pfsense 軟體防火強系統建構試驗的紀錄


 

這星期六日是電腦淘汰廢料零件的第2次試驗:軟體路由器的測試,從今天早上七點吃完早餐到下午三點半,才弄通網路的每個設備都被驅動及軟體設備,家用設備都可連線成功!
基本網路理論都很簡單,自己搞遇到的實務問題太多,小品牌網路卡沒有驅動程式,因為不是大廠產品,intel 網卡插上主板就可以立即找到,我那幾片2.5GB網卡是淘寶買來台灣瑞昱半導體的晶片,軟體商為了版本的空間限制考量,新版把原有網路卡驅動程式給閹割,以節省空間與系統負荷!
要自己搞驅動程式安裝,先以過去半生不熟linux安裝程式的方法,還要把SSH功能及22號port打開來,最後要修系統設定檔要改,編輯軟體vi卻忘了使用方式,命令模式,編輯模式都搞亂了,一個小時只處理兩行系統設定,最後四片個網路都有完整驅動起來,可以自由搭配運用!

This Saturday and Sunday mark the second trial of computer obsolete parts experimentation: testing software routers. From 7 a.m. this morning until 3:30 p.m. in the afternoon, I finally managed to get every device on the network up and running, including all the software components. Home devices can now connect successfully!

The basics of networking theory are quite simple, but practical problems often arise when dealing with them. My small-brand network cards didn't have the necessary drivers since they are not products from major manufacturers. On the other hand, when I plugged in an Intel network card into the motherboard, it was immediately recognized. The couple of 2.5GB network cards I purchased from Taobao were equipped with Realtek semiconductors. However, due to space limitations in newer versions of the software, the network card drivers were stripped down, saving space and reducing system load.

Installing the drivers myself required using methods I hadn't been familiar with since my early experiences with Linux installation. I had to enable the SSH feature and open port 22. Finally, I had to modify the system configuration files. However, I forgot how to use the vi editor properly, getting confused between command mode and edit mode. It took me an hour just to work on two lines of system configuration. In the end, I managed to get all four network cards fully functional, allowing for flexible combinations and applications!




pfsense系統是以Linux 的FreeBSD為基底的防火牆系統,系統很小,對於電腦要求不高⋯⋯就是種接近專業的防火牆軟體,防火牆規則設定本有些複雜,簡單說,既然是為了維護安全的防火牆,原則就是ports預設都是全面先關閉,要用的ports才需要再來打開,還可以限制資料風包允許的source 及可以到達的destination ,其他網路動向都不會通過!自己搞軟體設定,不見得合適,因為雜牌軍廢料要還可以用,就是一門苦差事,再來才是防火牆軟體設定的測試!

去買商品化的小型網路路由器會比較簡易,YT一堆大陸軟路由的影片很火紅,是因為大陸的網路被國家的長城防火牆給擋住,要科學上網,軟體路由器可以協助翻牆,才能看到中國以外的網路消息。pfsense在家用實在太複雜,市售網速2.5GB的八孔分享器要三千多元左右,繳個智商稅及加速晶片去庫存吧!

The pfsense system is a firewall system based on FreeBSD, a variant of Linux. It is a lightweight system that doesn't require high computer specifications. It can be considered a professional-grade firewall software. The configuration of firewall rules can be complex. In simple terms, since the firewall is designed to maintain security, the default setting is to have all ports closed. Only the ports that are needed should be opened, and it is possible to restrict the allowed source and destination of data packets. All other network activities are blocked! Configuring the software on your own may not be suitable, especially when dealing with miscellaneous hardware. It can be quite a challenging task, and then comes the testing of the firewall software configuration! If you want something simpler, buying a commercial network router would be easier. There are plenty of popular videos on platforms like YouTube about Chinese software routers because the internet in China is restricted by the country's Great Firewall. Software routers can help bypass the restrictions and allow access to internet content outside of China. pfsense is quite complex for home use, and commercially available 2.5GB eight-port routers can cost around three thousand yuan. It's like paying an "IQ tax" and investing in acceleration chips to clear the inventory!

留言

這個網誌中的熱門文章

腹腔鏡膽囊切除術 (LC)的風險與注意事項-卡洛氏三角區(Calot triangle)正確找出總膽管及膽囊動脈這兩條管路是手術安全的關鍵

情緒的神經科學