Saturday, December 12, 2020

How to Configure PfSense with an Open Source Firewall (pfBlockerNG)

 

How to Configure PfSense with an Open Source Firewall (pfBlockerNG)

Prerequisites

In this example we are going to install and configure PfSense in virtual environment. Hypervisor I am going to use is "Virtual Box". Basically you need two virtual machines.
  • Virtual machine 1 - PfSense
    • Memory 1G
    • Virtual Disk 5G
    • Two Interface Cards
  • Virtual machine 2 - Host VM
PfSense virtual PC should have two interface card. One for WAN network. Other one is for LAN. You have to download PfSense ISO image from PfSense official site.

When you create Virtual Machine for PfSense, You have to select Type as BSD and Version as FreeBDS 64-bit version.


Once you completed with Virtual Machine creation, go to settings of the virtual machine and go to Network. Change the network configurations as follow.



Network Diagram 

This is the network digram of our setup. IP details can be different according to your router IP.


PfSense Installation

Power-up the virtual machine and follow these steps.
  • Press "Enter"

  • Select Install pfSense and Press OK

  • Select default Keymap

  • Select Auto (UFS) and Press OK
  • Once the installation finished, remove the ISO image and reboot the VM
  • After reboot, you will get below interface

PfSense Interface Configurations

  • Select Assign Interface
  • Type "n" and Press Enter
  • Enter WAN Interface name
  • Enter LAN Interface name
  • Enter y to confirm the changers
  • Assign IP address for WAN interface. Select Option 2 and Press Enter
  • Select WAN interface and Press Enter
  • Disable DHCP on WAN interface
  • Enter Static IP address for WAN interface
  • Enter subnet Mask
  • Enter default gateway for WAN
  • Disable DHCP6 on WAN interface
  • Keep blank for IPv6 address
  • Configure web interface protocol HTTP

  • Assign IP address for LAN interface. Select Option 2 and Press Enter
  • Select LAN Interface
  • Enter static IP address for LAN interface
  • Enter subnet mask
  • Keep LAN default gateway empty
  • Keep IPv6 address empty and Press Enter
  • Enable DHCP for IPv4 address
  • Enter starting address as 192.168.2.100. End address as 192.168.2.200
  • Press Enter to continue


Now go to your second VM settings -> network. Under “Adapter 1” attached network interface to “internal Network”. Then select Name from drop down as “em1” 


Now power up your second VM and check whether you have received proper IP address from PfSense DNCP service.


Now access PfSense web interface with LAN IP or PfSense. (http://192.168.2.5). User: admin. Password: pfsense.


Configure "pfBlockerNG"

Install required packages

Install “pfBlockerNG” from PfSense package manager. Go to System->Package Manager->Available Packages. Search the package and install.


General settings

Go to Firewall -> pfBlockNG->General. Set below highlighted options and save.
  • In General Settings section, fill the following fields:
    • Enable pfBlockerNG: Checked
    • Keep Settings: Checked
    • Cron Settings: Select Every hour, select 0 as minute, hour and Daily/Weekly
    • De-Duplication: Checked
    • Suppression: Not checked
    • Global Logging: Not checked
    • MaxMind Localized Language: Select English
  • In Interface/Rules Configuration section, fill the following fields:
    • Inbound Firewall Rules: Select WAN and Block
    • Outbound Firewall Rules: Select LAN and Reject
      • If you have more than one internal interface, press CTRL or CMD (for Mac users) and click on interfaces
    • OpenVPN Interface: checked
    • IPSec Interface: checked
    • Floating Rules: checked
    • Rule Order: Select | pfB_Block/Reject | All other Rules | (original format)
    • Auto Rule Suffix: Select Null (no suffix)
    • Kill States: Not checked
    • Click on the Save button once all field are filling



Configure DNS Blocking (DNSBL)

