Welcome back to the savory course in building You're in for a sec lap. I'm your host and instructor Kevin Hernandes
and the last video were able to install and have a general overview off PF sense on all of its features
even though it was not fully configured. Since we're still missing, that were interface is basically it's operational and which will be able to install and configure it slightly until our lap is an inborn mature process.
We're also able to validate that within its op market or its models were able to find both lights quit squid and squid card, which will basically replace the need of a web proxy in our environment.
This will help us by basically lowering drastically the amount of free sources will we need in order to make this info sec lap.
Looking back our proposed lamp
applications we can notice that we have way more applications than that Install over here.
Yes, by categories itself. You have far walls.
and our 80 tools. Now what happens is when you start eliminating, decided, redundant or
that are duplicated you can see that the amount of CPU court are starting to get reduce our If you recall correctly, our pen test tool will not necessarily be required to be always on and therefore
and have it installed in your primary system
and therefore having four tools. If you use consumption for our lab to be fully operational
now, you might think, Oh, Kevin. But what about Windows and Santo's right? There's two different operating systems, and you do have a lot of more tools.
per technology, Then one per yes district will be required to make choices in here. We might not be able to install on tangled nor keep to fire ALS. But in the end, the end of the day you think about it. Your corporation or your workplace most likely has only one type off fire roll out day.
It doesn't matter if it's 2050 or just one simple fire will. Most likely you know, it has that one checkpoint infrastructure, one Palo Alto, one juniper et cetera. Right. It doesn't have normally different infrastructures in there unless you're in a very large corporation.
Therefore, even though we're installing different type of firewalls at the end of the day, you will only keep one operational from each category.
Also taking consideration that some resource is such as curator
Splunk. Basically any of these s I s are very research hungry. Therefore, you might be required to install these in different devices dedicated just for dese application.
So let's go back. What are we doing today? We installing? I'd be fire. It's mentioned earlier. It doesn't mean that will have both firewalled operation out at the same time. However, what will still show you how to install it? That way you know how to proceed and you make your own decision in which firewall
to utilize in your apartment.
It could be because of familiar station with a tool book if you prefer it if user interface that embrace maybe the features it brings.
But unless you install each and every one of these applications at least once or have a general or of you, you won't be able to properly determine which is the best option for your environment.
It's also itself very reality, right? What works for one corporation does not necessarily work for the other. That's when we have so many products in the market. If you ever come across a decision on incorporating in your technology, you should task more than one option to make sure it fits the needs off
Well, let's get started.
No, like in a prior install, I pee Fire requires us.
uncivil were extracted there.
I'm pretty sure you might also be able to just remove the extension at the inn.
But half a little collection like this, especially since I already worked with PF sense. Right.
And here you go, and you do have to image right there.
Now, before we continue with our insulation of empty fire, I must stop for a very, very small disclaimer.
Unlike Piff sense, where we were able to create or connect, our interface is by a utilization of fertile network brittle port little switches which we configure any excess. I I be fire seems a little more resistant
to these type of configurations.
I personally spend several hours in 90 fire configuration trying to get it to use the interfaces that we literally used a few hours ago during the PF sends insulation. However, it was just not available. I was only seeing the
interfaces name like the actual Nick
in it and not those virtual knicks were creating. So that led me to believe that I require additional hardware and I start Googling around and I was actually able to find the hardware requirements from a network in to face card.
And you will see these later on in the video.
Now, obviously, this is not as bad. If you're building your own computer, you can just
use one of those PC Island. So you have additional in there and just lap in a network interface card in there, which matches the criteria of defender. And that should be a lot easier
to be able to accomplish down during my research, at least for PF sends. I've did final our systems, and I'm gonna show them industry in a second. And I cannot tell you effectively
if if this is a reliable store, not right, are even if this is a reliable product or not. But I did find a lot of people using the products and water, didn't this? They don't have four
ah ports in the back for their far walls, actually. But instead of using them as a *** side box like we're doing well, they literally connected their motive castrating to this and then this to their network. So it's a different take
on what we're trying to accomplish. However, this option is also there. If you just want to use your fire wolf from the lab. And as you can see here, it does have a m 0.2 over there. It has a wireless. Or here
what? It looks for it where it was. Sorry,
it has some ramps. Lots over there.
It looks a pretty decent system has the basics.
And you see the four ports over here. Hey, think
it doesn't seem to have some fans in there, so be aware of that. So I may have a little bit off overheating issues, so options are there for you.
