{"id":2858,"date":"2024-04-02T18:29:15","date_gmt":"2024-04-02T16:29:15","guid":{"rendered":"https:\/\/hinakuu.xyz\/?p=2858"},"modified":"2024-04-02T20:49:25","modified_gmt":"2024-04-02T18:49:25","slug":"installer-pfsense-dans-vmware-workstation-pour-creer-un-lab-virtuel","status":"publish","type":"post","link":"https:\/\/hinakuu.xyz\/?p=2858","title":{"rendered":"Installer pfSense dans VMWare Workstation pour cr\u00e9er un lab virtuel"},"content":{"rendered":"\n<p><strong>Dans ce tutoriel, nous allons apprendre \u00e0 installer Pfsense au sein d&rsquo;une VM VMWare Workstation dans le but de cr\u00e9er un lab. Cette VM assurera le r\u00f4le de routeur et pare-feu virtuel.<\/strong>&nbsp;Gr\u00e2ce \u00e0 cette machine virtuelle Pfsense, vous allez pouvoir vous exercer sur diff\u00e9rents sujets notamment : la gestion d&rsquo;un pare-feu (autoriser ou refuser les flux du r\u00e9seau local vers Internet, et inversement), faire du NAT, cr\u00e9er des r\u00e8gles de redirection de ports, monter un serveur DHCP, effectuer la mise en place d&rsquo;un proxy, d&rsquo;un reverse proxy, la cr\u00e9ation d&rsquo;une DMZ, etc&#8230;<\/p>\n\n\n\n<p>Source : <a href=\"https:\/\/www.it-connect.fr\/tuto-vmware-workstation-lab-virtuel-pfsense\/\" target=\"_blank\" rel=\"noreferrer noopener\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">https:\/\/www.it-connect.fr\/tuto-vmware-workstation-lab-virtuel-pfsense\/<\/mark><\/a><\/p>\n\n\n\n<p>L&rsquo;objectif va \u00eatre de cr\u00e9er&nbsp;<strong>un r\u00e9seau interne (192.168.100.0\/24)<\/strong>, qui pourra acc\u00e9der \u00e0 internet ,par l&rsquo;interm\u00e9diaire du pare-feu pfSense et<strong>&nbsp;un r\u00e9seau DMZ (192.168.200.0\/24)<\/strong>&nbsp;qui h\u00e9bergera un serveur web IIS qui sera accessible en dehors de notre r\u00e9seau interne.<\/p>\n\n\n\n<p>L&rsquo;interface WAN, qui nous permettra de simuler l&rsquo;\u00e9vasion vers internet sera rattach\u00e9e (en mode bridge) \u00e0 une interface physique du PC sur lequel est d\u00e9ploy\u00e9 VMware Workstation. Cette interface WAN se verra attribuer une configuration IP (Adresse IP, masque de sous-r\u00e9seau, passerelle et serveur DNS) par le service DHCP de notre box internet.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1.Cr\u00e9er une machine virtuelle pour pfSense :<\/h3>\n\n\n\n<p class=\"has-text-align-center\">Dans VMWare Workstation Pro, ouvrez l&rsquo;assistant de cr\u00e9ation d&rsquo;une machine virtuelle depuis le menu \u00ab\u00a0<strong>File &gt; New Virtual Machine<\/strong>\u00ab\u00a0.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"279\" height=\"274\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-02.png\" alt=\"\" class=\"wp-image-2859\"\/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Une fois l&rsquo;assistant lanc\u00e9, nous allons s\u00e9lectionnez le mode de cr\u00e9ation \u00ab\u00a0<strong>Typical<\/strong>\u00a0\u00bb et cliquez sur \u00ab\u00a0<strong>Suivant<\/strong>\u00ab\u00a0.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"425\" height=\"429\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-03.png\" alt=\"\" class=\"wp-image-2860\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-03.png 425w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-03-297x300.png 297w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-03-150x150.png 150w\" sizes=\"auto, (max-width: 425px) 100vw, 425px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">A cette \u00e9tape, nous allons s\u00e9lectionner l&rsquo;option d&rsquo;installation depuis une image ISO et renseigner l&#8217;emplacement de l&rsquo;image.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"428\" height=\"397\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-04.png\" alt=\"\" class=\"wp-image-2861\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-04.png 428w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-04-300x278.png 300w\" sizes=\"auto, (max-width: 428px) 100vw, 428px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Ensuite, nous allons nommer notre machine virtuelle et d\u00e9finir l&#8217;emplacement o\u00f9 stocker les donn\u00e9es de la VM (fichier de configuration, disque dur virtuel, etc.).<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"428\" height=\"397\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-05.png\" alt=\"\" class=\"wp-image-2862\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-05.png 428w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-05-300x278.png 300w\" sizes=\"auto, (max-width: 428px) 100vw, 428px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Nous allons pouvoir configurer le disque dur virtuel de la VM. Dans notre cas, nous sommes dans un lab virtuel donc je vais conserver les param\u00e8tres par d\u00e9faut propos\u00e9s par l&rsquo;assistant de cr\u00e9ation de VM, et cliquer sur \u00ab\u00a0<strong>Suivant<\/strong>\u00ab\u00a0.