Go to Firewall->pfBlockNG->DNSBL->DNSBL. Select below highlighted options and save.
  • In DNSBL section, fill the following fields:
    • Enable DNSBL: Checked
    • Enable TLD: Not checked
    • DNSBL Virtual IP: Enter an IP address is not in our internal networks,
    • like 10.66.66.66
    • DNSBL Listening Port: Enter 8081
    • DNSBL SSL Listening Port: Enter 8443
    • DNSBL Listening Interface: Select LAN or another internal interface
    • DNSBL Firewall Rule: Checked
      • If you have several internal interfaces, press CTRL or CMD (for Mac users) and click on interface
  • In DNSBL IP Firewall Rule Settings section, fill the following fields:
    • List Action: Select Deny Both
    • Enable Logging: Select Enable
  • In Advanced Inbound Firewall Rule Settings, I don't change anything
  • In Advanced Outbound Firewall Rule Settings, I don't change anything
  • In Alexa Whitelist, I don't change anything
  • In Custom Domain Whitelist (this list contains custom domains that you need to allow access),
    • I recommend using + button in Alert tab to add custom domains to the whitelist. In fact, pfBlockerNG package uses DNS resolution to find CNAME associated to the domain you want to whitelist
    • To begin, enter the following whitelist domains:
.twitter.com
.play.google.com
.drive.google.com
.accounts.google.com
.www.google.com
.github.com
.outlook.live.com
.edge-live.outlook.office.com # CNAME for (outlook.live.com)
.outlook.ha-live.office365.com # CNAME for (outlook.live.com)
.outlook.ha.office365.com # CNAME for (outlook.live.com)
.outlook.ms-acdc.office.com # CNAME for (outlook.live.com)
.amazonaws.com
.login.live.com
.mail.google.com
.googlemail.l.google.com # CNAME for (mail.google.com)
.sites.google.com
.www3.l.google.com # CNAME for (sites.google.com)
.docs.google.com
.plus.google.com
evintl-ocsp.verisign.com
evsecure-ocsp.verisign.com
.digicert.com
  • In TLD Exclusion List, I don't change anything
  • In TLD Blacklist, I don't change anything
  • In TLD Whitelist, I don't change anything
  • Click on the Save button once all field are filling



DNSBL feeds contain list of URLs that contain adds, malicious software, etc. Please, note that the following list is not a complete and comprehensive list. To configure DNSBL feeds,

Go to Firewall->pfBlockNG->DNSBL>DNSBL Feeds and click on Add button
  • Click on + Add button
  • In DNSBL Feeds section, fill the following fields:
    • DNS GROUP Name: DNSBlockListGroup
    • Description: DNS Block list
    • DNSBL: Select Auto and ON, enter the full URL and give a name associated to the particular URL
  • Download Feed URLs from GIT repo. (Download)
  • List Action: Select Unbound
  • Update Frequency: Select Once a day
  • Weekly (Day of Week): Select Monday
  • Enable Alexa Whitelist: Not checked
  • In Custom Block List section, I don't change anything
  • Click on the Save button once all field are filling




To configure DNSBL Easy List

Go to Firewall-> pfBlockNG -> DNSBL-> DNSBL EasyList
  • In DNSBL - EasyList section, fill the following fields:
    • DNS GROUP Name: EasyList
    • Description: DNSBL Easy list
    • EasyList Feeds:
      • Select ON, EasyList w/o Elements, name it EasyListWOElements
      • Clicl on + Add button
      • Select ON, EasyPrivacy, enter EasyListWOElements
  • In DNSBL - EasyList Settings section, fill the following fields:
    • Categories: Press CTRL or CMD (for Mac users) + click to select following categories:
      • EASYLIST Adservers
      • EASYLIST Adservers Popup
      • EASYLIST Adult Adservers
      • EASYLIST Adult Adservers Popup
      • EASYPRIVACY Tracking Servers
      • EASYPRIVACY Tracking International
    • List Action: Select Unbound
    • Update Frequency: Select Once a day
    • Weekly (Day of Week): Select Monday
    • Enable Alexa Whitelist: Not checked
  • Click on the Save button once all field are filling

Verification

Check the "dnsbl" service running properly.


Follow below steps to fetch the feed from feed urls and update local database.



Check DNS Blocking (DNSBL)

To verify the DNS blocking, from your second VM, type following command. 

$ nslookup ads.google.com

If the configurations are working fine, you should get reply from PfSense like this.






Friday, November 13, 2020

Set Up Highly Available Web Servers with Keepalived and Floating IPs


Keepalived runs on an active LVS server as well as one or more optional backup LVS server. The active LVS server serves two roles:
  • To balance the load across the real servers.
  • To check the integrity of the services on each real server.
The active (master) server informs the backup server of its active status using the Virtual Router Redundancy Protocol (VRRP), which requires the master server to send out advertisements at regular intervals. If the active server stops sending advertisements, a new master is elected.

Prerequisites 

  • Need two linux servers any web server configured and should be up and running.
  • Port 80 should we open from firewall level
In this example I am using two CentOS-7 servers and I am using nginx as my webserver. You can use any OS and webserver as you like.


