📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

OPNSense - Unlock Next-Generation Firewall features with Zenarmor - Virtual Lab Building Series: Ep7

LS111 Cyber Security Education18:10

Transcription

In this video, I'm going to show you how to install Zen Armor on your OpenSense firewall to enable its next-generation firewall features. Let's jump straight in.

[Music]

[Music]

Hey, I'm Lal and welcome back to my channel. So, if you've been following my series this fall, we've done quite a number of various things with the OpenSense firewall, such as high availability and packet filtering and so forth. This is going to be the last video that we're going to be dealing with the OpenSense firewall in this series, where we're going to be installing the next-generation firewall features through an add-on called Zen Armor.

So, if you don't know what a next-generation firewall is, it's basically a firewall that has some sort of intelligence built into it using various technologies like threat intelligence that it ingests from third parties. It also has deep packet inspection and the ability to look at Layer 7 traffic or application layer traffic and understand completely what is inside that packet, instead of just looking at the sessions that are traversing the firewall. With threats becoming more advanced in today's age, it's important that we have these next-generation firewalls deployed in our networks, then, so we can have some sort of context about the security threats that are happening.

So, to install this firewall on OpenSense, we'll first need to do some upgrades to our firewall. So, we'll go to System and to Firmware and to Status. And then, what we'll do is we need to click on the "Check for Updates." I've already done this, and my firewall is fully up to date. Then, we'll head over to Plugins. And inside Plugins, you can see that I've already installed these next-generation features. They're called, in this case, OS Sensei, which I believe was the previous name that was given to Zen Armor. What you'll need to do is you'll need to type in "OS Sunny Valley." And this is just the repository that we need to first pull. And you'll see that you'll have a little plus sign that will be that'll be visible to you over there, and this will then install the repository. And then, once you've done that, you can then install Zen Armor following the same steps. Then, once you have all those installed, you'll see they will be available to you in your plugins.

Once Zen Armor is installed, you'll notice that there will be a menu option for it. So, you'll head down to it and you will click on Dashboard to get started. The first time you run Zen Armor, you'll be presented with a wizard screen. This is just part of the initial setup. So, to do this, we will select the checkbox here just to accept the terms of service and the privacy policy, and then we will click "Proceed." And then Zen Armor is going to just do a hardware check for us to make sure that we have compatible hardware in order to run the service. This usually takes about 30 seconds to complete. Once it's completed, it'll show you some little green ticks here just to show that the hardware is compatible. I recommend for this lab that you at least set up, uh, eight gigs of RAM on your virtual machine, or else it will fail. Click "Next."

So, we're going to set up our reporting database. For this lab, we're just going to be using the local Elasticsearch database. So, we'll say "Install Database" and "Proceed." And then we're just going to let it run its course. This usually takes a minute or two to get done. And then, once the installation is complete, you'll see that it'll give you a little successful message. Everything will be all nice and green, and you simply click "Next."

The next tab asks us to configure the interface selection. So, our deployment mode, we're going to leave as the rooted mode with Layer 3 mode enabled. And we are going to scroll down to our interface selection that we want the service to run on, and we'll select LAN and we'll click it across to the protected interfaces. And then, from there, we'll simply click "Next."

And then this window is just for the cloud reputation and web categorization service configuration. So, it just provides us with some sort of like threat intelligence and web categorization for our firewall to use. So, we're going to enable it. And if you scroll down, we're just going to leave it as default. So, it uses the European and the US East cloud nodes. And once you're done with that, you can click "Next."

And then this is just the updates and health checks. So, it's just telling the system when it needs to do any automatic updates and apply those updates. And we can leave all these settings as default and click "Next."

And then this option here gives us, or asks us rather, what are deployment sizes. In this case, I'm just going to set it up as "Home." We have less than 15 concurrent users, but this will vary obviously depending on the size of your organization or however, you know, you intend on using this. But for a lab environment, "Home" should be more than enough. And we'll click "Next."

And then we're all done. If you'd like to include your email address here, feel free to do so. I'm just going to click "Finish." And then Zen Armor is going to start its engine, and we're going to be all up and running. And then you'll be prompted with a prompt that will just tell you everything has been successfully completed and that Sensei has been installed. And you can click "Refresh." And then you'll have your Zen Armor status page and dashboard looking something similar to this.

So, now that everything has been installed successfully, it's time for us to go and explore a little bit and see what Zen Armor is capable of doing. So, the first place I'm going to start with is the Dashboard. I'll click on the Dashboard, and you'll see that it gives us these nice little graphs. This obviously won't be as populated when you start the service for the first time. Mine's been running for a few minutes, so it's already starting to fill up all these bits of information. So, just some obvious things at the top, we've got a filtering option where we can filter by a number of different categories that allows us to drill down onto any particular traffic or website or anything that we, we're after. And, uh, if you scroll down, you can see we've, we've, we've got a lot of information here at our fingertips. So, we've got like top promote hosts, top egress users, obviously only going to be one in this case because it's only my lab machine connected to this. And yeah, you can see things like egress and new connections by app over time, new connections and remote hosts and so forth. And then it also gives you information about the number of connections that's going through the system, top destination locations, heat map, and various other bits of information which may be useful for your organization or for your purposes.

