Multiple Vulnerabilities in PfSense
cybersecurity-help.cz
cybersecurity-help.cz
I was a big pfSense fan, telling myself that the odd stuff Netgate did was normal/justified.
Until the attack on Wireguard's Jason A. Donenfeld. Then I realised - it's all true. They are bordering on insane in that organisation. I regret suggesting my old workmate purchase some of their hardware now.
Opnsense is a great replacement. I'm sure it's not perfect, but they're open, friendly, responsive and don't make you question every comment you write on their forum for fear of being banned.
The APs are good and the switches too in my experience. However the UDM-P is a troubled device. It’s buggy, things break or stop working and it loses its config every so often. The form factor is very compelling and the concept is great.
I’d pay more if the software quality were better.
I've been running a UDM and UDMP for years, and have literally never run into any of those issues, despite having a somewhat complex network (for a home network anyway).
It runs 24/7 and only needs reboots when a software update requires it. Multiple VLANs, road warrior VPN. I run a site to site VPN between my UDMP at home and UDM at my summerhouse, and that has been rock solid as well.
In the latest EA version of the software, there is also some support for Wireguard (though UI's Teleport). I'm not sure if "raw" Wireguard is available (yet).
Latest version also implements policy based routing.
I’m in the latest stable version, as I updated after an outage last week where the controller was crashed.
The variability in user satisfaction suggests some sort of hardware issue or bugginess that hits a small portion of users.
Maybe that has changed but I'm not aware that it has.
I just ended up resetting my network (switch, sec gateway, controller, and AP) and it's a little tricky without their cloud. You need to do some SSH'ing.
Caveats aside, the hardware is outstanding, the disk AP is solid as is the consumer grade cube one. It's a good prosumer and small business option despite the downsides.
https://www.theregister.com/2019/11/07/ubiquiti_networks_pho...
The best firewalls/routers i've ever used have been Vyos (or Vyatta) based.
Point & Click has it's charms, but its a crutch. With Vyos you can "replay" you entire configuration over a serial port, as well as make changes to it in a regular text editor.
It does have a learning curve though :)
I'm also on the UniFi line of things for now, but i really wish somebody would make a decent Vyos based appliance (low powered ARM device) like the Ubiquiti Edgerouters of old.
Wasn’t EdgeOS a fork of Vyatta?
Long live the CLI :)
It's quite nerdy though. And all it does is move the single point of the failure to the switch (required for the hosts to talk to each other for VRRP etc)
Proxmox is so reliable in my experience though, but I don't tend to fiddle with it, just set and forget.
For comparison, an 8 Gbps capable pfSense appliance (like the Netgate 4100) requires 40W-50W (max 60W), where the UniFi Dream Machine Pro, also capable of 8Gbps, has a maximum power consumption of 33W, which includes a 3.5" harddrive for UniFi Protect. Mine uses about 18W without the harddrive, and 22W with a WD Red.
A difference of 25W over a year at current european electricity prices (€0.5/kWh) means a saving of 219 kWh (€109/year). Considering that electricity has been as high as €1.12/kWh this spring, it could be even higher.
As for virtualization, while it's a great learning experience, it's probably more trouble than it's worth. I greatly prefer appliances for network.
[0] https://www.anandtech.com/show/11110/semi-critical-intel-ato...
This sounds fun. do you know where I can read more?
edit: think i found a good start https://www.reddit.com/r/networking/comments/m6zjie/wireguar...
Events in chronological order:
- zx2c4 points out the brokenness of the Netgate implementation and his efforts to fix it: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649...
- ... which ends up being published by Ars: https://arstechnica.com/gadgets/2021/03/in-kernel-wireguard-...
- Netgate throws a fit, zx2c4 responds: https://lists.zx2c4.com/pipermail/wireguard/2021-March/00649...
- FreeBSD maintainer of the WireGuard implementation announces Netgate's implementation will be removed: https://lists.freebsd.org/pipermail/freebsd-hackers/2021-Mar...
- Netgate's damage control / copium response: https://www.netgate.com/blog/painful-lessons-learned-in-secu...
- FreeBSD dev steps down from further involvement with WireGuard-in-FreeBSD: https://lists.freebsd.org/pipermail/freebsd-hackers/2021-Mar...
is Jason (Wireguard creator).
I'm an Open Source user of pfSense (so they don't get money from me) but I still had an extremely helpful experience recently, when I had a feature request. Once I filed it, it was implemented quickly, MUCH better support than I could ever expect from a paid commercial firewall. Also the product runs reliably and is very stable since years. So I won't look for alternatives any time soon.
While I understand their complaints, I don’t understand the constant attacks and hate, as anyone who doesn’t want to support pfsense if there is a paid and a free oss version, is welcome to start a fork or work on other projects.
https://github.com/TKCERT/pfFocus
https://github.com/AndyX90/OPNReport
https://www.reddit.com/r/OPNsenseFirewall/comments/masujb/ti...
Firewall rules tend to aquire "cruft", especially in domestic settings, where you add rules to "fix something", and there is rarely any review of existing rules.
Personally i keep a spreadsheet of the firewall rules i need, including inter VLAN communication, with source/destination ip/port as well as a link to any article describing why this port needs to be open (like Sonos across VLANs, etc).
It sounds cumbersome, but it doesn't change frequently, and reimplementing it in a new firewall takes 30-60 minutes.
Not sure if they were impacted by the bug.
> Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
(The admin interface listens on all network interfaces, including all WAN interfaces. However the default firewall rules black-hole all incoming traffic on the WAN interfaces.)
Also, at least in OPNsense, for some reason, not all interfaces get an IP in the DNS. So if you want to access the admin interface via a name with a certificate, it may not always work if you selectively enable the listening interfaces.
I've had this happened a week ago, where the DNS name wouldn't resolve to the internal interface's IP for some reason... I would only get the WAN interface and some other restricted one I have.
I don’t get it. If you’re authenticated as a privileged user, don’t you have access anyway?
Also in a situation where you have admins with different levels of access, exploits like this could allow an individual low on gruntles to create a privilege escalation situation and gain access to features they should not.
So a low probability of exploit due to the mitigating factor, but a high potential for damage if an exploit is attempted and succeeds.
But these are all pretty lame "vulenrabilities".
pf.conf is very user-friendly, the BSD docs for it are great, and it's nice being able to put everything directly under source control. Diffing individual conf files is a lot prettier than those massive PFSense XMLs.
If it's something extra-special important, a POTS line and a modem make an excellent plan-B.
And this doesn't also reduce the number of customers?
If they're administrator, can't they just log in and use the root shell to do whatever the hell they want? Yes, it's a bug, but is it really a vulnerability?
I'd have not used that wording either, but it is technically incorrect.