Nginx Server 1 --> 192.168.1.17
Nginx Server 2 --> 192.168.1.18




Install and configure Keepalived

Thin this setup we need another additional IP which need to configure as our VIP. This VIP can we assign to either "Webserver 1" or "Webserver-2".

In this example we are using 192.168.1.20 as our VIP.


  • Create a loopback interface in each servers (Webserver-1 and Webserver-2)
Go to below location and create a file call "ifcfg-lo:vip". This file should contain below content.

DEVICE=lo:vip
IPADDR=192.168.1.20 # Change this to your VIP
NETMASK=255.255.255.255
#NETWORK=
# If you're having problems with gated making 127.0.0.0/8 a martian,
# you can change this to something else (255.255.255.255, for example)
#BROADCAST=
ONBOOT=yes
NAME=loopback



  • Then UP the newly created interface
ifup ifcfg-lo:vip
 

 

  • Install keepalived in both servers
yum install keepalived


  • Enable the keepalived service
systemctl enable keepalived
 

  • Goto keepalived configuration folder and backup the existing configuration file. 

  • Create a nginx status check script with below content.

#!/bin/bash

_status=`pgrep -f "nginx.conf" | wc -l`

if [ $_status -gt 0 ];
then
        exit 0
else
        exit 1
fi

  • Set Execution permission for that script
chmod 755 /usr/bin/status_nginx
 
  • Create a keepalived.conf file and add below content in each server.
Values highlighted in yellow should be change according to your environment.

In Webserver-1 

vrrp_script chk_nginx_status {
    script "/usr/bin/status_nginx"
    interval 10
}

vrrp_instance Float_NGINX {
    state BACKUP
    interface enp0s3 #Interface ID
    virtual_router_id 93 #This should be unique within the network
    priority 101        #101 on master, 100 on backup
    advert_int 1
    nopreempt

    track_script {
        chk_nginx_status #Nginx status check script
    }

    virtual_ipaddress {
        192.168.1.20/24 #VIP need to assign
    }
}
 
virtual_server 192.168.1.20 80 {
        lvs_sched rr
        lvs_method DR
        protocol TCP
        real_server 192.168.1.17 80 {
        weight 1
        TCP_CHECK {
                connect_port 80
                connect_timeout 3
                retry 3
                delay_before_retry 2
                }
        }
        real_server 192.168.1.18 80 {
        weight 1
        TCP_CHECK {
                connect_port 80
                connect_timeout 3
                retry 3
                delay_before_retry 2
                }
        }
}

In Webserver-2

vrrp_script chk_nginx_status {
    script "/usr/bin/status_nginx"
    interval 10
}

vrrp_instance Float_NGINX {
    state BACKUP
    interface enp0s3 #Interface ID
    virtual_router_id 93 #This should be unique within the network
    priority 100        #101 on master, 100 on backup
    advert_int 1
    nopreempt

    track_script {
        chk_nginx_status #Nginx status check script
    }

    virtual_ipaddress {
        192.168.1.20/24 #VIP need to assign
    }
}
 
virtual_server 192.168.1.20 80 {
        lvs_sched rr
        lvs_method DR
        protocol TCP
        real_server 192.168.1.17 80 {
        weight 1
        TCP_CHECK {
                connect_port 80
                connect_timeout 3
                retry 3
                delay_before_retry 2
                }
        }
        real_server 192.168.1.18 80 {
        weight 1
        TCP_CHECK {
                connect_port 80
                connect_timeout 3
                retry 3
                delay_before_retry 2
                }
        }

} 

  • vrrp_instance defines an individual instance of the VRRP protocol running on an interface. I have arbitrarily named this instance VI_1.
  • state defines the initial state that the instance should start in.
  • interface defines the interface that VRRP runs on.
  • virtual_router_id is the unique identifier that you learned about in the first article of this series.
  • priority is the advertised priority that you learned about in the first article of this series. As you will learn in the next article, priorities can be adjusted at runtime.
  • advert_int specifies the frequency that advertisements are sent at (1 second, in this case).
  • virtual_ipaddress defines the IP addresses (there can be multiple) that VRRP is responsible for.
Now check the VIP is successfuly assign to a server. It can be Webserver-1 or Webserver-2

You can simply type "ip addr" command to verify this.



You have to install "ipvsadm" package to inspect the virtual server table. From this tool you can see available nodes under your keepalived instance.



Type below command to get the available instance 

ipvsadm -L -n


Now brows the website with VIP in your browser.


Now Try to shutdown the web-server which VIP current being assign. Once you shutdown it, VIP should automatically assign to other server. Try to access your side also after you shutdown the server.