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"428\" height=\"397\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-06.png\" alt=\"\" class=\"wp-image-2863\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-06.png 428w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-06-300x278.png 300w\" sizes=\"auto, (max-width: 428px) 100vw, 428px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Enfin, nous allons finaliser la cr\u00e9ation de la VM en s&rsquo;assurant qu&rsquo;<strong>elle ne d\u00e9marre pas automatiquement une fois cr\u00e9\u00e9e<\/strong>. Nous allons modifier sa configuration, notamment les interfaces r\u00e9seaux n\u00e9cessaires. Voici l&rsquo;option \u00e0 d\u00e9cocher avant de cliquer sur \u00ab\u00a0<strong>Finish<\/strong>\u00a0\u00bb :<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"428\" height=\"397\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-06-1.png\" alt=\"\" class=\"wp-image-2864\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-06-1.png 428w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-06-1-300x278.png 300w\" sizes=\"auto, (max-width: 428px) 100vw, 428px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2.Configurer la machine virtuelle et ses interfaces r\u00e9seaux :<\/h3>\n\n\n\n<p>Les param\u00e8tres \u00e0 modifier sur notre machine virtuelle sont les suivants :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Passer la RAM \u00e0 2 Go (2048 Mo), minimum<\/li>\n\n\n\n<li>Passer le nombre de c\u0153ur de CPU \u00e0 2, minimum<\/li>\n<\/ul>\n\n\n\n<p>Nous allons cr\u00e9er 2 \u00ab\u00a0<strong>LAN Segment<\/strong>\u00a0\u00bb qui vont permettre d&rsquo;avoir plusieurs r\u00e9seaux virtuels au sein de VMWare Workstation distincts les uns des autres. Pour ce faire, lorsque vous \u00eates sur les param\u00e8tres d&rsquo;une interface r\u00e9seau, cliquez sur \u00ab\u00a0<strong>LAN Segment<\/strong>\u00ab\u00a0. Ensuite, cliquer sur \u00ab\u00a0<strong>Add<\/strong>\u00a0\u00bb et nommez-le.<\/p>\n\n\n\n<p>Dans notre cas, nous allons cr\u00e9er 2 LAN Segment :&nbsp;<strong>LAN&nbsp;<\/strong>et&nbsp;<strong>DMZ<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-gallery aligncenter has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image aligncenter size-large is-style-default\"><img loading=\"lazy\" decoding=\"async\" width=\"413\" height=\"317\" data-id=\"2875\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-08-1.png\" alt=\"\" class=\"wp-image-2875\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-08-1.png 413w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-08-1-300x230.png 300w\" sizes=\"auto, (max-width: 413px) 100vw, 413px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"314\" height=\"283\" data-id=\"2874\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-09.png\" alt=\"\" class=\"wp-image-2874\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-09.png 314w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-09-300x270.png 300w\" sizes=\"auto, (max-width: 314px) 100vw, 314px\" \/><\/figure>\n<\/figure>\n\n\n\n<p>Ensuite, il faut modifier le type de connexion au r\u00e9seau de la premi\u00e8re interface afin de s&rsquo;assurer qu&rsquo;elle soit sur \u00ab\u00a0<strong>Bridge<\/strong>\u00ab\u00a0. Ensuite, cliquez sur \u00ab\u00a0<strong>Add<\/strong>\u00a0\u00bb pour ajouter 2 interfaces r\u00e9seau suppl\u00e9mentaires.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"730\" height=\"626\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-11.png\" alt=\"\" class=\"wp-image-2891\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-11.png 730w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-11-300x257.png 300w\" sizes=\"auto, (max-width: 730px) 100vw, 730px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">L&rsquo;interface r\u00e9seau n\u00b02 sera rattach\u00e9 au LAN Segment \u00ab\u00a0<strong>LAN<\/strong>\u00a0\u00bb et l&rsquo;interface r\u00e9seau n\u00b03 a LAN Segment \u00ab\u00a0<strong>DMZ<\/strong>\u00ab\u00a0.<\/p>\n\n\n\n<figure class=\"wp-block-gallery aligncenter has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"732\" height=\"325\" data-id=\"2894\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-12.png\" alt=\"\" class=\"wp-image-2894\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-12.png 732w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-12-300x133.png 300w\" sizes=\"auto, (max-width: 732px) 100vw, 732px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"733\" height=\"326\" data-id=\"2895\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-13.png\" alt=\"\" class=\"wp-image-2895\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-13.png 733w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-13-300x133.png 300w\" sizes=\"auto, (max-width: 733px) 100vw, 733px\" \/><\/figure>\n<\/figure>\n\n\n\n<p class=\"has-text-align-center\">Pour terminer, enregistrez l&rsquo;ensemble des modifications.