Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Anyone get nist sp 800-171 CMMC Compliant using a Pfsense firewall

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 4 Posters 1.9k Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      dgall
      last edited by

      Anyone get their company CMMC Compliant using Pfsense?

      I need to use the nist sp 800-171 guidelines to get cmmc compliant the firewall is only a small percentage of getting compliant but even so everyone seems to push for the big commercial firewalls I see no reason I can not do it with Pfsense.

      G D 2 Replies Last reply Reply Quote 0
      • G Offline
        goulou @dgall
        last edited by

        @dgall One of the first questions towards compliance is what policies exist or need to be created and for which compliance level? Assuming you're starting at Level 1...

        Level 1 (FCI): Basic cyber hygiene; focuses on FAR 52.204-21 requirements, including foundational firewall rules.

        Level 2 (CUI): Requires adherence to NIST SP 800-171, mandating robust firewall configurations, logging, and often FIPS-validated crypto.

        Level 3: Builds on Level 2 with advanced practices, requiring high-level security for CUI.

        Key Firewall Requirements for CMMC 2.0:

        Boundary Protection (SC.L1-3.13.1): Firewalls must define and secure external (internet) and internal (network) boundaries, monitoring traffic for malicious activity, often with SIEM integration.

        Deny by Default (SC.L2-3.13.6):** Configure firewalls to block all traffic unless explicitly permitted by policy, allowing only necessary traffic on specific ports.

        Content & Packet Inspection: Firewalls need capabilities to inspect packets and filter malicious content, especially at internal boundaries.

        FIPS Validation (SC.L2-3.13.11): If the firewall encrypts CUI, it must use FIPS 140-2 or FIPS 140-3 validated cryptography.

        Access Control: Controls must limit and verify connections to external systems, requiring firewalls to enforce these rules.

        Optionally AI may be helpful for a Level 1; where do I start type situation but FWIW you obviously can't trust AI not to hallucinate answers/guidelines you'd be following. You'll need access to a qualified CMMC 2.0 Assessor to lead that kind of effort. Of course under no circumstance should private/privileged data ever be uploaded to AI. The point is that one way or another you can get in the weeds pretty quick without professional help. Say for example that your F/W needs to default deny all outbound traffic? That in itself is a pretty big lift just to identify what needs to be permitted outbound and then create all those rules (by port or IP? or some other combination restrictive policy. You'll need to have those policies thought out and written before trying to adhere to something that's not clearly defined and obviously no two networks are alike. No obvious reason pfSense can't be used in a CMMC 2.0 environment but what it would take to get there would ultimately be between you and a certified assessor.

        1 Reply Last reply Reply Quote 0
        • J Offline
          jake Rebel Alliance
          last edited by jake

          I wish, I could use pfSense for CMMC compliance. From what I understand firewall crypto hardware needs to be FIPS validated which Netgate hardware is not:

          https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules

          Please correct me if I'm wrong.

          D 2 Replies Last reply Reply Quote 0
          • D Offline
            dgall @jake
            last edited by

            This post is deleted!
            1 Reply Last reply Reply Quote 0
            • D Offline
              dgall @jake
              last edited by

              This post is deleted!
              1 Reply Last reply Reply Quote 0
              • D Offline
                dgall @dgall
                last edited by

                the PDF file link for firewall requirements for Government work.
                https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-41r1.pdf
                and thats just a small portion of what needs to be done setting up the network is the hard part.

                tinfoilmattT 1 Reply Last reply Reply Quote 0
                • tinfoilmattT Offline
                  tinfoilmatt LAYER 8 @dgall
                  last edited by

                  @dgall said in Anyone get nist sp 800-171 CMMC Compliant using a Pfsense firewall:

                  https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-41r1.pdf

                  Are you hiring? Is the Palo Alto guy fired yet?

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                  Privacy Policy · Cookie Policy