Setup and Secure pfSense Firewall with Cascading VPNs, Kill Switch, and Advanced Security Features
Budget: €8 – €30 EUR
We are looking for an experienced network security professional to configure and secure a pfSense firewall with advanced security features. This project includes setting up cascading VPNs, a kill switch, and several key security modules to ensure comprehensive protection.
Scope of Work:
1. Install and Configure Security Modules:
• Snort or Suricata for intrusion detection and prevention.
• pfBlockerNG to block malicious IPs, domains, and optionally, ads and trackers.
• ACME for automated SSL/TLS certificate management with Let’s Encrypt.
• Service Watchdog to monitor and automatically restart critical services.
• BandwidthD for monitoring bandwidth usage and detecting unusual network activity.
• Ntopng for real-time network traffic analysis.
2. VPN Setup and Configuration:
• Install and configure 3 cascading VPNs using OpenVPN for enhanced security and privacy.
• Ensure strong encryption (AES-256-CBC and SHA256) is used throughout all VPN connections.
• Configure client certificates and enable TLS Authentication.
• Implement a kill switch using firewall rules to block all traffic if the VPN disconnects, ensuring no data leaks outside the VPN tunnel.
3. DNS Leak Protection:
• Configure DNS servers via the VPN interface to prevent DNS leaks.
• Set up DNS Resolver to force all DNS queries through the secure VPN tunnel.
4. Securing the Web Interface:
• Restrict access to the pfSense admin interface and configure it to use HTTPS with a valid SSL/TLS certificate.
• Enable two-factor authentication (2FA) for added security.
5. Network Segmentation and Firewall Rules:
• Implement VLANs to segment the network and isolate different parts for enhanced security.
• Configure firewall rules following the principle of least privilege to allow only necessary traffic.
6. Monitoring and Backup:
• Set up continuous monitoring with alerting for critical events.
• Ensure regular configuration backups and provide a recovery plan in case of system failure.
Requirements:
• Proven experience with pfSense firewall configuration and advanced network security.
• Expertise in setting up and managing cascading VPNs.
• Familiarity with security best practices and tools.
• Ability to work remotely and deliver a fully configured, secure pfSense setup.
Deliverables:
• Fully configured and tested pfSense firewall with cascading VPNs, kill switch, and all requested security features.
• Documentation of the configuration process, including how to manage and maintain the system.
• Support for initial troubleshooting and adjustments after deployment.
Scope of Work:
1. Install and Configure Security Modules:
• Snort or Suricata for intrusion detection and prevention.
• pfBlockerNG to block malicious IPs, domains, and optionally, ads and trackers.
• ACME for automated SSL/TLS certificate management with Let’s Encrypt.
• Service Watchdog to monitor and automatically restart critical services.
• BandwidthD for monitoring bandwidth usage and detecting unusual network activity.
• Ntopng for real-time network traffic analysis.
2. VPN Setup and Configuration:
• Install and configure 3 cascading VPNs using OpenVPN for enhanced security and privacy.
• Ensure strong encryption (AES-256-CBC and SHA256) is used throughout all VPN connections.
• Configure client certificates and enable TLS Authentication.
• Implement a kill switch using firewall rules to block all traffic if the VPN disconnects, ensuring no data leaks outside the VPN tunnel.
3. DNS Leak Protection:
• Configure DNS servers via the VPN interface to prevent DNS leaks.
• Set up DNS Resolver to force all DNS queries through the secure VPN tunnel.
4. Securing the Web Interface:
• Restrict access to the pfSense admin interface and configure it to use HTTPS with a valid SSL/TLS certificate.
• Enable two-factor authentication (2FA) for added security.
5. Network Segmentation and Firewall Rules:
• Implement VLANs to segment the network and isolate different parts for enhanced security.
• Configure firewall rules following the principle of least privilege to allow only necessary traffic.
6. Monitoring and Backup:
• Set up continuous monitoring with alerting for critical events.
• Ensure regular configuration backups and provide a recovery plan in case of system failure.
Requirements:
• Proven experience with pfSense firewall configuration and advanced network security.
• Expertise in setting up and managing cascading VPNs.
• Familiarity with security best practices and tools.
• Ability to work remotely and deliver a fully configured, secure pfSense setup.
Deliverables:
• Fully configured and tested pfSense firewall with cascading VPNs, kill switch, and all requested security features.
• Documentation of the configuration process, including how to manage and maintain the system.
• Support for initial troubleshooting and adjustments after deployment.