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Installer pfSense sur la VM VMware Workstation<\/h3>\n\n\n\n<p>Maintenant que notre VM est configur\u00e9e selon notre besoin, nous allons pouvoir la d\u00e9marrer. Cliquer sur \u00ab\u00a0<strong>Power on this virtual machine<\/strong>\u00ab\u00a0. La VM va automatiquement d\u00e9marr\u00e9 sur le fichier d&rsquo;installation ISO de pfSense.<\/p>\n\n\n\n<p>L&rsquo;installeur de pfSense va d&rsquo;abord analyser la configuration mat\u00e9rielle de la VM et charger l&rsquo;assistant d&rsquo;installation.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"789\" height=\"430\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-15.png\" alt=\"\" class=\"wp-image-2898\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-15.png 789w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-15-300x163.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-15-768x419.png 768w\" sizes=\"auto, (max-width: 789px) 100vw, 789px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Une fois le chargement termin\u00e9, veuillez accepter le contrat d&rsquo;utilisation de pfSense (Tapez sur&nbsp;<strong>Entr\u00e9e<\/strong>).<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"733\" height=\"409\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-16.png\" alt=\"\" class=\"wp-image-2899\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-16.png 733w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-16-300x167.png 300w\" sizes=\"auto, (max-width: 733px) 100vw, 733px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Pour poursuive l&rsquo;installation, s\u00e9lectionnez \u00ab\u00a0<strong>Install pfSense<\/strong>\u00a0\u00bb et appuyez sur&nbsp;<strong>Entr\u00e9e<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"733\" height=\"409\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-17.png\" alt=\"\" class=\"wp-image-2900\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-17.png 733w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-17-300x167.png 300w\" sizes=\"auto, (max-width: 733px) 100vw, 733px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">A l&rsquo;\u00e9tape de partitionnement du disque, nous allons utiliser le mode \u00ab\u00a0<strong>Auto (ZFS)<\/strong>\u00a0\u00bb pr\u00e9s\u00e9lectionn\u00e9 et appuyer sur&nbsp;<strong>Entr\u00e9e<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"733\" height=\"409\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-18.png\" alt=\"\" class=\"wp-image-2901\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-18.png 733w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-18-300x167.png 300w\" sizes=\"auto, (max-width: 733px) 100vw, 733px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">A cette \u00e9tape, un r\u00e9capitulatif du partitionnement automatique ZFS est pr\u00e9sent\u00e9, appuyez sur&nbsp;<strong>Entr\u00e9e&nbsp;<\/strong>pour valider.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"733\" height=\"409\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-19.png\" alt=\"\" class=\"wp-image-2903\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-19.png 733w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-19-300x167.png 300w\" sizes=\"auto, (max-width: 733px) 100vw, 733px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Au travers du syst\u00e8me de fichier ZFS, pfSense peut-\u00eatre install\u00e9 sur de multiple disques pour assurer une disponibilit\u00e9 accrue du pare-feu. Pour en savoir plus sur le RAID, je vous invite \u00e0 consulter&nbsp;<a href=\"https:\/\/fr.wikipedia.org\/wiki\/RAID_(informatique)\" target=\"_blank\" rel=\"noreferrer noopener\">cet article Wikip\u00e9dia<\/a>&nbsp;&#8211; un article sur IT-Connect arrive bient\u00f4t \ud83d\ude42 !<\/p>\n\n\n\n<p class=\"has-text-align-center\">Dans notre cas, nous allons faire une installation sans redondance (<strong>mode stripe<\/strong>). Appuyez sur&nbsp;<strong>Entr\u00e9e<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"733\" height=\"409\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-20.png\" alt=\"\" class=\"wp-image-2904\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-20.png 733w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-20-300x167.png 300w\" sizes=\"auto, (max-width: 733px) 100vw, 733px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Pour s\u00e9lectionner le disque dur virtuel, appuyez sur&nbsp;<strong>Espace&nbsp;<\/strong>puis sur&nbsp;<strong>Entr\u00e9e&nbsp;<\/strong>et s\u00e9lectionner \u00ab\u00a0<strong>Yes<\/strong>\u00a0\u00bb (fl\u00e8che gauche et Entr\u00e9e).