Learn how to install pfSense on a Virtual Machine in VMware ESXi.
Permanent link to this article: https://achubbard.com/2020/03/06/installing-pfsense-on-vmware-esxi-virtual-machine-virtual-firewall/
Over the years I have had numerous different types of firewalls and UTMs in my home lab. For a while, I ran an ASA, then migrated to pfSense and soon after that I went over the a Ubiquiti USG-Pro. Looking for my next challenge, I stumbled across Untangle. Although I had heard of Untangle before I had never used it. I figured I would give it a try. Untangle has a home use version available for $50 per year. I purchased a subscription. So far, it has been a fairly decent application. I have been extremely happy with it. For $50 you get Untangle and most of their premium plugins. I thought it was a great deal.
To download and/or purchase Untangle at Home Please click the link below
The consumer can download Untangle in a couple of difference forms. ISO 32/64bit, Firmware or as a Virtual Appliance. I thought, great, I can download Untangle, spin up a VM and be on my way. As it turns out, Untangle only provides their appliance as an OVA. This is only supported by VMWare. Here in lies my issue, I am running Hyper-V. I was determined to get it this working either way. Untangle will install on Hyper-V, they just do not provide the virtual appliance.
Getting Untangle to work on Hyper-V took me some time. I ran into numerous configuration issues along the way. Almost to the point where I gave up on the whole project. However, I was fairly determined to make it work. My background is in ESXi and not Hyper-V so that was where most of my learning curve came from. For me, the biggest hangup was configuring the virtual switch for the WAN. Whatever my issue was, I could not get it to function. Hopefully my blog/tutorial post will help someone get their Untangle instance setup on Hyper-V
Virtual Switch Configuration
Prior to creating a new virtual machine for your Untangle install, open up the Hyper-V Management Console and create 2 virtual switches. The Virtual Switch Manager will help you do this. One will be for the LAN connection, the other will be for the WAN connection.
We will start with the “External” or the WAN switch first. On your physical host, this is where you will plug your ISP’s modem into.
Create your virtual switch. Give it a name that indicates it’s use, so in this case, mine is simply, “WAN”. From the drop down menu under the “External Network” radio button, select the physical adapter that you will use. Be sure to un-check “Allow management operating system to share this network adapter” – this will prevent your host from trying to use it.
Repeat the virtual switch creation process again, only this time, select the physical network adapter on your host that you will be connecting to your LAN. Select “External” for this switch too. Be sure to check off “Allow management operating system to share this adapter” – this will allow your host to share LAN access with this VM.
Virtual Machine Creation and Specs
Create a new virtual machine. If you need help creating a virtual machine, please see my post titled “CentOS 7 Minimal Installation on Hyper-V”or click on the link to take you there. The only difference with this virtual machine will be the specs. Here is what I have chosen for my install:
Processor: 2 Virtual Processors
Hard Drive: 40gb
Network Adapters: 2 – 1 for LAN, 1 for WAN
Once your VM has booted, you will see the “Untangle Installer Boot Menu” – I used the graphical install option
Select your language
Pick your location
Choose your keyboard type
Untangle will show you a system summary before beginning it’s installation process
To continue with the installation, select “yes” to format your VHD.
Write the changes to disk
Untangle will continue it’s base install. This process takes a little while, you may want to go make yourself a coffee and come back.
Untangle has now completed it’s long installation, click on continue and the VM will reboot.
With Untangle on Hyper-V I have found that it sometimes has the tendency to appear to be hung up on this spot. Don’t worry though, let it sit and it will come right up. It is not stuck.
When the VM boots up and launches the OS, you will be prompted to go through the initial setup phase. This is fairly straight forward. At this point, you have now installed Untangle on Hyper-V.
I hope this tutorial helps you understand how to get Untangle installed on Hyper-V. It is a fairly straight forward process. Although I ran into some issues initially because I had never done it before.
Permanent link to this article: https://achubbard.com/2018/02/01/installing-untangle-hyper-v/
CentOS Minimal Installation Tutorial
This tutorial will show you how to install CentOS minimal on a Hyper-V virtual machine. We will also focus on getting network connectivity.
