Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    A Road Warrior pfSense Laptop

    Scheduled Pinned Locked Moved General pfSense Questions
    10 Posts 6 Posters 926 Views 6 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NollipfSenseN Offline
      NollipfSense
      last edited by

      Has anyone setup a road warrior laptop using pfSense firewall for traveling? My thoughts are installing pfSense on say VirtualBox with the laptop's WIFI as WAN. So, one would be routing traffic going through the physical laptop to the virtual network then back to the physical laptop. What are your thoughts and how would you achieve this? I doubt I would install any packages, but if possible, it would be Suricata or Snort.

      pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
      pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

      P 1 Reply Last reply Reply Quote 0
      • A Offline
        akuma1x
        last edited by

        I'm curious, what would be the point of running IDS/IPS on a traveling network connection? Are you dragging along (maybe on the laptop itself) servers while you travel?

        Jeff

        NollipfSenseN 1 Reply Last reply Reply Quote 1
        • NollipfSenseN Offline
          NollipfSense @akuma1x
          last edited by

          @akuma1x said in A Road Warrior pfSense Laptop:

          I'm curious, what would be the point of running IDS/IPS on a traveling network connection? Are you dragging along (maybe on the laptop itself) servers while you travel?

          Jeff

          Jeff, the laptop would be just like going to the coffee shop and accessing the WIFI. Still not sure whether I would have IDS/IPS as memory is limited. For sure, I would want a floating rule blocking in direction. So far, I have installed it on VirtualBox and trying to configure it but having difficulty access LAN. I have enabled two network adapters on VirtualBox but thinking I need to enable three network adapters.

          pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
          pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

          1 Reply Last reply Reply Quote 0
          • R Offline
            riften
            last edited by

            I had thought about it, but then thought better of it. Instead I setup openvpn. When I am out with the laptop or tablet, I just launch the VPN. It requires a TLS key to initiate the connection, a certificate+username and password to authenticate, and by not allowing a split tunnel, all my internet must go through the tunnel and into my home network, then out the PFSense router using all my rules, PFBlocker and Snort. I also loaded up the VPN on my cell phone so can even surf with that encrypted on a public wifi. The goal for me is not to have someone sniffing what I am doing, and I think this fits the need.

            1 Reply Last reply Reply Quote 1
            • noplanN Offline
              noplan
              last edited by

              use case ?

              install openVPN (no splitt tunnel allowed)
              fire it up @ starbucks and noone can sniff your traffic cuz all is goin over the vpn

              works fine her for years
              br NP

              1 Reply Last reply Reply Quote 0
              • chpalmerC Offline
                chpalmer
                last edited by

                I followed this when I did it.. https://youtu.be/7rQ-Tgt3L18

                Triggering snowflakes one by one..
                Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                noplanN 1 Reply Last reply Reply Quote 0
                • noplanN Offline
                  noplan @chpalmer
                  last edited by

                  @chpalmer
                  always a very good channel for pfS related stuff
                  yes and it works ;)

                  1 Reply Last reply Reply Quote 0
                  • P Offline
                    pi @NollipfSense
                    last edited by

                    @NollipfSense

                    Were you able to get this to work? I’d be interested in the results

                    noplanN 1 Reply Last reply Reply Quote 0
                    • noplanN Offline
                      noplan @pi
                      last edited by

                      @pi

                      of course is openVPN here running
                      with the topping of notification via mail when user was on the system
                      without prolblems

                      1 Reply Last reply Reply Quote 0
                      • NollipfSenseN Offline
                        NollipfSense
                        last edited by

                        Thanks guys for chiming in and suggesting VPN; however, the idea isn't about connecting to one's home network ... the idea assumes that one doesn't have a home network at all ... the only assumptions are that one has a laptop and one is traveling as well as the laptop has limited RAM (16 or less).

                        One avenue that looks very promising is pfSense cloud and I will look into it this week: https://www.netgate.com/solutions/pfsense/index.html#cloud

                        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.