<\/p>\n\n\n\n<figure class=\"wp-block-gallery aligncenter has-nested-images columns-default is-cropped wp-block-gallery-3 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"396\" height=\"221\" data-id=\"2906\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-21-edited.png\" alt=\"\" class=\"wp-image-2906\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-21-edited.png 396w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-21-edited-300x167.png 300w\" sizes=\"auto, (max-width: 396px) 100vw, 396px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"454\" height=\"154\" data-id=\"2907\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-22.png\" alt=\"\" class=\"wp-image-2907\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-22.png 454w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-22-300x102.png 300w\" sizes=\"auto, (max-width: 454px) 100vw, 454px\" \/><\/figure>\n<\/figure>\n\n\n\n<p class=\"has-text-align-center\">L&rsquo;installation est relativement rapide. Une fois achev\u00e9, validez le red\u00e9marrage de la VM.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"340\" height=\"122\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-23.png\" alt=\"\" class=\"wp-image-2911\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-23.png 340w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-23-300x108.png 300w\" sizes=\"auto, (max-width: 340px) 100vw, 340px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">4. Premier d\u00e9marrage de pfSense :<\/h3>\n\n\n\n<p>Au premier d\u00e9marrage, pfSense d\u00e9tecte automatiquement les interfaces r\u00e9seau. La plupart du temps, vous verrez&nbsp;<strong>l&rsquo;interface WAN rattach\u00e9e \u00e0 l&rsquo;interface em0 correspondant \u00e0 la premi\u00e8re interface ajout\u00e9e. L&rsquo;interface LAN quant \u00e0 elle sera rattach\u00e9<\/strong>e \u00e0 l&rsquo;<strong>interface em1<\/strong>, correspondant \u00e0 la deuxi\u00e8me interface ajout\u00e9e \u00e0 la VM.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"655\" height=\"341\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-24.png\" alt=\"\" class=\"wp-image-2914\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-24.png 655w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-24-300x156.png 300w\" sizes=\"auto, (max-width: 655px) 100vw, 655px\" \/><\/figure>\n\n\n\n<p>Comme on peut le voir, la configuration IP de l&rsquo;interface WAN a \u00e9t\u00e9 attribu\u00e9e par le serveur DHCP de mon r\u00e9seau. Nous allons configurer l&rsquo;interface LAN avec sa configuration IP ad\u00e9quate.<\/p>\n\n\n\n<p><strong>Pour modifier la configuration IP de notre interface LAN, nous allons proc\u00e9der comme suit :<\/strong><\/p>\n\n\n\n<p>Choisissez l&rsquo;option 2.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"647\" height=\"272\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-25.png\" alt=\"\" class=\"wp-image-2915\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-25.png 647w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-25-300x126.png 300w\" sizes=\"auto, (max-width: 647px) 100vw, 647px\" \/><\/figure>\n\n\n\n<p>Ensuite, nous allons s\u00e9lectionner l&rsquo;interface LAN en entrant l&rsquo;option&nbsp;<strong>2<\/strong>&nbsp;et indiquer que&nbsp;<strong>nous n&rsquo;allons pas configurer l&rsquo;interface via DHCP<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"539\" height=\"143\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-26-1.png\" alt=\"\" class=\"wp-image-2916\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-26-1.png 539w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-26-1-300x80.png 300w\" sizes=\"auto, (max-width: 539px) 100vw, 539px\" \/><\/figure>\n\n\n\n<p>Enfin, nous allons d\u00e9finir la configuration IP de notre interface manuellement :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Adresse IP de l&rsquo;interface LAN&nbsp;<\/strong>: 192.168.100.1<\/li>\n\n\n\n<li><strong>Masque de sous-r\u00e9seau (en notation CIDR)&nbsp;<\/strong>: 24 = 255.255.255.0<\/li>\n\n\n\n<li><strong>Pas de passerelle<\/strong><\/li>\n\n\n\n<li><strong>Pas de configuration IPv6<\/strong><\/li>\n\n\n\n<li><strong>Pas de serveur DHCP IPv4&nbsp;<\/strong>&#8211; il pourra \u00eatre configur\u00e9 par la suite depuis l&rsquo;interface Web<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"660\" height=\"353\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-27.png\" alt=\"\" class=\"wp-image-2917\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-27.png 660w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-27-300x160.png 300w\" sizes=\"auto, (max-width: 660px) 100vw, 660px\" \/><\/figure>\n\n\n\n<p>Une fois termin\u00e9, l&rsquo;URL pour acc\u00e9der \u00e0 l&rsquo;interface Web d&rsquo;administration de pfSense s&rsquo;affiche et faire \u00ab\u00a0<strong>Entr\u00e9e<\/strong>\u00a0\u00bb pour terminer.