Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Data loss prevention with pfsense

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 3 Posters 3.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cehviet
      last edited by cehviet

      I need to configure pfsense to function against data loss:
      Users upload files in their local network to the internet via mediafire, googe drive, email attachments, … (they can still access the site to download files to work), I do not know pfsense Is there such a function?
      i'm from vietnam - 0919679920

      1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott
        last edited by

        PfSense is a firewall/router.  It has no such function as protecting user data.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          you could do some rules with snort.. But you have to make sure all traffic going through snort was in the clear.. So you would have to do mitm on all https sort connection.. Your best bet is just block services if your worried about users posting stuff up on say dropbox, etc.

          You have to make sure user can not just throw the data on their usb stick.  Or for that matter just email the data to outside addresses, and blocking of encrypted attachments, etc.  Or I could just zip my confidential data and leak it out

          An actual viable DLP program is very difficult to implement.. First place to start which is difficult for many companies is even classification of their data.  So while you could build your own sort of system using with opensource tools and software.. It will a long and drawn process with many many hours of configuration and setup and then maintaining..

          Not something you click install on pfsense package system and look here boss we have a fully functional DLP ;)

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • C
            cehviet
            last edited by

            Thank you for this, however my company only needs internal data control given the internet environment. It's nice that pfsense can do this.

            i'm from vietnam - 0919679920

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.