What's new

siting an ips/ids/dnsBlock(PfSense? or ClearOs?) in a vpn cascade?

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

RedeyeAce

New Around Here
Current: Inet->wan-AC68u (ipsec passthrough)-lan ->wan-AX11000gt

Hello all,

Firstly, I wish everyone safe and well during this time of global worry.

Please, could you kindly help me out,
I think I know what to do, however I don't want to sway advice with my inexperienced opinion.
After 8 months of struggling with Bitdefender Box 2 (great idea, stupidly hampered by no ipsec passthrough and they pulled the ability to change subnets...). I have now replaced it.
  • Replaced bitdefender box 2 for : ac-86u on merlin at gateway for 'guest wifi iot', 'guest wifi for guests' and 'standard wifi; owned devices not requiring local network'. IPSec passthrough. Running at 2.4ghz only.
  • AX1100gt for local network: nas and devices that need access to it, 'guest wifi work network' and a 'standard wifi; network for local specific devices' to backup securely to cloud storage providers via qnap and independantly. Running at 5Ghz only.
To save messing around with switching either networks or disabling/re-enabling of vpn's via mac addressing,my current thinking is to have 2 seperate vpn's and understand that everything will just be a bit slower internetwise but be more secure the ax11000 local side.​
  1. Where do I site IPS/IDS and DNSBlocker? i'm wishing to catch malicious etc. from all devices
  2. Which small form factor-NUC to use?
Dual nic, dual core celeron no aes-ni or
Single nic i7 with aes-ni using proxmox (I believe that should enable aes-ni via vm) and a Thunderbolt dock for the second nic Caldigit TS3 plus, currently giving me a headache.

I have:-

Trialled a vm on qnap for pfsense, but you cant use aes-ni in that vm, thought that would be significant, also didn't have enough experience of vm's back then and didn't want to use our wantingly secured nas to handle edge features of pfsense.
Trialled a dual nic dual celeron nuc for pfsense, awesome but no aes-ni on cpu. Trialled as gateway and after bitdefender box2 (dual and triple nat issues)

Currently scratching head with i7 single onboard nic, no m.2 or variant of additional onboard connectors can get an additional nic going via adaptors , so have to go with a thunderbolt dock albeit i cant seem to get the ts3 working atm, but it does work without issues on a macbook.

3. Whilst I like PFSense, there may be extended periods, where I am not able to administrate it. I'm wondering if the ' implement and forget' nature of Clearos paid home user is a better idea for my wife to be able to use?
Thanks all and stay safe,
Jon


 
I think I know what to do...

Everything you want to have, good enough for home setup, can be done on a single router only - your RT-AC86U.

- AiProtection is your router version of IPS
- Diversion script is your DNS-based blocker
- Skynet script is your IP-based blocker
- the CPU has hardware AES support, OpenVPN speeds >200Mbps
- selective routing and VPN k.switch via Asuswrt-Merlin tools
- separation of IoT via Guest Network is available
- different SSIDs for VPN/NoVPN connections via YazFi script
- remote administration via VPN not an issue

If you want to go SMB gear way with pfSense, x86 router + switch + controller + APs, no other routers are needed.

- pfSense is your main router/firewall
- Snort/Suricata is your IDS/IPS
- pfBlockerNG is your IP/DNS-based blocker
- ntopng is your enhanced network stats (optional)
- Status_Traffic_Totals is your simple traffic stats (optional)
- Cloud Controller is your central APs management, extra network stats, roaming assistant, remote management
- IoT separation can be done via VLANs or using controller options (Guest Network), switch/APs dependent
- VPN Server/Client, selective routing, VPN k.switch all available
- remote administration via VPN available

You kind of already purchased equipment you don't really know what to do with and plan to purchase more for not very clear for me reason. If really 2 x APs are needed to cover your place, I would go with:

a) 2 x RT-AC86U routers with wired backhaul and AiMesh
- for low cost, simplicity, easy setup, good enough for home use performance/roaming

b) pfSense + Omada/UniFi WiFi Solutions with 2 x APs
- for good price/performance, better security/stability/roaming, easier per component upgrades
 
Last edited:

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top