Starting pfsense for New Users

bert64

Senior Member
Joined
Jan 20, 2020
Messages
1,027
Reaction score
539
Basically if you want redundancy, better avoid the following two.

SingTel ONR -- but you can request to bridge the ONR.

MyRepublic: CGNAT, but you can pay S$50 to get Static IP as the workaround.

But with the above two, you will not have IPv6 if you care for IPv6. I do not care about IPv6 myself based on my testing using Singtel ONT (6rd IPv6 implementation, not dual stack, performance is worse than IPv4).

You can choose all other ISPs. I will actually recommend M1 (relatively stable) and Viewquest (high performance but less stable). But if you do not care for IPv6, then MyRepublic with Static IP is also with good performance (close to Viewquest).

Second that, i have pfsense working with M1 and no issues. IPv6 on M1 is generally quicker than legacy ip especially to europe, singtel's is poor because they use a tunnel and not a proper native implementation. You could actually use a third party tunnel (eg tunnelbroker.net) with any isp that doesn't put you behind CGNAT.

IPv6 is extremely important for the future and enables a lot of things not possible/practical with legacy ip, but we're stuck with a chicken and egg problem - Users don't realise the importance and don't demand it, isps dont provide it properly because of the aforementioned lack of demand.
The alternative future is that every isp puts all of their customers behind cgnat, many in other countries have already done this and it's only a matter of time before it happens here too.
 

toyota

Junior Member
Joined
Aug 19, 2000
Messages
81
Reaction score
3
I am using MR with static IP as primary WAN. Singtel with ONR bridged at host side as secondary WAN. I recommend MR with Static IP.

Both of my WAN are connected using LACP LAGG to a 10Gbe switch distributing to every room LAN points. Primary WAN channel to a VLAN connected to LAN PCs and secured servers. Secondary WAN channel to a few VLANs to run CCTVs, IOT and mobile devices.

good to know about your recommendation on MR and also bridge for SingTel ONR. Since I have ONR, think I will try out the bridge mode SingTel to see if it works.

Working towards the dual WAN at my new place so test pfsense out currently to familiarise with the workings of it.
 

toyota

Junior Member
Joined
Aug 19, 2000
Messages
81
Reaction score
3
By default Singtel will put you behind their ONR, so using pfsense with this setup would give you double nat and no ipv6. You can get them to put the ONR in bridged mode, or on some models you can do this yourself. It can be quite a pain getting hold of someone to make that change for you.

Personally i've not used dual wan with pfsense in singapore, although i have configured dual and triple wan connectivity in other countries. You can have failover or load balancing, although if you have 2x 1gbps connections going into the firewall you'll need something faster (port bonding can work) for the inside if you want to make use of >1gbps.

Understand about SingTel double NAT.

Looking at dual wan so that I do not get downtime rather than for the speed. Not hosting anything so don't need super duper high bw. 500M I thought would be more than enough although 1G seems to be the norm now.

Will have to study about port bonding for homework. :)
 

toyota

Junior Member
Joined
Aug 19, 2000
Messages
81
Reaction score
3
Basically if you want redundancy, better avoid the following two.

SingTel ONR -- but you can request to bridge the ONR.

MyRepublic: CGNAT, but you can pay S$50 to get Static IP as the workaround.

But with the above two, you will not have IPv6 if you care for IPv6. I do not care about IPv6 myself based on my testing using Singtel ONT (6rd IPv6 implementation, not dual stack, performance is worse than IPv4).

You can choose all other ISPs. I will actually recommend M1 (relatively stable) and Viewquest (high performance but less stable). But if you do not care for IPv6, then MyRepublic with Static IP is also with good performance (close to Viewquest).

noted on M1 :)
 

TanKianW

Supremacy Member
Joined
Apr 21, 2005
Messages
6,910
Reaction score
3,620
good to know about your recommendation on MR and also bridge for SingTel ONR. Since I have ONR, think I will try out the bridge mode SingTel to see if it works.

Working towards the dual WAN at my new place so test pfsense out currently to familiarise with the workings of it.

Just take note that the bridging of your Singtel fiber need to be done at Singtel host side. Not on your ONR itself. It is zero configuration from your side.

It will take some time back and forth, arrows flying between the tech person and the CSO, before all can be settled.

Hope it helps.
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
36,406
Reaction score
12,337
Understand about SingTel double NAT.

Looking at dual wan so that I do not get downtime rather than for the speed. Not hosting anything so don't need super duper high bw. 500M I thought would be more than enough although 1G seems to be the norm now.

Will have to study about port bonding for homework. :)

Just take note that the bridging of your Singtel fiber need to be done at Singtel host side. Not on your ONR itself. It is zero configuration from your side.

It will take some time back and forth, arrows flying between the tech person and the CSO, before all can be settled.

Hope it helps.

With regards to the ONR bridging, take note of the following important points to reduce the chance of things going wrong, based on the SingTel 1Gbps thread.

1) make sure you have the Huawei ONR. If not they need to change to Nokia ONR and then carry out the bridging. Nokia ONR can nor be bridged by SingTel as of now. In that case, a technician needs to come down to replace the Nokia ONR and then carry out the bridging.

