Time
6 hours 28 minutes
Difficulty
Intermediate
CEU/CPE
7

Video Transcription

00:00
Welcome back to the savory course in building You're in for a sec lap. I'm your host and instructor Kevin Hernandes
00:06
and the last video were able to install and have a general overview off PF sense on all of its features
00:14
even though it was not fully configured. Since we're still missing, that were interface is basically it's operational and which will be able to install and configure it slightly until our lap is an inborn mature process.
00:28
We're also able to validate that within its op market or its models were able to find both lights quit squid and squid card, which will basically replace the need of a web proxy in our environment.
00:41
This will help us by basically lowering drastically the amount of free sources will we need in order to make this info sec lap.
00:48
Looking back our proposed lamp
00:52
applications we can notice that we have way more applications than that Install over here.
00:57
Yes, by categories itself. You have far walls.
01:02
Yes, I am Sze
01:03
proxies.
01:06
I p s
01:07
are virtual machine
01:10
the pant Estelle's
01:12
and our 80 tools. Now what happens is when you start eliminating, decided, redundant or
01:19
that are duplicated you can see that the amount of CPU court are starting to get reduce our If you recall correctly, our pen test tool will not necessarily be required to be always on and therefore
01:32
and have it installed in your primary system
01:34
and therefore having four tools. If you use consumption for our lab to be fully operational
01:41
now, you might think, Oh, Kevin. But what about Windows and Santo's right? There's two different operating systems, and you do have a lot of more tools.
01:49
Current
01:52
per technology, Then one per yes district will be required to make choices in here. We might not be able to install on tangled nor keep to fire ALS. But in the end, the end of the day you think about it. Your corporation or your workplace most likely has only one type off fire roll out day.
02:12
It doesn't matter if it's 2050 or just one simple fire will. Most likely you know, it has that one checkpoint infrastructure, one Palo Alto, one juniper et cetera. Right. It doesn't have normally different infrastructures in there unless you're in a very large corporation.
02:30
Therefore, even though we're installing different type of firewalls at the end of the day, you will only keep one operational from each category.
02:40
Also taking consideration that some resource is such as curator
02:46
Splunk. Basically any of these s I s are very research hungry. Therefore, you might be required to install these in different devices dedicated just for dese application.
03:00
So let's go back. What are we doing today? We installing? I'd be fire. It's mentioned earlier. It doesn't mean that will have both firewalled operation out at the same time. However, what will still show you how to install it? That way you know how to proceed and you make your own decision in which firewall
03:21
to utilize in your apartment.
03:22
It could be because of familiar station with a tool book if you prefer it if user interface that embrace maybe the features it brings.
03:30
But unless you install each and every one of these applications at least once or have a general or of you, you won't be able to properly determine which is the best option for your environment.
03:42
It's also itself very reality, right? What works for one corporation does not necessarily work for the other. That's when we have so many products in the market. If you ever come across a decision on incorporating in your technology, you should task more than one option to make sure it fits the needs off
03:59
your company.
04:01
Well, let's get started.
04:03
No, like in a prior install, I pee Fire requires us.
04:09
So basically
04:10
uncivil were extracted there.
04:13
I'm pretty sure you might also be able to just remove the extension at the inn.
04:17
But half a little collection like this, especially since I already worked with PF sense. Right.
04:25
And here you go, and you do have to image right there.
04:30
Now, before we continue with our insulation of empty fire, I must stop for a very, very small disclaimer.
04:40
Unlike Piff sense, where we were able to create or connect, our interface is by a utilization of fertile network brittle port little switches which we configure any excess. I I be fire seems a little more resistant
04:57
to these type of configurations.
05:00
I personally spend several hours in 90 fire configuration trying to get it to use the interfaces that we literally used a few hours ago during the PF sends insulation. However, it was just not available. I was only seeing the
05:18
interfaces name like the actual Nick
05:21
in it and not those virtual knicks were creating. So that led me to believe that I require additional hardware and I start Googling around and I was actually able to find the hardware requirements from a network in to face card.
05:35
And you will see these later on in the video.
05:39
Now, obviously, this is not as bad. If you're building your own computer, you can just
05:46
use one of those PC Island. So you have additional in there and just lap in a network interface card in there, which matches the criteria of defender. And that should be a lot easier
05:58
to be able to accomplish down during my research, at least for PF sends. I've did final our systems, and I'm gonna show them industry in a second. And I cannot tell you effectively
06:12
if if this is a reliable store, not right, are even if this is a reliable product or not. But I did find a lot of people using the products and water, didn't this? They don't have four
06:21
ah ports in the back for their far walls, actually. But instead of using them as a *** side box like we're doing well, they literally connected their motive castrating to this and then this to their network. So it's a different take
06:38
on what we're trying to accomplish. However, this option is also there. If you just want to use your fire wolf from the lab. And as you can see here, it does have a m 0.2 over there. It has a wireless. Or here
06:54
what? It looks for it where it was. Sorry,
06:56
it has some ramps. Lots over there.
06:58
It looks a pretty decent system has the basics.
07:01
And you see the four ports over here. Hey, think
07:04
it doesn't seem to have some fans in there, so be aware of that. So I may have a little bit off overheating issues, so options are there for you.
07:15
You just have to, you know,
07:17