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. Premi\u00e8re connexion \u00e0 l&rsquo;interface d&rsquo;administration de pfSense : <\/h3>\n\n\n\n<p>Depuis le poste client (c&rsquo;est-\u00e0-dire depuis notre r\u00e9seau LAN virtuel), nous allons nous connecter \u00e0 l&rsquo;interface Web d&rsquo;administration de pfSense \u00e0 l&rsquo;adresse IP \u00ab\u00a0<strong>https:\/\/192.168.100.1\/<\/strong>\u00ab\u00a0.<\/p>\n\n\n\n<p>Au pr\u00e9alable, il est n\u00e9cessaire de configurer l&rsquo;interface r\u00e9seau de la machine virtuelle cliente comme suit :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Adresse IPv4&nbsp;<\/strong>: 192.168.100.2<\/li>\n\n\n\n<li><strong>Masque<\/strong>&nbsp;: 255.255.255.0 ou \/24<\/li>\n\n\n\n<li><strong>Passerelle<\/strong>&nbsp;: 192.168.100.1<\/li>\n\n\n\n<li><strong>Serveur DNS<\/strong>&nbsp;: 1.1.1.1 ou celui de votre choix<\/li>\n<\/ul>\n\n\n\n<p><em>Le certificat de s\u00e9curit\u00e9 SSL utilis\u00e9 pour la connexion HTTPS est auto-sign\u00e9, il est donc normal d&rsquo;avoir un avertissement de s\u00e9curit\u00e9. Il est possible, selon vos besoins de d\u00e9finir un certificat provenant d&rsquo;une autorit\u00e9 de certification d&rsquo;entreprise ou publique.<\/em><\/p>\n\n\n\n<p>Pour vous connecter \u00e0 l&rsquo;interface Web d&rsquo;administration, il est n\u00e9cessaire de saisir l&rsquo;identifiant et le mot de passe pr\u00e9d\u00e9fini \u00e0 l&rsquo;installation. Voici les identifiants par d\u00e9faut :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Identifiant<\/strong>&nbsp;: admin<\/li>\n\n\n\n<li><strong>Mot de passe&nbsp;<\/strong>: pfsense (\u00e0 modifier par la suite)<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">L&rsquo;assistant de configuration Web :<\/h3>\n\n\n\n<p>Une fois connect\u00e9, l&rsquo;assistant de configuration Web s&rsquo;ouvrira. Cliquez sur \u00ab\u00a0<strong>Next<\/strong>\u00ab\u00a0.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"426\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-29-1-800x426-1.png\" alt=\"\" class=\"wp-image-2920\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-29-1-800x426-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-29-1-800x426-1-300x160.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-29-1-800x426-1-768x409.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Cliquez \u00e0 nouveau sur \u00ab\u00a0<strong>Next<\/strong>\u00a0\u00bb pour valider les modalit\u00e9s de support fourni par l&rsquo;\u00e9diteur.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"392\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-30-800x392-1.png\" alt=\"\" class=\"wp-image-2921\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-30-800x392-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-30-800x392-1-300x147.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-30-800x392-1-768x376.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Ici, nous allons pr\u00e9ciser les serveurs DNS de notre firewall pfSense, \u00e0 savoir \u00ab\u00a0<strong>1.1.1.1<\/strong>\u00a0\u00bb et \u00ab\u00a0<strong>8.8.8.8<\/strong>\u00ab\u00a0, et cliquer sur \u00ab\u00a0<strong>Next<\/strong>\u00ab\u00a0. Adaptez ces valeurs si vous le souhaitez.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"660\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-31-800x660-1.png\" alt=\"\" class=\"wp-image-2922\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-31-800x660-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-31-800x660-1-300x248.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-31-800x660-1-768x634.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">A cette \u00e9tape, nous allons configurer le serveur de temps qui est<strong>&nbsp;important pour b\u00e9n\u00e9ficier de logs \u00e0 jour<\/strong>. S\u00e9lectionnez le fuseau horaire correspondant \u00e0 votre emplacement puis cliquez sur \u00ab\u00a0<strong>Next<\/strong>\u00ab\u00a0.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"298\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-32-800x298-1.png\" alt=\"\" class=\"wp-image-2924\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-32-800x298-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-32-800x298-1-300x112.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-32-800x298-1-768x286.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">A l&rsquo;\u00e9tape 4, conservez les param\u00e8tres pr\u00e9d\u00e9finis par pfSense pour la configuration de l&rsquo;interface WAN en veillant \u00e0 d\u00e9cocher les 2 options suivantes : \u00ab\u00a0<strong>Block private networks form entering via WAN<\/strong>\u00a0\u00bb et \u00ab\u00a0<strong>Block non-internet routed networks from entering via WAN<\/strong>\u00ab\u00a0. Ces deux param\u00e8tres, lorsque pfSense est install\u00e9 dans un r\u00e9seau local existant (lab virtuel), permet de ne pas bloquer le trafic reposant sur des adresses IP priv\u00e9e. Ici, entre notre box internet et pfSense.