fw kitten - Brandon-Duffy/SYS-265 GitHub Wiki
Firewall configuration for group 3 is as follows
- WAN interface IP - 172.16.1.203
- WAN Upstream gateway IP - 10.0.17.2
- LAN interface IP - 172.16.1.2
- Default Credentials
Username: admin
Password: pfsense
- First thing to do is add another network interface if there is not already 2. Set the first interface to the WAN and the second to your LAN.
- After turning on your firewall, you should be at a screen like this:
Select option 1 to assign interfaces and make sure that WAN is assigned to em0 and LAN is assigned to em1
- Head back to the main menu and select the option 2 to set interface IP and follow these steps:
Select 1 again to pick the WAN interface
Do not use DHCP for the WAN IPv4 address
Our wan IP address is 10.0.17.203
You are using a 24 bit subnet mask
For the WAN, your upstream gateway is 10.0.17.2
Use the gateway as your IPv4 name server as well
We will not be using IPv6, respond no when asked about DHCP.
Press to bypass IPv6 configuration
When asked about HTTP for the GUI, respond no (we want to use secure https)
Select 2 again to configure the other Interface's IP Address
Select 2 to pick the LAN interface
We are not using DHCP
Your LAN IP Address is 172.16.1.2
You are using a 24 bit subnet mask
You do not have an upstream LAN gateway (you are the gateway for the LAN). Press
No DHCP
Press to bypass IPv6 configuration
Do not enable a LAN DHCP Server
Do not revert to HTTP
This is what should be shown after finishing assigning IPs, we are done with the console configuration portion now
- Head over to any Windows workstation that has network connectivity
Open up a browser and head to https://172.16.1.2 and bypass any certificate warning
Sign in using the same credentials that were used to sign into the console
Complete the setup wizard and follow these steps as these are the only settings that the defaults are changed
Skip over the wizard and leave the setting checked to override the DNS server on PPP/WAN
System Wizard: General Information
Hostname: fw-kitten
Domain: kitten.local
Primary DNS: 8.8.8.8
System Wizard: Configure WAN Interface
RFC1918 Networks: Uncheck "Block private networks from entering via WAN"