Before we begin this tutorial, please head over to centos.org and grab a copy of the latest ISO of CentOS Minimal, link below.
Creating the virtual machine:
Once you’ve downloaded your ISO, on your server or workstation running Hyper-V, launch the Hyper-V management console.
Within the management console, right click on your server, and select “New” and then “Virtual Machine”
Give your new VM a name and instruct Hyper-V on where to store the config files.
Select the amount of memory you want your virtual machine to have. In my case, I have chosen to give mine 1024mb or 1gig.
Pick your network connection (this is your virtual switch) and click “next”
Once you’ve assigned your new VM a network connection, you need to create a virtual hard disk for it. Select “Create Virtual Hard Disk” from the menu, give it a name, select the location you wish to save it in and the size.
Now we must tell Hyper-V where to find the CentOS ISO that we downloaded. Select “Install an operating system from a boot CD/DVD-ROM” pick the “Image File (.iso)” option. Click on “Browse” and locate the ISO. Then click “Next”
Finally a summary page will be displayed. This will tell you all of the options that you selected for your virtual machine. At this step, please click on “Finish.” Clicking “Finish” will bring you back to the Hyper-V management console.
In the Hyper-V management console, find your newly created virtual machine, select it and right click. Click on the “Connect” option that appears.
Go ahead and click on the green power button to fire up your VM.
Installing CentOS on your Virtual Machine
Your virtual machine will now begin to read the ISO inserted into it’s virtual optical drive. Using the arrows on your keyboard, highlight the “Install CentOS 7” and hit the enter key.
Select your language. In my case, I left it as the default of English. Then click continue.
Select the disk on which you wish to install CentOS. I typically allow CentOS to use the automatic partitioning feature. Then click “Done”
During the installation, you are asked to set a root password and/or create a user. I have chosen to do both. You may click each icon and assign a password and create a user. CentOS will then set these during it’s installation.
Allow CentOS to complete it’s installation process. Once this step is complete, the virtual machine will reboot. Once it has rebooted, you will see the following prompt. Here you can login with either your root user or the user you had CentOS create during installation. CentOS is now installed.
Gaining Network Access
CentOS minimal out of the box on Hyper-V will not get an IP Address. You can verify this by logging in and issuing the command “ip addr”
If you get an IP address, you should see it listed under “eth0” – in this case we do not see an IP address. This is because CentOS does not go out and try to grab an IP on boot. In order to change this, you must issue the command, “vi /etc/sysconfig/network-scripts/ifcfg-eth0”
To change this config, hit the “i” key to switch vi into insert mode. Arrow down until you get to the last entry, “ONBOOT”, you must change this from “no” to “yes” – when you’ve changed this, hit the : key and type wq to write the changes and quit vi.
Restart your network interface by issuing the command “systemctl restart network” – CentOS will hang for a moment and then restart the network adapter.
Now you can issue the command “ip addr” again and you should see an IP address listed for interface eth0.
You now have a base CentOS Minimal install with network connectivity. This will give you a great base to install Nagios. I will be writing a tutorial shortly on the installation and configuration of Nagios Core on CentOS.
Check out some of my other blogs on Hyper-V!
Permanent link to this article: https://achubbard.com/2018/01/31/centos-7-minimal-installation-hyper-v/
Unifi and NanoStation VLAN Configuration
This is a tutorial on how to configure a VLAN on a Ubiquiti Unifi Controller and switch. We will also go over how to use the second ethernet port on a Ubiquti NanoStation on a different VLAN for use with a Ubiquiti Security Camera.
I have a rather long driveway, our upper half of the driveway is where my office and house are located. The lower half houses an area for our growing animal population and parking. I have multiple VLANs, 1 of which is for my security cameras. I wanted the 2nd port on the Ubiquiti NanoStation placed on the lower portion of the driveway to be able to utilize my camera VLAN.
This tutorial will assume that all of the hardware is in place and you are ready to make the secondary ethernet port on the NanoStation work on another VLAN.
In my case, I have a Unifi Controller that will need to be configured with my security VLAN, VLAN35, prior to configuring my NanoStations.
