While our smoothwall is and has been working well for us for the past two years, I recently had the need for something a little more robust.

I came across a fork of the monowall project, pfSense is a free, open source customized distribution of FreeBSD tailored for use as a firewall and router. In addition to being a powerful, flexible firewalling and routing platform, it includes a long list of related features and a package system allowing further expandability without adding bloat and potential security vulnerabilities to the base distribution.

Here’s a short summary of some of the eye catching features.

Filtering by source and destination IP, IP protocol, source and destination port for TCP and UDP traffic
Able to limit simultaneous connections on a per-rule basis
pfSense utilizes p0f, an advanced passive OS/network fingerprinting utility to allow you to filter by the Operating System initiating the connection. Want to allow FreeBSD and Linux machines to the Internet, but block Windows machines? pfSense can do so (amongst many other possibilities) by passively detecting the Operating System in use.
Option to log or not log traffic matching each rule.
Highly flexible policy routing possible by selecting gateway on a per-rule basis (for load balancing, failover, multiple WAN, etc.)
Aliases allow grouping and naming of IPs, networks and ports. This helps keep your firewall ruleset clean and easy to understand, especially in environments with multiple public IPs and numerous servers.
Transparent layer 2 firewalling capable – can bridge interfaces and filter traffic between them, even allowing for an IP-less firewall (though you probably want an IP for management purposes).
Packet normalization – Description from the pf scrub documentation – Scrubbing is the normalization of packets so there are no ambiguities in interpretation by the ultimate destination of the packet. The scrub directive also reassembles fragmented packets, protecting some operating systems from some forms of attack, and drops TCP packets that have invalid flag combinations.
Enabled in pfSense by default
Can disable if necessary. This option causes problems for some NFS implementations, but is safe and should be left enabled on most installations.
Disable filter – you can turn off the firewall filter entirely if you wish to turn pfSense into a pure router.
pfSense offers three options for VPN connectivity, IPsec, OpenVPN, and PPTP.
There’s a ton of other great features that you can read up on at http://is.gd/iauk

The LiveCD ISO is available from http://www.pfsense.org/mirror.php?section=downloads and for VMware folks, a prebuilt VM is available at http://files.pfsense.org/vmware/pfSense-1.2.2-VM.zip

–Matt Lestock

Leave a Reply

Your email address will not be published. Required fields are marked *

*

No Comments

  • CO2 laser engraving cutting machine / engraver cutter CNC router
    http://www.ecpur.com/itm/2220.html
    This is hot products CO2 Laser engraver and cutter instrument stand by Carve and Edit after non-metal, such as rubber,ox horns, wood, plexiglass, atomic materials, crystal, bowlder, etc…
    http://www.ecpur.com/images/40w-laser-engraving/laser-engraving-cutting_6.jpg
    http://www.ecpur.com/images/40w-laser-engraving/laser-engraving-cutting_7.jpg
    http://www.ecpur.com/images/40w-laser-engraving/laser-engraving-cutting_10.jpg
    You can easily to shoot up this gang fitting for invidious wood, plexiglass, making models.
    carving rubber stamp ,carving wood dog tag
    Laser Type : CO2 Gas
    Laser Power : 40W
    Tube Trigger Volt : 20KV
    Tube Operating Volt : 15KV
    Current : 0-22mA
    Interface to Computer : USB Port
    Maximum Item Size to Engrave : 320mm * 220mm * 70mm (12.6W * 8.7L * 2.8H in )
    Laser Tube (life hours) : 1100-1400 Hours
    Engraving Speed : 0-350mm/s (0-13.8 in./s )
    Cutting Speed : 0-35mm/s (0-1.38 in./s)
    Minimum Shaping Character : 1mm * 1mm (0.04 X0.04in )
    Resolution Ratio : 0.026mm (0.001 in ) / (1000dpi)
    Resetting Positioning : ?0.01mm (0.0004 in )
    Motor Type : Stepper Motor
    Software Supported : CorelDraw X4 and MoshiDraw 2013
    Power Consumption : ?250W
    Operating Temperature : 0-45?
    Graphic Format Supported : .PLT / .DXF / .BMP / .JPG / .GIF / .PGN / .TIF etc..
    Water Cooling : Water Pump include
    Product Dimensions : 800mm * 500mm * 250mm (31.4in * 19.6in * 9.8in.)
    Recommended Not spoken for Parts / Consumables Laser Tube, Convergent lens, Consideration lens
    *Co2 lasers at one’s desire blemish undisguised metals when coated with a metal marking solution.
    LMM Coated Metals are metals that from been sprayed with an LMM or Laser Marking Substantial Spray. Typically a CO2 laser engraver like the joined sold here ordain not imprint on metals unless it is painted metal. Nonetheless, LMM sprays clothed recently been introduced to the bazaar and if toughened correctly, drive aid a CO2 laser engraver to carve on diverse types of metal. We do not sell LMM spray but you can find it on the internet. No matter what, we dont guarantee LLM floral arrangement desire situation as we do not fabricator it. It would be up to you to learn how to reject it. We do not take on returns on this jotting in search the fitting of it did not engrave on metal.
    CO2 Laser engraver and cutter machine is toughened as a service to etching or penetrating of non-metal materials: such as rubber,ox horns, wood, plexiglass, atomic materials, crystal, bowlder, etc… Cutting thickness: 0-10mm (depends on different materials)