Anyone get nist sp 800-171 CMMC Compliant using a Pfsense firewall
-
Anyone get their company CMMC Compliant using Pfsense?
I need to use the nist sp 800-171 guidelines to get cmmc compliant the firewall is only a small percentage of getting compliant but even so everyone seems to push for the big commercial firewalls I see no reason I can not do it with Pfsense.
-
@dgall One of the first questions towards compliance is what policies exist or need to be created and for which compliance level? Assuming you're starting at Level 1...
Level 1 (FCI): Basic cyber hygiene; focuses on FAR 52.204-21 requirements, including foundational firewall rules.
Level 2 (CUI): Requires adherence to NIST SP 800-171, mandating robust firewall configurations, logging, and often FIPS-validated crypto.
Level 3: Builds on Level 2 with advanced practices, requiring high-level security for CUI.
Key Firewall Requirements for CMMC 2.0:
Boundary Protection (SC.L1-3.13.1): Firewalls must define and secure external (internet) and internal (network) boundaries, monitoring traffic for malicious activity, often with SIEM integration.
Deny by Default (SC.L2-3.13.6):** Configure firewalls to block all traffic unless explicitly permitted by policy, allowing only necessary traffic on specific ports.
Content & Packet Inspection: Firewalls need capabilities to inspect packets and filter malicious content, especially at internal boundaries.
FIPS Validation (SC.L2-3.13.11): If the firewall encrypts CUI, it must use FIPS 140-2 or FIPS 140-3 validated cryptography.
Access Control: Controls must limit and verify connections to external systems, requiring firewalls to enforce these rules.
Optionally AI may be helpful for a Level 1; where do I start type situation but FWIW you obviously can't trust AI not to hallucinate answers/guidelines you'd be following. You'll need access to a qualified CMMC 2.0 Assessor to lead that kind of effort. Of course under no circumstance should private/privileged data ever be uploaded to AI. The point is that one way or another you can get in the weeds pretty quick without professional help. Say for example that your F/W needs to default deny all outbound traffic? That in itself is a pretty big lift just to identify what needs to be permitted outbound and then create all those rules (by port or IP? or some other combination restrictive policy. You'll need to have those policies thought out and written before trying to adhere to something that's not clearly defined and obviously no two networks are alike. No obvious reason pfSense can't be used in a CMMC 2.0 environment but what it would take to get there would ultimately be between you and a certified assessor.
-
I wish, I could use pfSense for CMMC compliance. From what I understand firewall crypto hardware needs to be FIPS validated which Netgate hardware is not:
https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules
Please correct me if I'm wrong.
-
This post is deleted! -
This post is deleted! -
the PDF file link for firewall requirements for Government work.
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-41r1.pdf
and thats just a small portion of what needs to be done setting up the network is the hard part. -
@dgall said in Anyone get nist sp 800-171 CMMC Compliant using a Pfsense firewall:
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-41r1.pdf
Are you hiring? Is the Palo Alto guy fired yet?
Privacy Policy · Cookie Policy