Hey, welcome back, everyone. This is Section two of PF. Since configuring firewalls owns eso were in the lab environment right now and what you're looking at is a virtual machine. It's the PF sense I saw that's been installed in the side very lab,
and it's fully booted.
And what you're looking at here briefly is just some of the options that you have when you configure in this particular via will. Things that we're gonna focus on is that when land and the opt one, which is gonna be our DMC interfaces. So those are the three that we want to configure,
and we're gonna move around and about with our Windows operating system and our Linux operating system. I'm a little toggle through
to get to those virtual machines,
we'll be able to live into these and, you know, see if we could pass traffic based off the configuration we have
within RPF sense viral.
So let's get started. The very first thing that we want to do is we want a sign
the interface with an I P address. Okay, so we're gonna do that now just step through this together.
We're gonna select option to which tells us that we can set interfaces for an I P address.
the way in, which is gonna be option number one, as you can see under the available interfaces section.
Now, it's gonna give us a couple of questions throughout this quote unquote wizard or
this guide that we're going to
Make a decision about
allowing d A. C p on this one in her face, right? Independent on your set up,
whether you're doing this at home or you're in a production environment, your firewall, this particular firewall can handle D h E p, which is gonna be that dynamic host configuration protocol that, you know, leases are hands out. I p addresses for
whatever host or assets are on that particular
sub net or a zone. All right, but for now, we're gonna go ahead and choose no,
where we're gonna want to focus solely on the fact that we just want to get the face is up and running. Okay,
I'm gonna put in my i p address
and then we're gonna give it a slash 24.
So cider notation basically tells us the amount of I P addresses we're gonna be ableto have for that particular sub network that were created. Okay,
so that's what we just did with the slash 24 we're gonna go ahead and proceed,
we're just gonna hit enter here. We don't need to configure an upstream gateway at this time, okay?
And we're also gonna go with
no for this particular question. This is gonna be I p b six, right? We're not concerned about I p v six at this point and again, we don't have an interest in allowing d A. C p on these interfaces from the PF sense. Right? DCP might be handled from a domain controller
host in the environment, but for this particular lab, we're not interested in that.
And so we're just gonna hit enter again. We don't have an interest in I p v six
and we're not gonna interest ourselves in reverting the Web configuration protocol, which is gonna really handle the Web configuration website that we would see. And we'll get to that in a bit. So we'll hit. No,
and we just configure the when interface right
we could see it visible there on that top line. It's gotta write the address. It's got our cider notation of slash 24 we're gonna move on
and continue the effort
with the next two lengths the less of the next two segments which is gonna be our land and our d m z.
Okay, so again, we're gonna choose option number two
and then we're gonna choose
Interface number two.
I'm gonna give an I P address.
I'm gonna go to slash 24.
We're gonna go ahead, Enter. We're not concerned about the upstream gateway at this time.
We may interfere. I b b six address. We're not concerned about that either.
We're gonna go with no on the A C. P
and when I choose no. On that
revert for the A c T p Y configuration protocol.
Now, you could see that the land address
is where we're gonna be able to access the actual
web console for the PF sense. So it's very important that when you're going through
and you set this up in your lab environment, if you choose to do so that you understand that this https address is what you're gonna need actually connect to the actual console so you don't have to use command line to configure the rest of your router. Or I should say, your firewall,
even though this is behaving like a rodders. Well, keep that in mind.
so this is what you're gonna need, right? So this is very important to just keep that
and understand that that's how you're gonna access the, uh, the web counsel to do the port fording the black or the allow for a particular traffic
on the networks that we're setting up. Okay,
so we're gonna enter, and we're gonna go ahead and configure the when.
Excuse me. We're gonna configure the D m Z.
We're gonna give that an I P address.
We're gonna give this last 24.
We're gonna hit Enter.
We're going to enter again.
We're gonna choose no for D A c. P.
You were not gonna revert.
What do you have? There is three separate
network segments. Wouldn't for your wang one for your land. Another one for your d m z.
So now that we've got that complete,
we could actually go about the business of configuring
the PF sense through that Web link. Right. So we're gonna move over to that Windows eight machine
we're gonna sign into that machine.
We're gonna go and access
the actual H H D. S. I P address that provides us with that link. Remember? I
I showed you that earlier.
All right, so we're just gonna go ahead and type in that
the Atlanta address,
and that should get us there.
Now, the reason why the screen looks the way it is, it's because that certificate is not trusted. Right? So we're just gonna wanna continue to this website
and then there you have it. We've got the logging splash screen for P f Sense, and now we're gonna be able to sign it
and go about the business of actually configuring
R P s sense firewall.
Now, upon the very first time, sign into European sense firewall. Whether it's in a lab environment or you download it yourself and do this at home, you're gonna go through some prompts. And for the sake of falling along with this lab, all you have to do is hit next. They're not gonna change anything here.
We're gonna keep everything as is.
Obviously you're doing this at home, you're probably gonna want to change the password. You don't want to keep that default password. You don't have to write. So that's important to kind of read through those things as you do at home. But for now, we just want to keep going through and
clicking necks. Not gonna change anything,
go ahead and reload.
And then we're gonna choose
to go to the actual PF sense of Web configuration,
and we're in, right, So you could see that all three interfaces air up.
All of the actual I p addresses that I assigned are visible. And,
you know, now we could we can actually go ahead and move forward and making sure that
we're in a position where we're gonna allow trap it to pass through. And there's a couple of things that we want to do. All right, so we're gonna go to interfaces.
We're gonna choose the land interface to start. I was just gonna make sure that we're not blocking private networks, right? We're working in a private network space, and so it's important that you know, the 17 to the 192 or the 1920.10 with a 10.0 addresses,
are are able to talk to one another based off of,
um, this private networks configuration here. And obviously those are the type of I P addresses we're gonna use for our three separate interfaces. Right? So very important that
you check that and make sure you know we're not blocking your artsy 1918 or those private networks. Okay?
What did it say there?
We're gonna apply changes. One really cool thing about PF sense is that, you know, anytime you do make a change in the environment, it doesn't automatically make that change without you applying. So you get to go back and really make sure that you know what you did is what you really wanted to do. So
just another one of those No measure twice cut once type of rules that you'll see with pf sense. And we're gonna want to repeat this for the next two segments. Okay, so we'll go to our auto one, which is gonna be I d m z. We're gonna make sure that both of these air on check,
And then we'll do that again for the win.
And as you can see for the when they are checked. But we're gonna uncheck it
for the sake of this lab to make sure that we can see in about an outbound filter and at work.
So next up, we're gonna talk about network connectivity testing. Okay, so stay right there and I'll be right back.