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"290\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-33-800x290-1.png\" alt=\"\" class=\"wp-image-2926\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-33-800x290-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-33-800x290-1-300x109.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-33-800x290-1-768x278.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">A l&rsquo;\u00e9tape 5 de l&rsquo;assistant, conservez la configuration de l&rsquo;interface LAN que nous avons fait en amont.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"296\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-34-800x296-1.png\" alt=\"\" class=\"wp-image-2927\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-34-800x296-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-34-800x296-1-300x111.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-34-800x296-1-768x284.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\"><span style=\"color: rgb(68, 68, 68); font-family: &quot;PT Sans&quot;; font-size: 16px; text-align: justify; white-space-collapse: collapse;\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-white-color\">A l&rsquo;\u00e9tape 6 de l&rsquo;assistant, d\u00e9finissez un nouveau mot de passe et cliquer sur \u00ab\u00a0<\/mark><\/span><span style=\"box-sizing: border-box; font-weight: 700; border: 0px; font-variant-numeric: inherit; font-variant-east-asian: inherit; font-variant-alternates: inherit; font-variant-position: inherit; font-stretch: inherit; line-height: inherit; font-family: &quot;PT Sans&quot;; font-optical-sizing: inherit; font-kerning: inherit; font-feature-settings: inherit; font-variation-settings: inherit; font-size: 16px; margin: 0px; outline: 0px; padding: 0px; vertical-align: baseline; color: rgb(68, 68, 68); text-align: justify; white-space-collapse: collapse;\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-white-color\">Next<\/mark><\/span><span style=\"color: rgb(68, 68, 68); font-family: &quot;PT Sans&quot;; font-size: 16px; text-align: justify; white-space-collapse: collapse;\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-white-color\">\u00ab\u00a0.<\/mark><\/span><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"296\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-35-800x296-1.png\" alt=\"\" class=\"wp-image-2929\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-35-800x296-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-35-800x296-1-300x111.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-35-800x296-1-768x284.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">A l&rsquo;\u00e9tape 7, cliquez sur \u00ab\u00a0<strong>Reload<\/strong>\u00a0\u00bb afin de recharger la configuration de pfSense avec les informations que nous venons de d\u00e9finir.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"201\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-36-800x201-1.png\" alt=\"\" class=\"wp-image-2930\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-36-800x201-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-36-800x201-1-300x75.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-36-800x201-1-768x193.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">Apr\u00e8s quelques secondes, nous arrivons \u00e0 la fin de l&rsquo;assistant de configuration. Nous pouvons cliquer sur \u00ab\u00a0<strong>Finish<\/strong>\u00a0\u00bb pour acc\u00e9der au tableau de bord.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"595\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-37-800x595-1.png\" alt=\"\" class=\"wp-image-2931\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-37-800x595-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-37-800x595-1-300x223.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-37-800x595-1-768x571.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">6. PfSense : ajouter une interface DMZ :<\/h3>\n\n\n\n<p class=\"has-text-align-center\">Pour ajouter l&rsquo;interface DMZ \u00e0 PfSense, acc\u00e9dez au menu \u00ab\u00a0<strong>Interfaces<\/strong>\u00a0\u00bb puis \u00ab\u00a0<strong>Assignments<\/strong>\u00ab\u00a0.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"432\" height=\"167\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-38.png\" alt=\"\" class=\"wp-image-2936\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-38.png 432w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-38-300x116.png 300w\" sizes=\"auto, (max-width: 432px) 100vw, 432px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">On constate que l&rsquo;interface \u00ab\u00a0<strong>em2<\/strong>\u00a0\u00bb peut \u00eatre ajout\u00e9e : cliquez sur \u00ab\u00a0<strong>Add<\/strong>\u00a0\u00bb puis \u00ab\u00a0<strong>Save<\/strong>\u00ab\u00a0.