Time
6 hours 28 minutes
Difficulty
Intermediate
CEU/CPE
7

Video Transcription

00:00
Welcome back to the savory course in building. You're in for a sec lap. I'm your host and instructor, Kevin Hernandez.
00:06
Our previous lesson We are introduction into E s Excite. Familiarize ourself with a dash for learn how to read System Resource is Terra Terra. We also apply R E s exile items that we can't from being where themselves as a free license.
00:23
On today's lesson, we will start installing our first next gen firewall. In this scenario, it will be PF sense.
00:31
Let's get started now. Before Winstar pf sense there were different variants of options when downloading it Such a USB stick on I s Oh, now, if you haven't downloaded yet, the PF sent image. Please go ahead.
00:45
Once downloaded, you'll notice that it has a thought You sold GC former on it
00:51
new scenario. Let's extract the data prior to starting art installation.
00:56
We've been seven. Sit for this.
00:59
Okay,
01:00
we're for the extraction to finish.
01:03
Once completed, you will find an actual eyes. So in this path over here
01:07
Keep that in consideration. I remember the path
01:11
also. We'll need to find it and look license once we start installation
01:17
now, before we start installation of the farm. All let's make sure we have some networking are villains, which is Herbie switches in here, configured to go to the networking tab.
01:26
I got a little switches you been seeing. We have none in error or the standard.
01:33
Let's create a new one
01:34
was Call it
01:37
P up sense switch
01:42
and we can say it's our laying right
01:47
and let's click Add
01:49
area What's going here
01:52
Now we will come back into creating our part groups unless we actually start routing traffic to it.
01:57
For the meantime, let's just continue with insulation and creating our virtual machine.
02:02
Let's go back to birds. Machines
02:06
create register. BM.
02:07
Now you basically have three options. Create a new virtual machine. You play a burrito munching from a B F O B A file
02:14
on register an existent virtual machine.
02:17
Now this second option, it's more towards when were migrating are Callie box our medicine pliable. More of our own. Those pen testing type of machines, right?
02:28
In this case, since we're gonna be using I s so far we go here to create a new birds, a machine and klink next
02:35
1% that with some
02:37
any fault information such as the name she'll put P up sense in it.
02:43
We have, ah, compatibility, right exercise version that guest. A West family in this case will pick other
02:51
on the guest OS version, which is free. BSD
02:55
64 bit Right here,
03:00
Mom and let's click Next
03:04
Here you will be basically picking the storage device you'll be utilizing for your PF sense insulation.
03:10
Since I only have one hard drive in this configuration, you only have one option in your scenario, it might be different and you might have different options.
03:21
But let's just click next and continue
03:24
Now. Here's where we start customizing are settings right
03:28
now. If you remember closely,
03:30
let's look up. Our document
03:32
PF send has both a minimum and recommended usage for both RAM CPU and storage, right? In this case, even though it doesn't say so,
03:44
this will be one core at list
03:46
for it so wanted. It hurts
03:49
off CPU
03:51
longa, Vita Ram and eight gigs of storage. So let's go back here right and memories already at
03:57
one gig.
04:00
CPU one core You see they don't half gigahertz options
04:03
hardness. It's a gig
04:05
and basically kind of loaded the default for us if you pay close attention right now, here's where it gets a little bit tricky, right?
04:15
Basically, we want to make sure we select our I s O in here in order to install
04:20
PF sent. Select Selected.
04:23
You're presented with this. Where were you? Basically click upload
04:28
to select our image.
04:30
And right here we can see where our information set.
04:33
It's very undetected. I s O
04:36
right there
04:39
and it will be uploading it in a second.
04:44
You can see a little progress bar here on the right side.
04:48
Now the upload is completed. You can see RPF since I s o over here. Have a little for us to select.
04:56
Click on it
04:58
and click Select
05:00
Now let's make sure images here.
05:04
Yes, sir. I s O Phile,
05:08
right?
05:09
I don't see puke or don't you? A room. It gives the storage
05:14
and everything. I also in default. Let's click next.
05:17
Here you have a summary of everything before it starts
05:21
configuring it. So let's click. Finish and see what happens
05:28
was completed. It will be presented with the following screen which basically states the copyrights on this region. Notice about PF Since
05:40
Let's accept
05:42
those terms.
05:46
And now you're presented we three options
05:49
in isolation,
05:51
recovery
05:53
and record from a backup if you want to put it that way. So let's go with configuration
05:59
installation.
06:02
Now you're percent that we default standard for US keyboard. And if you want to continue with it or switch to keep our standard in our case, I will continue with the default. Tibor for us, keep our map.
06:18
Now, In this scenario, it requests us more information. How you want to do to this set up?
06:23
This case will continue with the default auto option and hit OK to continue
06:30
if
06:31
and insulation will start
06:40
now, as this is the SST, it's pretty fast insulation compared to, you know, erect traditional drive. However, be cautious. Be aware
06:48
that you gotta wait for a full process to be completed
06:53
and there it is pretty fast. As you saw
06:56
basically a new machine, it's install finished before exiting the cellar.
07:00
Um, Justin and any final quantification of this case we're gonna say no.
07:08
And now we have to read with the system. So let's reel it
07:12
here you have to service is turn it off. Basically, for the system to restart
07:19
and pretty fast
07:23
reboot my opinion.
07:24
And here we have again
07:26
this system.
07:27
It's let it little buddy fall.
07:31
Yes, previously, it's loading it. Service is starting up its process. It's Cheddar.
07:36
Prosecuting a minute now basically is asking if you want to set up the Big Island's no balance, our need to be set up first, and feelings will not be used for Onley optimal interfaces. If it's typical, say no here
07:50