You just have to, you know,
be aware of those and be careful when buying and research a little more
on the products were gonna be purchasing.
Now there's also, you know, the limitations itself.
Even if you want to do this, you're used reports might not allow you, right. I was lucky that this is some my pig that they're, like, persistent. I picked had a USB three point. Oh, and I was able to find a gigabit adapter for only $15. Give or take
on Amazon And how actually show does during the video. However,
depending on the part of world where you live,
this might not be available to you, But whichever options you go through, you know, make sure you use a gig of it cause, you know, 100 mags connection might not be enough for a fire. Well, so be aware of that. And that will not organ use B 2.1 right
now. I might personally be wrong on this, right? And if you have work with I p Fire have set it up.
Uh, feel free to shoot me an email, my contacts in here. And I will gladly modify this video and make the configuration reinstall it and update the court just to make this clear. Okay, Now, let's go ahead and show you this USB port. And after that, I was able to acquire
to meet the criteria to install. I'd be fired.
The passport I pee fire website. In order for like this work, we'll need a USP dongle. Such is that once this right. This is an eyepiece fire sign
to you. Three e t g. Years be three point out to kick of it, and in it, after
you can find it right here in Amazon for around $13.65
or to utilize that USB
Internet adapter we'll need to down on any appropriate
drivers in order to utilize it in E S X I
small search led us to this page.
except the technical real license
down. Let's not complete. However, let's make sure we've looked at the instructions how to proceed,
says Donald DISIP for a specific version of E. S s i. N s case like we did six, not seven
up. No, the Excite host using SCP or data store browser. So let's go ahead and do that. Now,
if you're not familiar with recipe to free tool that would allow you to transfer files from and to your virtual machines.
Go ahead and run it,
let's go ahead and install it.
And it looks like it already installed
right here. We have one s a p.
It's amazing. The way it works is you put the compere name
is your name and very important factor Before trying to use when a city is that you will have to enable sshh. Now let me show you what happens when you attempted to win s a p without s s a
and tonight, right, However come here
tend to reconnect. Now you can see is actually prompting for a password. Or you could actually come in now a very crucial part when installing Ah, displaying Ortiz driver He said you have to do it in the bar log bm where path or directory. So come here.
Okay And they're still far
So now let's connect it, buddy,
curier this spring to make it easier.
Now you're clear to skin Before we continue, you gotta put the exact site in maintenance vote.
you can either do to see ally
you ready for the interface. You wanted it to the user interface. You click in actions
interment in his vote.
A little warning will make sure you won't be able to the change. It's Sarah. So yes,
Now we've got to do the following command. Now, before you copy, paste the holding attention. This is a description or what you need to do.
In other words, don't call me pace the holding. So one other thing the structures don't tell you is that in order for you to install this properly, you need to actually run this from the bar lock. BM where
Otherwise, you will receive errors have seen above.
So in other words, when you upload a file, make sure your uploaded to this path over here.
This is very crucial for this To work
afterwards, you won't see it will need to reboot the system.
So let's go ahead and take care of that.
Like always using the council. I don't know. Wife. Let's click, reload and read it.
Let's give it a minute.
No, let's look again and see if it worked.
Yes, you would. But firm.
now that you have to U s fi interface right here, let's create a slight change your face for it. It's come here,
stream it. Let's say Lynn.
So like the interface
at it. You see up Link one part groups here. In other words, you have to assign it to a port group.
So let's create a new
let's also call it Lynn
and select the land fertile such and hit ad.
Now, if you notice this still is one
and don't break your head,
you didn't do anything wrong.
Well, you have to do now is come to host,
said the system. Back to maintenance. Mope
every with the system.
Let's give it a minute for it to reboot the interfaces on Let's go ahead and longing.
And as you can see now we have to Networking interfaces
now play close attention. You see the line here service still making the most.
So let's go ahead and
exit maintenance work for it.
Now let's go back to Network E. Make sure everything is done correctly.
court roofs, everything. Luke suit.
nothing's assigned to it, so now you gotta sign into a system.
Let's go back to host
Let's edit the settings.
now. If you go back to networking,
it should be taken care of. Now that we have full installed all the power requirements to run. I pee fire. Let's go ahead and take a small break
once you return would actually go through the insulation. If I pee fire and have a little tour on the application itself.
I hope to see you soon. Have a great day.