<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Pfsense on Tecnologia</title>
    <link>https://blog.bemanuel.com.br/tags/pfsense/</link>
    <description>Recent content in Pfsense on Tecnologia</description>
    <generator>Hugo</generator>
    <language>pt-br</language>
    <lastBuildDate>Sun, 08 Nov 2020 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://blog.bemanuel.com.br/tags/pfsense/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>pfSense - pfBlocker e a Lista de Reputação do Serpro</title>
      <link>https://blog.bemanuel.com.br/2020/11/pfsense-pfblocker-e-a-lista-de-reputa%C3%A7%C3%A3o-do-serpro/</link>
      <pubDate>Sun, 08 Nov 2020 00:00:00 +0000</pubDate>
      <guid>https://blog.bemanuel.com.br/2020/11/pfsense-pfblocker-e-a-lista-de-reputa%C3%A7%C3%A3o-do-serpro/</guid>
      <description>&lt;h2 id=&#34;pfsense-e-pfblocker&#34;&gt;pfSense e pfBlocker&lt;/h2&gt;&#xA;&lt;p&gt;O pfSense é um sistema completo de firewall opensource sob a licença BSD, baseado no FreeBSD. Tem sido amplamente utilizado por diversas instituições publicas ou privadas não só pelo fato de ter seu segmento voltado para a comunidade mas também por ser de fácil uso, estável, dispor de ótimas ferramentas complementares como OpenBGPD, SquidGuard, Suricata, dentre muitos outros, além de permitir que sejam desenvolvidos pacotes que complementem suas funcionalidades, como é o caso do &lt;a href=&#34;https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.html&#34;&gt;pfBlocker&lt;/a&gt;, ferramenta que permite que se adicione ao pfSense funcionalidades como:&lt;/p&gt;</description>
    </item>
    <item>
      <title>NXFilter autenticando em AD</title>
      <link>https://blog.bemanuel.com.br/2017/07/nxfilter-autenticando-em-ad/</link>
      <pubDate>Mon, 03 Jul 2017 00:00:00 +0000</pubDate>
      <guid>https://blog.bemanuel.com.br/2017/07/nxfilter-autenticando-em-ad/</guid>
      <description>&lt;h4 id=&#34;apresentação&#34;&gt;Apresentação&lt;/h4&gt;&#xA;&lt;p&gt;O &lt;a href=&#34;https://nxf.kernel.inf.br&#34;&gt;NXFilter&lt;/a&gt; é uma ferramenta que começou com a ideia de atuar como filtro DNS e agora provê também a possibilidade de filtro de conteúdo web.&lt;/p&gt;&#xA;&lt;p&gt;A documentação completa da ferramenta está no &lt;a href=&#34;http://docs.nxf.kernel.inf.br&#34;&gt;tutorial&lt;/a&gt; já traduzido.&lt;/p&gt;&#xA;&lt;p&gt;Dentre as vantagens disponibilizadas se tem:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;É uma ferramenta leve e de fácil instalação&lt;/li&gt;&#xA;&lt;li&gt;Controle por autenticação usando: LDAP, AD, Single-sign-on ( SSO ), etc&amp;hellip;&lt;/li&gt;&#xA;&lt;li&gt;Pode substituir inclusive o seu proxy-cache como o Squid, em determinadas funções&lt;/li&gt;&#xA;&lt;li&gt;Usando outros componentes permite inclusive o bloqueio de ferramentas como UltraSurf e Tor&lt;/li&gt;&#xA;&lt;li&gt;Reconhecimento dinâmico de sites, não depende apenas de listas, encontra o padrão e a classifica&lt;/li&gt;&#xA;&lt;li&gt;Detectar trojans na sua rede&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;h4 id=&#34;funcionamento&#34;&gt;Funcionamento&lt;/h4&gt;&#xA;&lt;p&gt;Seu principio é atuar como servidor DNS, pode fazer:&lt;/p&gt;</description>
    </item>
    <item>
      <title>NXFilter no pfSense</title>
      <link>https://blog.bemanuel.com.br/2016/04/nxfilter-no-pfsense/</link>
      <pubDate>Wed, 13 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://blog.bemanuel.com.br/2016/04/nxfilter-no-pfsense/</guid>
      <description>&lt;h3 id=&#34;apresentação&#34;&gt;Apresentação&lt;/h3&gt;&#xA;&lt;p&gt;&lt;strong&gt;Atenção essa instalação não foi homologada em produção e não teve testes de segurança, se feito não tenho responsabilidades pelos problemas causados&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Com o lançamento do pfSense 2.3 a instalação do NxFilter no mesmo servidor teve algumas mudanças, seguem os procedimentos para fazê-lo.&lt;/p&gt;&#xA;&lt;h5 id=&#34;instalando-o-java&#34;&gt;Instalando o Java&lt;/h5&gt;&#xA;&lt;p&gt;O Java é o pré-requisito e foi a maior mudança que houve no processo de instalação.&#xA;Acesse o servidor via SSH:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/openjdk8-jre-8.66.17_3.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/giflib-5.1.2_2.