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"200\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-39-800x200-1.png\" alt=\"\" class=\"wp-image-2937\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-39-800x200-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-39-800x200-1-300x75.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-39-800x200-1-768x192.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">En cliquant sur le nom de l&rsquo;interface sur la page pr\u00e9c\u00e9dente, nous pouvons acc\u00e9der \u00e0 sa configuration. Ici, nous allons<strong>&nbsp;activer l&rsquo;interface<\/strong>&nbsp;et la&nbsp;<strong>nommer DMZ au lieu de OPT1<\/strong>&nbsp;afin de l&rsquo;identifier facilement. Nous allons \u00e9galement d\u00e9finir la configuration IPv4 statique.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"218\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-40-800x218-1.png\" alt=\"\" class=\"wp-image-2938\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-40-800x218-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-40-800x218-1-300x82.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-40-800x218-1-768x209.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"156\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-41-800x156-1.png\" alt=\"\" class=\"wp-image-2939\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-41-800x156-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-41-800x156-1-300x59.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-41-800x156-1-768x150.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\"><span style=\"color: rgb(68, 68, 68); font-family: &quot;PT Sans&quot;; font-size: 16px; text-align: justify; white-space-collapse: collapse;\">Pour terminer, cliquer sur \u00ab\u00a0<\/span><span style=\"box-sizing: border-box; font-weight: 700; border: 0px; font-variant-numeric: inherit; font-variant-east-asian: inherit; font-variant-alternates: inherit; font-variant-position: inherit; font-stretch: inherit; line-height: inherit; font-family: &quot;PT Sans&quot;; font-optical-sizing: inherit; font-kerning: inherit; font-feature-settings: inherit; font-variation-settings: inherit; font-size: 16px; margin: 0px; outline: 0px; padding: 0px; vertical-align: baseline; color: rgb(68, 68, 68); text-align: justify; white-space-collapse: collapse;\">Save<\/span><span style=\"color: rgb(68, 68, 68); font-family: &quot;PT Sans&quot;; font-size: 16px; text-align: justify; white-space-collapse: collapse;\">\u00a0\u00bb et \u00ab\u00a0<\/span><span style=\"box-sizing: border-box; font-weight: 700; border: 0px; font-variant-numeric: inherit; font-variant-east-asian: inherit; font-variant-alternates: inherit; font-variant-position: inherit; font-stretch: inherit; line-height: inherit; font-family: &quot;PT Sans&quot;; font-optical-sizing: inherit; font-kerning: inherit; font-feature-settings: inherit; font-variation-settings: inherit; font-size: 16px; margin: 0px; outline: 0px; padding: 0px; vertical-align: baseline; color: rgb(68, 68, 68); text-align: justify; white-space-collapse: collapse;\">Apply Changes<\/span><span style=\"color: rgb(68, 68, 68); font-family: &quot;PT Sans&quot;; font-size: 16px; text-align: justify; white-space-collapse: collapse;\">\u00ab\u00a0.<\/span><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"122\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-42-800x122-1.png\" alt=\"\" class=\"wp-image-2940\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-42-800x122-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-42-800x122-1-300x46.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-42-800x122-1-768x117.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\">D\u00e9sormais, PfSense est initialis\u00e9 et les trois interfaces r\u00e9seau sont pr\u00eates. A partir des r\u00e9seaux \u00ab\u00a0LAN\u00a0\u00bb et \u00ab\u00a0DMZ\u00a0\u00bb nous pouvons acc\u00e9der \u00e0 Internet gr\u00e2ce aux r\u00e8gles de NAT dynamiques cr\u00e9\u00e9es par d\u00e9faut par PfSense.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">7. Installer un serveur Web :<\/h3>\n\n\n\n<p>Comme indiqu\u00e9 en introduction de cet article, nous allons<strong>&nbsp;installer un serveur Web dans la zone DMZ<\/strong>.<\/p>\n\n\n\n<p>La suite de cet article est \u00e0 adapter \u00e0 votre besoin. En effet, vous pouvez aussi utiliser une distribution Linux sur laquelle vous installez Apache pour publier votre site internet.