A real firewall you build yourself β free. Learning rules, NAT, VLANs and VPNs on pfSense is foundational blue-team knowledge that directly transfers to enterprise firewalls.
Follow the steps β click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Two NICs: one faces out, one governs your lab net.
Start by blocking everything, then punch deliberate holes.
VLANs are how one breach stops being every breach.
Attacker's view of your own policy: verify, don't assume.
Real-world remote-access pattern, built free.
| Rules | pass/block, top-down first match |
| NAT | port forwards (avoid!) |
| VLANs | segmentation |
| Aliases | named groups = readable rules |
| LogsβFirewall | every decision logged |
| Suricata pkg | IDS/IPS addon |
Aliases first, rules second β future-you can read your own policy.
Block outbound too; C2 needs egress. Default LAN rule is a gift to malware.
pfBlockerNG adds IP reputation blocking in two clicks.
Recreate the classic DMZ lab: public web VM vs internal AD.
Use pfSense only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β plenty of legal targets, zero risk.