2) If you have the Huawei ONR, contact SingTel and tell them you have the advanced networking equipment and want to carry out ONR bridging.

3) Once they agree and the backend will push a profile suitable for you. If you do not have SingTel TV box, the profile is supposed to be simple, with one bridged port and no VLAN required.

If you have Singtel TV, one port will be bridged with no VLAN required. The other ports will not be bridged and will be used for Singtel TV box (up to three boxes).

After this have been done, your router connected to the bridged ONR port should work, no Singtel VLAN settings are required.

4) Recently the cases seem to be more smooth, previously there were reports of bricked ONR, non working SingTel TV, non working of telephone, etc, especially for new sign-up.

5) So far the bridged ONR will not have IPv6 based on the reports.
 

TanKianW

Supremacy Member
Joined
Apr 21, 2005
Messages
6,910
Reaction score
3,620
Recently got to install pfsense on a few mini x86 pc boxes bought from taobao. These boxes are used to secure my team's home network while they are working remotely from home. I found this spec pretty good and runs a few plugins quite well with minimal power.

CPU: Intel Celeron Quad Core J4105 (faster and more recent than J4205 and some U series CPU) TDP at 10W.
*Recommend to check Intel ark website on the actual specs and user cpu benchmark to compare the CPUs
https://ark.intel.com/content/www/u...-j4105-processor-4m-cache-up-to-2-50-ghz.html

RAM: 8GB
Storage: 128GB
Chassis: passively cooled small chassis
NIC: 4 x Intel NIC i211
Price: Varies from $220-$240 (4GB-64S to 8GB-128S) including direct shipping

TAk94bn.jpg
 
Last edited:

TanKianW

Supremacy Member
Joined
Apr 21, 2005
Messages
6,910
Reaction score
3,620
Updated Post 2 on understanding the concept of firewall rules on pfsense and some best practices.

*IMPORTANT (Please LEARN)* Setting up VLAN using pfsense
Do plan and map the whole network before starting to set up your VLANs. Your firewall rules should also prevent VLANs from communicating with each other just in case one of the VLANs are compromised.
https://www.youtube.com/watch?v=b2w1Ywt081o

*IMPORTANT (Please LEARN)* Understanding the firewall set up on pfsense and best practices
Tom from Lawrence system clearly explain the concept of firewall using pfsense and what are the good practices to look out for.
https://www.youtube.com/watch?v=eb1pTs7XamA

Some recommendations for home network setup using pfsense:
3) Separate VLANs to segregate the network devices. (Eg. IOTs, Mobile devices, wired PCs, laptops, guests, etc) Your firewall rules should also prevent VLANs from communicating with each other.
5) Refrained from using the default port (Eg. port 80 & 443) to access your firewall GUI and restrict specific VLANs to access your firewall. You should not exposed your firewall to be accessed externally!

Example of VLANs firewall rules (Eg. Preventing IOT VLAN from accessing Firewall Web config and other LAN network:
SfTNQOA.jpg
 
Last edited:

Mach3.2

Great Supremacy Member
Joined
Apr 8, 2011
Messages
72,511
Reaction score
2,488
Since you're on firewall rules, I'd like to add that floating rules have precedences over the individual interface rules, then under the interface tabs, the rules are processed from top to bottom.

That is to say, if you have a rule permitting access to everywhere all the way on top of the list, and a rule blocking access to another subnet at the bottom of the list, your blocking rule won't work.

Remember to check the order of your rule, and of course test it out to ensure it's working as intended.
 

TanKianW

Supremacy Member
Joined
Apr 21, 2005
Messages
6,910
Reaction score
3,620
Just a note:

If you are using the pfblockerNG plugins, you notice that floating rules will automatically be created from the filter lists. Do not edit it, you may screw it up, unless you really know what you are doing.

The best way to test if the firewall rules work is to ping/test it. Sometimes right after making changes to the firewall rules, it may take some time for the firewall table to flush out the old rules. Even though most of the time it will be pretty fast.

The use of "invert match" in the firewall rules are also extremely useful too. For Eg, if you select an IP to block, but you check "invert match", it means the opposite where all other IPs will be blocked, except the IP selected.

Do check out the firewall explanation here:
https://www.youtube.com/watch?v=eb1pTs7XamA

Firewall rules can be configured very differently, and yet serve the same purpose. There is no one rule fits all solution. This really prove the flexibility of firewall configuration on pfsense.
 
Last edited:

bert64

Senior Member
Joined
Jan 20, 2020
Messages
1,027
Reaction score
539
5) So far the bridged ONR will not have IPv6 based on the reports.

Singtel does not provide native IPv6 at all...

If you are in bridged mode however, you can configure their 6rd tunnel and it does work with pfsense.

There is some configuration information on another post but it's pretty simple, if you set the wan interface ipv6 type to 6rd you then have 2 options - 6rd prefix which is "2400:d803::/32" and 6rd border relay which is "202.166.127.6".

