would through them out eventually if they got too out of dated id put them in a lab environment.
I'll look into the PF Blocker Dev version. I installed a handful of plugins lastnight (bandwidthd, darkstat, ntopng, status traffic controls, etc.) I really like ntopng so far! I def. need to understand it more and dig deeper with it. So much to learn w/all of this but its a good thing.
Yes, I will post in a new/deticated thread if i run into issues. Thanks for the heads up on the 3020 update info, i'll keep that in mind. Right now I just have a 64gb ssd in the 3020 running pf sense. Figured thats good enough for pf sense as long as it has 2 NIC connections (which we know it does lol).
-
You're doing great.
Its probably very unlikely anyone is gonna to find your AP's and hack through them into the dark web.....
Possible sure. Likely?
There's several Wifi6 AX POE AP's now with 2.5gb ports. 2.5gb is becoming more and more common. I wouldn't buy an AP that isn't just for future protection. Prices are coming down too.
With POE injectors you don't need a fancy POE switch either.
Given every thing you've done so far really, IPV6 should be no problem. Then you've got all that setup stuff done. There's only a couple of settings that you have to play with, like prefix delegation, pool size, range for the RA stuff in the DHCP6 Server. While it isn't critical it does belong in the "setup" set of stuff.
-
I think this is still under the “Setup” category.
To eliminate the need for a switch right away coming off the PFSense box I have serveral NIC’s in my PFSense box. It is that first switch.
That is the main reason I like the 390’s or 3010’s, multiple PCE-E slots. You can do so on the 3020 as well.
Some folks do so and make each NIC a separate “network” or VLAN kind of thing.
Me I bridge them so PFSense looks at all of the NIC’s as one thing, like a switch. Or like the Ethernet ports on the typical router.
1gb NIC’s are cheapo.
I use 2.5gb and even those are getting more reasonable.
You can even use dual port NIC’s. Pop in 3 of them, use the built in LAN port as the WAN, and you have a 6 port router.
Bridge mode is very easy to setup.
There’s no practical difference between coming off one Ethernet port and then to a switch. For my setting it is an office space and had to make sure there wasn’t the clutter of wires to this, wires to that, etc.
If power goes out the switch is one less device I have to plug into the UPS. PFSense box stays on, switch stays on.
I actually have a dual port 2.5gb Intel based NIC coming from BHPhoto for a new PFSense box build using a 3010. Doing so with my grandson who wants to learn. His favorite part is the disassembly phase however. Which we’ll do first to clean and sort the used 3010 box.
-
@jsmiddleton4 said in PF Sense Setup:
His favorite part is the disassembly phase
Awesome that he shows an interest at all though.
-
Gave him a Snap Circuit kit, one of the big ones, for Christmas. He’s building electronic projects non-stop. He’s only 7.
-
@jsmiddleton4 Thank you. I appreciate that! You are right, probably no one is going to hack into my APs but being in IT for years, I also know how us IT nerds are, so its more I want to just be aware. I cant be aware of everything nor will i know how everything works but the more I know about my network and what looks right/doesnt the better off i'll be. Its all fun and learning for me especially now that im in more of a project management role instead of IT i actually WANT to work on these types of projects and learn for fun.
Let alone, watching Mr. Robot did not help in the 'people are hacking you' thoughts. lol.
DHCP6 will come down the road. My next goal is setting the plugins up and watching everything. I am curious because i just got alerted that im over my data cap again!
Something is def. off since its not every month. Ive already got a good idea of whats on my network but i've been running ip scanner for a few months now and just noticed a few more things that im gonna double-check.
Good information to note in regards to the NICs etc.