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/libXt-1.1.5,1.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/xproto-7.0.28.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/libSM-1.2.2_3,1.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/libICE-1.0.9_1,1.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/libX11-1.6.3,1.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/kbproto-1.0.7.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/libXdmcp-1.1.2.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/libxcb-1.11.1.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/libpthread-stubs-0.3_6.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/libXtst-1.2.2_3.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/libXext-1.3.3_1,1.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/xextproto-7.3.0.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/inputproto-2.3.1.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/libXi-1.7.6,1.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/libXfixes-5.0.1_3.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/fixesproto-5.0.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/recordproto-1.14.2.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/java-zoneinfo-2015.f.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/libXrender-0.9.9.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/renderproto-0.11.1.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/freetype2-2.6.2.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/alsa-lib-1.1.0.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/fontconfig-2.11.1_1,1.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/dejavu-2.35.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/mkfontdir-1.0.7.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/mkfontscale-1.1.2.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/libXau-1.0.8_3.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/java-zoneinfo-2015.f.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/javavmwrapper-2.5.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;fetch http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/libfontenc-1.1.3.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;#Instalando o openjdk8&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;pkg add openjdk8-jre-8.66.17_3.txz&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;#Pontos de montagem necessários&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;mount -t fdescfs fdesc /dev/fd&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;mount -t procfs proc /proc&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Testando o funcionamento do pacote java&lt;/p&gt;</description>
    </item>
    <item>
      <title>NXFilter - O Filtro DNS</title>
      <link>https://blog.bemanuel.com.br/2016/04/nxfilter-o-filtro-dns/</link>
      <pubDate>Fri, 15 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://blog.bemanuel.com.br/2016/04/nxfilter-o-filtro-dns/</guid>
      <description>&lt;h4 id=&#34;apresentação&#34;&gt;Apresentação&lt;/h4&gt;&#xA;&lt;p&gt;O &lt;a href=&#34;https://nxf.kernel.inf.br&#34;&gt;NXFilter&lt;/a&gt; é uma ferramenta que começou com a ideia de atuar como filtro DNS e agora provê também a possibilidade de filtro de conteúdo web.&lt;/p&gt;&#xA;&lt;p&gt;A documentação completa da ferramenta está no &lt;a href=&#34;http://docs.nxf.kernel.inf.br&#34;&gt;tutorial&lt;/a&gt; já traduzido.&lt;/p&gt;&#xA;&lt;p&gt;Dentre as vantagens disponibilizadas se tem:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;É uma ferramenta leve e de fácil instalação&lt;/li&gt;&#xA;&lt;li&gt;Controle por autenticação usando: LDAP, AD, Single-sign-on ( SSO ), etc&amp;hellip;&lt;/li&gt;&#xA;&lt;li&gt;Pode substituir inclusive o seu proxy-cache como o Squid&lt;/li&gt;&#xA;&lt;li&gt;Usando outros componentes permite inclusive o bloqueio de ferramentas como UltraSurf e Tor&lt;/li&gt;&#xA;&lt;li&gt;Reconhecimento dinâmico de sites, não depende apenas de listas, encontra o padrão e a classifica&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;h4 id=&#34;funcionamento&#34;&gt;Funcionamento&lt;/h4&gt;&#xA;&lt;p&gt;Seu principio é atuar como servidor DNS, pode fazer:&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