and used a Web configuration to configure Be lance later if required. Right. So let's go back to our sheet, right and at a reminder,
08:00
configure big plans,
08:03
all right.
08:03
And right here, it says in the Web configuration
08:16
and the recent we don't want to configure does. Yet it's because I kind of want to have the whole infrastructure installed prior to starting a billing. These connections, I don't wanna accidentally blake the Internet access at home or anything like that. Okay,
08:31
so let's sit no
08:35
area
08:39
and I say auto detection,
08:46
right and person enter into
08:50
and it says, facing no link to detect.
08:54
So basically, this is face on the
08:58
configuration in there we saw earlier. Okay,
09:01
so let's take a look into that and fix it.
09:03
So for first
09:05
one, we're gonna add BMX zero to basically skip it, and then we're gonna do for the land. Just leave it blank and hit. Enter to basically symbolize your fish,
09:16
right? Do you want to proceed? Yes.
09:18
The reason we're doing this is because our interface is virtual, not physical. Therefore, many install diets that are out there are gonna be completely different to what you're seeing today.
09:28
And here's configuring that one interface
09:33
that we can always come back and reconfigured is if needed. Okay, so don't be scared.
09:50
Yeah, it's gonna be your any really
09:56
and right here you have it.
10:01
Make sure you keep a screen shot of this
10:07
right, and we're taking a snippet,
10:11
putting it to work. So
10:13
just to keep the data in there
10:18
and lets it safe
10:22
and let's go back to the dashboard,
10:26
I want your input that i p you'll be presented with this and here's PF sense
10:31
itself.
10:35
Uh, yeah.
10:35
Congratulations. You have now installed P Epson's.
10:41
Now obviously, you have to check further defaults credentials, which in this case, are in p absence.
10:46
So let's
10:50
sect imminent,
10:52
and we'll welcome to P F Sense. Here you'll have percent of the warning to change your password in the use for a manager,
11:01
it says. Welcome to the Wizard. Here was start with insulation itself or continue
11:07
wrote support.
11:13
Thanks
11:15
in this case, since I'm half ah, coming tomorrow to give me a warning.
11:20
So let's actually do this outside of Incumbent a moat. And here we are
11:26
again. CP. Use that, remember? Uses. You can see it's not using the full gig that we provided it, and it's only advertising 12% of eight gigs we gave him for storage.
11:37
Looks pretty simple.
11:39
Let's start with, uh,
11:41
pass for changing. If I recall correctly system user manager
11:46
on right here, you can see the admin
11:48
account, so let's check it.
11:50
So look
11:52
here has changed a pastoral quick
11:56
tape it twice, and it's safe
12:00
scenario. This case, it's asking me to update it.
12:03
I'll to it
12:05
now. One thing I like personally is not using the admin account itself, So let's create another user account real quick.
12:13
In this case, let's call it
12:16
he heard in this
12:18
right
12:20
type in my password. No expiration. I'm gonna give you the same access
12:24
That's the other one. So remember shoes Adam to admit.
12:31
And that's it. Safe a user in there we go
12:37
added too much. Last pass bolt A CZ You can see you cannot delete the admin s. You can delete the user we just created. Okay,
12:48
you have groups groups. As you can see, there's admin group. In all these years, you can have different groups as well and we'll go over those options s we continue with the PF sense? Of course.
13:00
Let me remember closely. You do have to farm all options here.
13:05
You do have over here your BP and settings.
13:09
I'd be sad, dull to the p up in BP in. And you do have other options. A slow right here.
13:16
If you recall correctly. I said that the PF sends will be able to achieve function of Sasha's a proxy. Now, you don't see that option right here, but if you go into the system
13:28
Package manager
13:31
available packages, right? You look literally. First squid you confined
13:37
like squid here. Michigan installing configured.
13:41
We'll go over all these packages during our configuration off um
13:48
pf send itself.
13:50
So what did we learn today
13:52
when still be of sense. We basically look at its default features. I was also able to show you
14:01
the point proxy Such a squid, right with sauce. Quit line was all
14:05
squid car and different features or functions that we were mentioning right here in this tool
14:13
that were able to be accomplished within
14:16
Dad
14:16
Next Gen firewall right here. Right. So even though you can install squid in Santos or whatever future you want to use as mentioned here, you can have it within PF sense itself.
14:31
Now
14:33
what we will do in our next lesson, we're gonna start light the fire. Now you might think, Oh, why install two firewalls? Will there be conflict? There might be Right now, the reason is, we want to install our features, all the different applications and there just so you can get a fee feeling off what you could accomplish from the lab
14:52
after we're installing all the applications, all the different configurations, installations that will peak dose that we will want to utilize for discourse. Rink
15:01
U s. A person don't have to pick the same once we pick Fred. Of course, however,
15:07
you're more than welcome to install whichever application you prefer now? If you, for example, use, I'd be fire at work or entangled or you have prior experiences that might be your default or primary next year. Fire will not Wanting to remember from our video is that we did not confirm the virtual Citrus
15:26
on any of those,
15:28
um
15:28
interfaces in this configuration insulation. We're basically just installing the basic default in order to have to interface up in following videos will be installing and configuring everything together from the virtual switch to the PF sends to the
15:46
switch that we have physically that we installed in our prior videos.
15:54
I hope to see you soon in our next video. Have a great day.

Up Next

Building an InfoSec Lab

This course will guide you through the basics of incorporating several Information Security Engineering Tools in your home and/or lab. By building this lab you will be able to obtain corporate-level security within your home network, as well as a higher understanding of the capabilities and advantages these tools bring to your network.

Instructed By

Instructor Profile Image
Kevin Hernandez
Instructor