Files
notes/projects/kwa/firewall_migration/20250318-OPNsense_Migration.md
2025-03-18 14:23:17 +01:00

1.0 KiB

Base Info

  • Deadline: 03.05
  • Anzahl User: 15

Angebot Liste

Bestehende Hardware

  • System: Linux, Memory: 7888 MB, 8 processors
  • No PPPoe (done by Fritz)

Funktionen

  • Basis Setup (routing, Generische Einstellung, Firewall Regeln, Authentizierung via AD,..)
  • VLANs als Grundlage (MGMT, SRV, CLIENT, WLAN, WLAN-Guest)
  • VPN (OpenVPN)
  • Free SSL certs (via ACME)
  • Web Proxy (Caching Proxy, Web Filter, Transparent Proxy, SSL Inspection, https de-/encryption) (!NOTE! OPNsense CA needs to be trusted by every client. Distribute via Filewave)
  • OPNsense Antivirus Loesung (Clamav + C-Icap)
  • IDS/IPS
  • WAF
  • OPNcentral

Zertifikate

  • SSL for https (Let's Encrypt oder gekaufte Wildcard)
  • Self Signed for Web Proxy (SSL Inspection)
  • Self Signed for OpenVPN