The menu option we're going to look at is the Status option. This just gives us a breakdown of the status of the service running on the firewall, information about the engine version and so forth, and the different cloud node statuses that is available to us. I had an update that I needed to install just after we did the, did the installation. So, you may have that in your case if you've been following along as well. Uh, it's well worth installing the update, then, at least you know everything is, is up to date and ready to roll.

The next menu option we're going to look at is the Reports menu. This looks very similar to the Dashboard that we just looked at. However, they have now included some tabs at the top here, then, so we can break down the, the reporting by connections, threats, um, content that's been blocked, web, DNS, and TLS. You can also apply a similar filter like we saw with the Dashboard. But what's quite nice about this menu is it also gives us a live session explorer. So, if we click on it, and then we can see all the active connections and sessions that's currently going through the firewall in real time. And if it hits any of the policies, in this case, we just have a default policy, but you may have other policies here for specific needs. Those sort of features will be available in the premium or the, the full version of, of Zen Armor. We're currently running the free version, um, however, yeah, for, for the sake of this lab, I think this gives us more than enough information to explore. So, we can drill down into these and see, you know, yeah, we've got a bit of DNS traffic going to 8.8.8, and it gives us some sort of, um, you know, little actions here. So, we can view the details, drill down on that, we can block that connection in real time if we wanted to, and we could do a query on that as well.

The next tab that we can look at is Threats. This would obviously be populated if there were any threats detected by your firewall. In this case, everything is 100% on mine, so there's no threats or anything along those lines. But all that information would be populated in the, in this menu. And then we have Blocks. Same case here, I don't have anything blocked at the moment, but if there were websites that were blocked, they would land up in this section. And also, with every single one of these reporting features, we have a live block session explorer. And the same with threats, we also have a live security event monitor. So, we can drill down further on those. And then the same applies for Web. We can look at our top web categories, the ports used, they have these little like tag clouds and so forth. And the same with DNS and TLS as well.

The next option we're going to look at is Policies. So, as I said earlier, because this is the free edition, we can only set up one policy. If you try to add another policy, it will give you this prompt saying you've discovered a premium feature, and then you can upgrade to premium. Um, so we'll just use this one single default policy. And then it just gives you a breakdown here of what the, the policy has active at the moment. So, it is currently active, its status has been applied, and we have security enabled. I haven't enabled any app controls. We'll check out that menu in a, in a few minutes. But if I had any app controls applied, it would also come up as enabled. And I have a few web controls enabled. So, to edit this policy, we'll click on the little pencil icon. And if we just went back one tab to Policy Configuration, you'll see that all of this is just grayed out because it is the default policy. We, we can't actually make any changes to this unless we have a premium subscription.

If we go to the Security tab, you will see we have the essential security enabled. So, this is things like blocking malware and phishing servers and spam sites and so forth. You can obviously select your, what you would like. These advanced security features on the side is once again a premium only option, so we can't enable those in this lab.

The next tab we're going to look at is the App Control tab. And inside here, you'll see there's a large number of apps that come pre-installed that we can set up to, to block. So, let's just have a look at, for example, if we click on the little folder next to it, it'll drop down and give us all those particular apps related to email that we could block, so Google Mail, Google Webmail, etc. And they have this for gaming and various other services as well. And similar to app controls, we also have web controls. And at the top, it gives us an option to select the preset profile. So, "Permissive" would be everything's allowed. And then we have a "Moderate Control" and a "High Control." If you would like to select custom controls here, once again, you need a premium subscription. But, uh, it is what it, what it states here. These are different web categories that we can block. So, it's going to be all the obvious ones like ad trackers and adult and pornography and drugs and all those kind of things that generally wouldn't be allowed in any organization or enterprise.

And then the final tab option here is the Exclusions, where it's pretty self-explanatory. You can have a whitelist and a blacklist, and you can choose what you would like to exclude and include across your network.

The final option we're going to look at is just the Configuration. This looks very similar to when we did the initial installation, where we set up our deployment mode and our interfaces. However, if you need to come back and make any changes, this is the place that you'll do all of those kind of things. And, yeah, you can set up your cloud threat intel, if there's any updates, how frequently you want your updates to run, reporting and data, if you need to make any backups. And then they've also got a cloud management portal feature, which you can enable. This comes part of your premium package. And other tabs like About and Uninstall and so forth.

So, to wrap this video up, we've successfully installed Zen Armor on our OpenSense firewall. Go ahead and play around with it in your lab environment and learn its full capabilities. I believe in cybersecurity that it's important that you guys are aware of how these next-generation firewalls work, and this gives us a free way to explore a lot of those features which you'll only have access to in the enterprise environment, which generally costs a lot of money to be able to have access to those kind of features and devices and so forth.

If you've enjoyed this video, please don't forget to give me a thumbs up and to subscribe. It'll help me to grow my channel. And as always, if you have any comments or questions, or if you get stuck anywhere along the way with the installation, please do drop me a line, and I'll try my best to answer the questions and resolve any issues that you guys have. That's all for this video. Stay tuned. I've got some exciting lab work planned for the future. We're going to be looking at some Windows vulnerabilities and also learning how to set up some threat hunting features in our lab. So, stay tuned for that. Thanks again for watching, and I'll see you guys soon. Cheers for now.

[Music]