home/toolvault/soc & defense/pfsense

pfSense //

SOC & Defensefirewall

A real firewall you build yourself β€” free. Learning rules, NAT, VLANs and VPNs on pfSense is foundational blue-team knowledge that directly transfers to enterprise firewalls.

difficulty Β· intermediate
45 min
time to first win
5
guided steps
0
students started here*

HOW TO USE PFSENSE

Follow the steps β€” click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

pfsense β€” guided lab session
static view
step 01

Install as router VM

WAN=nat, LAN=host-only net

Two NICs: one faces out, one governs your lab net.

step 02

Default-deny philosophy

Firewall β†’ Rules β†’ LAN

Start by blocking everything, then punch deliberate holes.

step 03

Segment the lab

Interfaces β†’ VLANs + DHCP per segment

VLANs are how one breach stops being every breach.

step 04

Prove it works

nmap from 'users' VLAN to 'servers' VLAN

Attacker's view of your own policy: verify, don't assume.

step 05

Add remote access

VPN β†’ OpenVPN wizard

Real-world remote-access pattern, built free.

THE WORKFLOW AT A GLANCE

🧱
Install
router VM
πŸšͺ
Segments
VLANs+zones
πŸ“œ
Rules
default deny
πŸ”¬
Verify
scan yourself
πŸ”
VPN
safe access
LEARNING CURVE
intermediate β€” 45 min to first win

FLAGS & SUPER-MOVES

Rulespass/block, top-down first match
NATport forwards (avoid!)
VLANssegmentation
Aliasesnamed groups = readable rules
Logs→Firewallevery decision logged
Suricata pkgIDS/IPS addon

PRO TIPS

01

Aliases first, rules second β€” future-you can read your own policy.

Aliases first, rules second β€” future-you can read your own policy.

02

Block outbound too; C2 needs egress. Default LAN rule is a gift to malware.

Block outbound too; C2 needs egress. Default LAN rule is a gift to malware.

03

pfBlockerNG adds IP reputation blocking in two clicks.

pfBlockerNG adds IP reputation blocking in two clicks.

04

Recreate the classic DMZ lab

Recreate the classic DMZ lab: public web VM vs internal AD.

βš–οΈ

Golden rule

Use pfSense only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β€” plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
✍️ Author LDM · ldmhub4u@gmail.com
full guide v1 Β· v2 immersive Β· latest news
Made for learners, everywhere Β· 2026
*plausibly. verify commands with official docs.