Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN Client, ClamAV and PFblocker

    OpenVPN
    3
    10
    1.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      westlos
      last edited by

      I have VPN client set up and works great. I set up PFblocker and Squid/ClamAV set up and all looks good. All my traffic goes through the VPN client. My question, will ClamAV work inside the VPN client, which is encrypted? If not, any suggestions how to make it work.

      Also, will PFblocker work with all my traffic going through the VPN client?

      I use a Firewall Box.

      Thank you.

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @westlos
        last edited by

        @westlos

        ClamAV is antivirus software, which has nothing to do with VPNs. So, unless you mount the client disk through the VPN (bad idea) it won't do anything for it. Pfblocker is a pfsense extension, so it works on pfSense interfaces, including VPNs.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • W
          westlos
          last edited by westlos

          Thank you.

          Is it possible to have anti-virus at the firewall/router level in pfsense. I want it to pick up malware before my desktop anti-virus has to do it. I was hoping ClamAV would do that. Is this possible to do in any way?

          I do have all my traffic going through my vpn client.

          T 1 Reply Last reply Reply Quote 0
          • T
            tfbiii @westlos
            last edited by

            @westlos - Squid is an HTTP proxy and Clam is tied to that, so only traffic going through the proxy is going to be virus scanned. You would need to have the proxy sitting behind your VPN client for traffic to get scanned. Even then, it would not be full stateful inspection of all of the packets being xfered over the VPN. You will need to ensure you have AV on your end-points as well.

            W 1 Reply Last reply Reply Quote 0
            • W
              westlos @tfbiii
              last edited by

              Thank you very much.

              Is there anyway to get a malware prevention method in pfsense on a firewall box router? Or should I just rely on my AV on my computers?

              1 Reply Last reply Reply Quote 0
              • T
                tfbiii
                last edited by

                Using snort or suricata are probably your best bets to review traffic going over the various interfaces. Suricata seems to be more favored these days, but you also want to maybe dump out the logs to splunk, or an alternative, to get some better visibility into trends and attacks.

                All of this will always include having some sort of AV on your servers and end points.

                1 Reply Last reply Reply Quote 0
                • W
                  westlos
                  last edited by

                  Thank you very much.

                  Will Suricata or Snort work if all my traffic is in the VPN Client tunnel?

                  T 1 Reply Last reply Reply Quote 0
                  • T
                    tfbiii @westlos
                    last edited by

                    @westlos I honestly don't know. If the tunnel is presented as an interface, maybe? I do not have that configuration to test it with. I would install suricata and see if you are presented with the tunnel as an option to monitor.

                    1 Reply Last reply Reply Quote 0
                    • W
                      westlos
                      last edited by

                      Thank you. I will try it. My Open VPN Client is set up as an Interface.

                      Part of my question in this is can any of the PFsense packages/services access a VPN Client information since it is encrypted? Does using a VPN client put one at risk?

                      1 Reply Last reply Reply Quote 0
                      • W
                        westlos
                        last edited by westlos

                        Here is a utube from Lawrence about Suracata and encryption. I am not a IT pro. Maybe some can let me know if you find this accurate?

                        https://www.youtube.com/watch?v=7gZYbIr_Qj4

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.