be aware of those and be careful when buying and research a little more
07:23
on the products were gonna be purchasing.
07:26
Now there's also, you know, the limitations itself.
07:29
Even if you want to do this, you're used reports might not allow you, right. I was lucky that this is some my pig that they're, like, persistent. I picked had a USB three point. Oh, and I was able to find a gigabit adapter for only $15. Give or take
07:46
on Amazon And how actually show does during the video. However,
07:50
depending on the part of world where you live,
07:54
this might not be available to you, But whichever options you go through, you know, make sure you use a gig of it cause, you know, 100 mags connection might not be enough for a fire. Well, so be aware of that. And that will not organ use B 2.1 right
08:11
now. I might personally be wrong on this, right? And if you have work with I p Fire have set it up.
08:16
Uh, feel free to shoot me an email, my contacts in here. And I will gladly modify this video and make the configuration reinstall it and update the court just to make this clear. Okay, Now, let's go ahead and show you this USB port. And after that, I was able to acquire
08:37
to meet the criteria to install. I'd be fired.
08:41
The passport I pee fire website. In order for like this work, we'll need a USP dongle. Such is that once this right. This is an eyepiece fire sign
08:50
to you. Three e t g. Years be three point out to kick of it, and in it, after
08:54
you can find it right here in Amazon for around $13.65
09:03
or to utilize that USB
09:05
Internet adapter we'll need to down on any appropriate
09:09
drivers in order to utilize it in E S X I
09:13
small search led us to this page.
09:18
So let's go here
09:20
except the technical real license
09:22
Delon
09:24
down. Let's not complete. However, let's make sure we've looked at the instructions how to proceed,
09:31
says Donald DISIP for a specific version of E. S s i. N s case like we did six, not seven
09:35
up. No, the Excite host using SCP or data store browser. So let's go ahead and do that. Now,
09:43
if you're not familiar with recipe to free tool that would allow you to transfer files from and to your virtual machines.
09:50
Go ahead and run it,
09:56
except
09:58
let's go ahead and install it.
10:05
And it looks like it already installed
10:11
Bush
10:16
right here. We have one s a p.
10:18
It's amazing. The way it works is you put the compere name
10:22
is your name and very important factor Before trying to use when a city is that you will have to enable sshh. Now let me show you what happens when you attempted to win s a p without s s a
10:35
being able
10:35
Come here
10:39
catalog in
10:41
and tonight, right, However come here
10:48
unable to service
10:50
tend to reconnect. Now you can see is actually prompting for a password. Or you could actually come in now a very crucial part when installing Ah, displaying Ortiz driver He said you have to do it in the bar log bm where path or directory. So come here.
11:09
Take the file
11:11
and hit upload
11:13
Okay And they're still far
11:16
So now let's connect it, buddy,
11:18
for the i p enters
11:28
longing
11:33
curier this spring to make it easier.
11:37
Now you're clear to skin Before we continue, you gotta put the exact site in maintenance vote.
11:43
So
11:45
in this case,
11:46
you can either do to see ally
11:48
or
11:50
you ready for the interface. You wanted it to the user interface. You click in actions
11:54
interment in his vote.
11:56
A little warning will make sure you won't be able to the change. It's Sarah. So yes,
12:03
let's put it back.
12:07
Now we've got to do the following command. Now, before you copy, paste the holding attention. This is a description or what you need to do.
12:16
In other words, don't call me pace the holding. So one other thing the structures don't tell you is that in order for you to install this properly, you need to actually run this from the bar lock. BM where
12:28
directory.
12:30
Otherwise, you will receive errors have seen above.
12:33
So in other words, when you upload a file, make sure your uploaded to this path over here.
12:39
This is very crucial for this To work
12:41
afterwards, you won't see it will need to reboot the system.
12:46
So let's go ahead and take care of that.
12:48
Like always using the council. I don't know. Wife. Let's click, reload and read it.
12:56
Let's give it a minute.
13:01
No, let's look again and see if it worked.
13:09
Yeah,
13:22
Yes, you would. But firm.
13:28
Yeah,
13:33
now that you have to U s fi interface right here, let's create a slight change your face for it. It's come here,
13:39
stream it. Let's say Lynn.
13:43
So like the interface
13:46
at it. You see up Link one part groups here. In other words, you have to assign it to a port group.
13:52
So let's create a new
13:54
let's also call it Lynn
14:00
and select the land fertile such and hit ad.
14:03
Now, if you notice this still is one
14:05
and don't break your head,
14:07
you didn't do anything wrong.
14:09
Well, you have to do now is come to host,
14:13
said the system. Back to maintenance. Mope
14:18
every with the system.
14:22
Let's give it a minute for it to reboot the interfaces on Let's go ahead and longing.
14:33
And as you can see now we have to Networking interfaces
14:37
now play close attention. You see the line here service still making the most.
14:43
So let's go ahead and
14:46
exit maintenance work for it.
14:50
Now let's go back to Network E. Make sure everything is done correctly.
14:54
Little searches,
14:56
court roofs, everything. Luke suit.
14:58
Now, if you see
15:01
nothing's assigned to it, so now you gotta sign into a system.
15:03
Let's go back to host
15:07
for machines.
15:09
Pick P of sense.
15:11
Let's edit the settings.
15:18
Pick Lynn.
15:18
It's safe
15:20
now. If you go back to networking,
15:28
it should be taken care of. Now that we have full installed all the power requirements to run. I pee fire. Let's go ahead and take a small break
15:37
once you return would actually go through the insulation. If I pee fire and have a little tour on the application itself.
15:46
I hope to see you soon. Have a great day.

Up Next

Building an InfoSec Lab

This course will guide you through the basics of incorporating several Information Security Engineering Tools in your home and/or lab. By building this lab you will be able to obtain corporate-level security within your home network, as well as a higher understanding of the capabilities and advantages these tools bring to your network.

Instructed By

Instructor Profile Image
Kevin Hernandez
Instructor