Enter the Unifi controller and navigate to Settings >Networks.
Click on the “Create New Network” button. Select “VLAN Only” from the “Purpose” section. Give your VLAN a name and a number. I chose 35.
You can then configure any other settings for your new VLAN that you may need. In my case, I only needed the basics. No DHCP on my security VLAN. You can then click on the “Save” button.
Once saved, in the Unifi controller, navigate to “Devices”
Select your switch and it will open the device’s configurations on the right hand side of the page. Select your port from the list and click “Edit”
On my “Core” (I use quotations because it is not really a core switch, but it is my main switch) I picked port 2 to use for my NanoStation uplink.
You want to make sure the “Switch Port Profile” is set to “All” – The reason is that this port is going to act as a trunk port and provide all of the VLANs to your first NanoStation. You want this if you wish to pass all of your VLANs over the bridge. Click “Apply”
NanoStation Station 1 Configuration
Next, login to the web interface of your NanoStation that will be acting as the “Station” – Navigate to the “Wireless” tab. Here you want to configure your wireless bridge settings (IE: your SSID, WPA2 Key, Channel Width etc) – I will leave that up to you to determine what works for your application. Since this NanoStation is acting as the “Station” you want to make sure the “Wireless Mode” is set to “Station”
Below is what I chose for my settings:
Once the wireless portion of your first station is configured, go to the “Network” tab. Here you can configure your station with a static IP etc. For the purposes of this tutorial, we will assume you have already given your station a static IP address, gateway, mask, DNS and so forth. You will want to make sure that the “Network Mode” is set to “Bridge” and that the “Configuration Mode” is set to “Simple”
NanoStation Station 2 Configuration
After completing the setup of your first NanoStation, login to the web interface of the second NanoStation. First go to the “Wireless” tab on your second NanoStation. This time you will want “Wireless Mode” to be set as “Access Point” – You will then match the rest of the settings to the settings you configured on the “Wireless” tab on your first NanoStation.
Once you have selected your settings, navigate to the “Network” tab on your second NanoStation. This is where things get to be a little be more complex. Since the wireless bridge itself is passing all of the VLANs across it, we need to tell the NanoStation what VLAN to use for the 2nd onboard ethernet port. This is the port we will be daisy chaining our camera off of.
VLAN and Bridge Configuration
On station number 2, your “Network Mode” will also be set to “Bridge”, you will have the option to set a static IP, mask, gateway and so forth. The real difference here is that the “Configuration Mode” MUST be set to “Advanced” this will open up a slew of different options for you.
When “Advanced” is selected, you will now see a bunch of options at the bottom of the page. For this example, the LAN0 port is feeding a switch, the LAN1 port is what the camera will be daisy chained off of and WLAN0 is the wireless bridge between the two NanoStations.
Under the VLAN Network section, we first must add VLAN35 to each interface. This will allow the NanoStation to pass VLAN 35 over the wireless bridge and the 2 ethernet ports.
After adding the VLAN to the interfaces, come on down to the “Bridge Network” section. If memory serves me correctly, you must break the existing bridge to configure a new bridge.
BRIDGE0 is allowing LAN0 and WLAN0 to communicate thus passing management traffic to the switch connected to that ethernet port.
BRIDGE1 is allowing LAN1 and WLAN0.35 to communicate thus allowing camera traffic to pass from LAN1 to the wireless bridge, and back to the NVR.
After configuring the bridges, you must go up to the “Management Network Settings” section. Select “Management Interface”, in my case, it is “BRIDGE0” or my “management” VLAN.
The final step before you can plug the camera in, is to enable POE Passthrough. This allows the NanoStation to power the camera via POE on the secondary LAN port. On your second NanoStation, navigate to the “Advanced” tab. Scroll down until you find “Advanced Ethernet Settings”. Check the checkbox labeled “POE Passthrough enabled”. Click the change button and you should now be able to power up your camera on a separate VLAN.
Hope this helps someone, I spent a lot of time trying to get this to work on my property.
Permanent link to this article: https://achubbard.com/2018/01/30/ubiquiti-unifi-vlan-configuration-and-nanostation-ethernet-port-vlan-configuration/