But it is a tunnel, it will reduce your MTU and performance won't be great.
 

TanKianW

Supremacy Member
Joined
Apr 21, 2005
Messages
6,910
Reaction score
3,620
Quite a few have asked me on the setting up of IDS/IPs on pfsense, and which one I personally prefer.

Personally I like both equally and are both capable. For Suricata, it just take much more time to tweak, configure as it is more sensitive and produce more false positive during the initial stage and it is really not novice friendly. For most home users, I will go with Snort but you do need to register for a free account with them. Below are the recommended youtube links from Lawrence system on the installation and setting up. I will also add this in on Post #5.

Installation and setting up of Suricata on pfsense:
https://www.youtube.com/watch?v=S0-vsjhPDN0&t=12s

Installation and setting up of SNORT on pfsense:
https://www.youtube.com/watch?v=-GgqYq5-EBg&t=883s

Running IDS/IPS Snort:
vKo0cKu.jpg

lahs2Oc.jpg

TsR3hK7.jpg
 
Last edited:

Mach3.2

Great Supremacy Member
Joined
Apr 8, 2011
Messages
72,511
Reaction score
2,488
One plus point for Suricata is multithreading, snort is only single threaded.

I only run IDS on the interface I had a VPN server on. I turned off the WAN IDS because there is simply too much noise from all the port scanning and script kiddies, and I'm already dropping those packets in the first place.

I'm actually thinking of turning off IDS completely, since packets are all encrypted nowadays and IDS has limited usefulness because it can't inspect the packet contents.
 

TanKianW

Supremacy Member
Joined
Apr 21, 2005
Messages
6,910
Reaction score
3,620
Update Page 1, #Post 2 on the setting up of OpenVPN to connect remotely to your office or home:

Setting up OpenVPN using pfsense.

It is pretty straight forward on pfsense. Just follow the wizard. The wizard will even create the certificate and the firewall rules. It is good if your CPU supports AES-NI crypto to speed up the encryption.

https://www.youtube.com/watch?v=PgielyUFGeQ

After setting up OpenVPN on pfsense, you just need to download the install client (with OpenVPN client export plugin installed) from the OS list and set up on the connecting pc.
jebbbBT.jpg


Some might need to set up your DDNS (due to DHCP at ISP side) to connect remotely using OpenVPN if you do not have a static IP. I recommend using the following:
1) DuckDNS (FOC)
2) Digital Ocean (Cloud subscription)

*There are quite a few options for you to choose from on pfsense. You can also choose from their drop down list.
*Take look of this too, if you have the time: https://www.youtube.com/watch?v=5mygS-TiT9c

Setting up DDNS:
wZHgWmg.jpg

N2UTE55.jpg
 
Last edited:

TanKianW

Supremacy Member
Joined
Apr 21, 2005
Messages
6,910
Reaction score
3,620
Just a quick recap, this thread should have covered the following topics, basics and slightly more advanced features of pfsense:

1) Hardware recommendations
2) Initial set up
3) LACP LAGG
4) Dual-WAN
5) VLAN set up
6) OpenVPN (DDNS)
7) IPS/IDS
8) Firewall rules
9) Enforcing https using ACME certificates and HAproxy
10) Running a Sinkhole using pfblockerNG


With all the above, I trust that it should help majority of the forumers who wanted to give pfsense a try (which you really should) a good head start, and also empower home users during this "Work from Home" period. Hope we will be out of this COVID19 situation very soon next year.

*Moving on, I will update this thread as and when I could, with updated information. Thanks.
 
Last edited:

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
36,406
Reaction score
12,337
Recently got to install pfsense on a few mini x86 pc boxes bought from taobao. These boxes are used to secure my team's home network while they are working remotely from home. I found this spec pretty good and runs a few plugins quite well with minimal power.
CPU: Intel Celeron Quad Core J4105 (faster and more recent than J4205 and some U series CPU) TDP at 10W.
*Recommend to check Intel ark website on the actual specs and user cpu benchmark to compare the CPUs
https://ark.intel.com/content/www/us...-2-50-ghz.html
RAM: 8GB
Storage: 128GB
Chassis: passively cooled small chassis
NIC: 4 x Intel NIC i211
Price: Varies from $220-$240 (4GB-64S to 8GB-128S) including direct shipping
TAk94bn.jpg
From another link.
this was just released. great specs
or DIY a miniPC add as many port u want
Other than the network adapter, spec seems to be similar. Price is a bit higher but with two more ports. 8GB/128GB is at RMB1330, but need to add GST and Shipment.
mPYOeiV.jpg

DjUpEZM.jpg

8BWSTba.jpg

dg4WijT.jpg
 
Last edited:

TanKianW

Supremacy Member
Joined
Apr 21, 2005
Messages
6,910
Reaction score
3,620
Yo! Any guide on how to setup SingTel MIO TV settings on the pfsense?

xiaofan’s guide configure the pfsense VLANs to work with miotv. This should work.

Another way is to connect the miotv and digital phone line str to the (bridged) Huawei ONR. I am using this method. It works too.
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top