0xCDE

joined 2 years ago
[–] 0xCDE@infosec.exchange 0 points 2 weeks ago (1 children)

@Chewt found the issue in the end... i had two interfaces share the same IP and was creating a conflict on the linux hosts. I dont know why Windows was not affected by it but all good in the end

[–] 0xCDE@infosec.exchange 2 points 2 weeks ago

@homelab

solved: There was an arp conflict, I had two interfaces sharing the same IP address, one from proxmox and one from pfsense. Once I changed the IP address from the proxmox interface everything worked!

Thanks everyone for helping!

[–] 0xCDE@infosec.exchange 0 points 3 weeks ago (1 children)

@Gobo yes the gateway is configured properly. If ti wasnt the system would not have internet after a firewall refresh

[–] 0xCDE@infosec.exchange 0 points 3 weeks ago (3 children)

@Gobo gw? I have tried with and without dhcp and the issue persists

[–] 0xCDE@infosec.exchange 0 points 3 weeks ago (3 children)

@Chewt
yes they can still ping my firewall while not connected to the internet.
Here are two screenshots from one of the ubuntu vms on the home network and one from the kali vm on the infra network

[–] 0xCDE@infosec.exchange 0 points 3 weeks ago (5 children)

@Chewt
The node has others vms as well, some of them are windows vms but they are not discussed as they do not face any problems connecting to the internet no matter what interface they are connected on. The Linux VMs that are on the WAN network which is the one that has the linux bridge that is connected to a port and those systems do not have any connectivity issues.

The other two lans also have a linux bridge that is not bound to any port and the Linux systems need the interface refresh in order to access the internet. Windows systems on those networks are connected to the internet with no issues.

yes the pfsense hardware is as you describe it. (picture attached)

For the last paragraph, I need to have some devices that will be isolated from my WAN (home network) because I want to create a cybersecuirty lab and I do not want anything to "escape" to my home devices.

Plus this teaches me how to manage a network with proper segmentation etc.

[–] 0xCDE@infosec.exchange 0 points 3 weeks ago (7 children)

@Chewt

  1. pfsense is virtualized on a Proxmox VM
  2. If i bring down the network interface and back up it loses connectivity once more
  3. The firewall is for and internal network so the WAN is my home network. I have an ubuntu server acting as a NAS and another ubuntu server for Jellyfin. Both servers are on the same proxmox instance, just on the WAN interfaces on the pfSense so I can access them from all the computers on the local network.
 

Linux systems unable to reach out to internet behind pfsense while Windows work fine.

I am trying to set up my #homelab for #forensics and I have encountered a very weird issue. I am running an internal pfsense #firewall for my environment. On this firewall there are 3 interfaces: WAN and two Isolated Labs.

On the "WAN" interface, both #linux and windows systems are able to access the internet without any problems.

But on the other two lans - named Infrastructure and Lab - the Linux systems are not able to connect to the internet after booting, while the systems are able to communicate with each other. In order to get them working I need to go the respective interface and make any change there and save the page, practically refreshing the settings on the interface. After this all currently online linux systems on that interface are working as expected and connectivity is restored. As you can imagine this is a huge pain, especially when I am testing things and I need to turn on various systems at different times. If i put the systems on the WAN interface they face no issue at all, so what could be the solution here for fixing connectivity for linux systems on the other interfaces?

edit: it issue is both on pfsense 2.7.2 and 2.8.0

@homelab
@pfSense

#dfir #proxmox #dfir #homelab #firewall #pfsense #networking #network