No replies
Bill Haynes
Bill Haynes's picture
User offline. Last seen 4 days 21 hours ago. Offline
Joined: 03/25/2009

Not too long ago I setup pfsense and wrote an article, since then I have accrued a tremendous amount of logs, which I can analyse and tune the network with; I have to say that I am thoroughly impressed. Using Ntop, pftop, and Snort alongside everything else is absolutely amazing. The only downfall I can think of is that I have yet to find a solution that EASILY impliments blocklists and offers automated updating [of the lists]. I'm frantically searching for a solution at the moment. I've looked at using moblock or iplist and a few others as alternatives but have thus far come up with no luck of finding anyone who has gotten this working on PfSense. My firewall & IDS offer amazing functionality and I don't see any way that I would replace  it, but I have moved on to possibly creating a transparent firewall in Linux that will allow me to filter content going to the LAN after PfSense has gotten ahold of it. Using this configuration:

Net Connection: --> PfSense --> Transparent Firewall +blocklists --> 24-port Switch --[My Access Point is connected to the switch]
My PfSense Hardware is :
2.2Ghz Athlon
1GB RAM
3 - 10/100 NICS
1- Wifi Card [Not in use ATM]
This hardware isn't much but it is doing an  an amazing job.
This is the way I have my network setup now with the exception of the transparent firewall. So far this has been an amazing solution as is, I've gained a bit of download speed from my 1.5 Mbps connection, better management of request handling and an complete set of tools that allow me to go over all of my traffic with a fine toothed comb. If I can get the blocklists setup at the firewall layer, it would force additiona l protection on any machine in the LAN and would add an additional layer of security for any unprotected/vulnerable machines.
For now I am stuck using client-based [end point] blocklist solutions. Let me konw if anyone has any ideas on a better solution, or any questions about my current setup.
Share/Save
n/a

Recent activity