Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Setup Still Relevant? Hell YES!

    Scheduled Pinned Locked Moved IDS/IPS
    3 Posts 1 Posters 614 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NollipfSenseN
      NollipfSense
      last edited by

      I have had my PFSense machine up and running now since October of last year. Now, I shall fine tune as the system should have learn my moves or states. I have Snort, PFBlockerNG, Suricata and Squid's ClamAV Antivirus packages running as well. I have been reading this thread: https://forum.pfsense.org/index.php?topic=78062.0 hoping to use as a guide in helping me to fine tune; however, I wondered whether it's relevant today in the sense that all packages have evolved and lots of the scripts have been included in the offerings now.

      Things that seem relevant are the firewall aliases and rules; however, it's lots of reading and one can get lost easily in some of the steps. So, how would you approach using that guide today since it was originally for 2014? Hints would be appreciated. My only addition to firewall other than default is forced DNS to PFSense via OpenDNS (https://doc.pfsense.org/index.php/Blocking_DNS_queries_to_external_resolvers).

      For the packages installed, I followed what Lawrence system posted to YouTube.

      pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
      pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

      1 Reply Last reply Reply Quote 0
      • NollipfSenseN
        NollipfSense
        last edited by

        So, I swallowed the pill. I began setting up as directed…I ran into the floating rule blocking everything...but, I like how it works; so, instead of any direction, I set  inbound. Later, I read I wasn't alone experience it blocking everything.

        So, now I am going through the entire thread...I still have not implemented any script nor install Cron because I notice while I boot my machine that Cron started...there is no service though.

        I hope BBcan177 would chime in because PFBlockerNG has a wide range of IP list already. I am glad I saw his suggestion to log the floating rule. I am currently on page 9...long way to go.

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        1 Reply Last reply Reply Quote 0
        • NollipfSenseN
          NollipfSense
          last edited by

          Okay, I read through the entire thread…one doesn't need to implement all those scripts as one can use the custom DNSBL Feed rules into PFBlockng...really grateful to BBcan177.

          I also changed firewall flowing rule to block with the quick set checked, interface: WAN, direction: any, family address: IPv4+IPv6,  protocol: TCP, source: any, destination: any, destination port range: other, then from the WebGUI to the WebGUI.

          I also added a second firewall flowing rule to block with the quick set checked, interface: WAN, direction: in, family address: IPv4+IPv6, protocol: TCP, source: any, destination: any, destination port range: other, then from outgoing privilege ports to outgoing privilege ports.

          Extremely grateful to jflsakfja as well thank you and wish you all the best.

          pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
          pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.