<\/p>\n\n\n\n<p>Dans le cadre de notre lab virtuel, la configuration IP du serveur Web (pouvant \u00eatre adapt\u00e9e) est la suivante :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Adresse IPv4<\/strong>&nbsp;: 192.168.200.2<\/li>\n\n\n\n<li><strong>Masque<\/strong>&nbsp;: 255.255.255.0 ou \/24<\/li>\n\n\n\n<li><strong>Passerelle<\/strong>&nbsp;: 192.168.200.1<\/li>\n\n\n\n<li><strong>Serveur DNS<\/strong>&nbsp;: 1.1.1.1 ou celui de votre choix<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">8. Les r\u00e8gles de pare-feu avec pfSense : <\/h3>\n\n\n\n<p>Une fois votre serveur Web pr\u00eat \u00e0 \u00eatre utilis\u00e9, nous allons d\u00e9finir les r\u00e8gles de pare-feu permettant d&rsquo;acc\u00e9der \u00e0 serveur Web sur pfSense. L&rsquo;objectif \u00e9tant de limiter les flux au strict n\u00e9cessaire, notamment pour que depuis le LAN, nous puissions acc\u00e9der \u00e0 la DMZ uniquement pour contacter le serveur Web en HTTP.<\/p>\n\n\n\n<p>Nous allons cr\u00e9er les r\u00e8gles de flux suivantes :<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>Interface<\/strong><\/td><td><strong>Action<\/strong><\/td><td><strong>Source<\/strong><\/td><td><strong>Destination<\/strong><\/td><td><strong>Protocole(s) &amp; Port(s)<\/strong><\/td><\/tr><tr><td>LAN<\/td><td>Bloquer<\/td><td>LAN net<\/td><td>DMZ net<\/td><td>Tous<\/td><\/tr><tr><td>LAN<\/td><td>Autoriser<\/td><td>LAN net<\/td><td>Serveur Web (192.168.200.2)<\/td><td>TCP &#8211; IPv4 &#8211; 80 (HTTP)<\/td><\/tr><tr><td>DMZ<\/td><td>Bloquer<\/td><td>DMZ net<\/td><td>LAN net<\/td><td>Tous<\/td><\/tr><tr><td>DMZ<\/td><td>Autoriser<\/td><td>DMZ net<\/td><td>Tous<\/td><td>TCP &#8211; IPv4 &#8211; 80 (HTTP)<\/td><\/tr><tr><td>DMZ<\/td><td>Autoriser<\/td><td>DMZ net<\/td><td>Tous<\/td><td>TCP &#8211; IPv4 &#8211; 443 (HTTPS)<\/td><\/tr><tr><td>DMZ<\/td><td>Autoriser<\/td><td>DMZ net<\/td><td>Tous<\/td><td>TCP\/UDP &#8211; IPv4 &#8211; 53 (DNS)<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"has-text-align-center\">La cr\u00e9ation d&rsquo;une nouvelle r\u00e8gle se fait depuis l&rsquo;interface Web d&rsquo;administration pfSense, dans le menu suivant :&nbsp;<strong>Firewall &gt; Rules<\/strong>.<\/p>\n\n\n\n<p class=\"has-text-align-center\">Ensuite, s\u00e9lectionnez l&rsquo;interface sur laquelle cr\u00e9er la r\u00e8gle puis cliquez sur \u00ab\u00a0<strong>Add<\/strong>\u00ab\u00a0.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-gallery aligncenter has-nested-images columns-default is-cropped wp-block-gallery-4 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"531\" height=\"247\" data-id=\"2944\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-44.png\" alt=\"\" class=\"wp-image-2944\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-44.png 531w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-44-300x140.png 300w\" sizes=\"auto, (max-width: 531px) 100vw, 531px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"266\" data-id=\"2945\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-45-800x266-1.png\" alt=\"\" class=\"wp-image-2945\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-45-800x266-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-45-800x266-1-300x100.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-45-800x266-1-768x255.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n<\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>9.A LAN &#8211; Bloquer les flux vers la DMZ<\/strong> :<\/h3>\n\n\n\n<p>D&rsquo;abord, s\u00e9lectionnez l&rsquo;interface&nbsp;<strong>LAN&nbsp;<\/strong>puis cliquez sur \u00ab\u00a0<strong>Add<\/strong>\u00ab\u00a0, puis renseignez les param\u00e8tres de r\u00e8gle suivants :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Action&nbsp;<\/strong>: Block<\/li>\n\n\n\n<li><strong>Interface<\/strong>&nbsp;: LAN<\/li>\n\n\n\n<li><strong>Address Family<\/strong>&nbsp;: IPv4+IPv6<\/li>\n\n\n\n<li><strong>Protocol&nbsp;<\/strong>: Any<\/li>\n\n\n\n<li><strong>Source&nbsp;<\/strong>: LAN net<\/li>\n\n\n\n<li><strong>Destination<\/strong>&nbsp;: DMZ net<\/li>\n\n\n\n<li><strong>Description&nbsp;<\/strong>: Bloquer les flux LAN vers la DMZ<\/li>\n<\/ul>\n\n\n\n<p>Ce qui donne :<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"668\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-46-800x668-1.png\" alt=\"\" class=\"wp-image-2949\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-46-800x668-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-46-800x668-1-300x251.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-46-800x668-1-768x641.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">9.B LAN &#8211; Autoriser l&rsquo;acc\u00e8s au serveur Web sur la DMZ :<\/h3>\n\n\n\n<p>S\u00e9lectionnez l&rsquo;interface&nbsp;<strong>LAN&nbsp;<\/strong>puis cliquez sur \u00ab\u00a0<strong>Add<\/strong>\u00ab\u00a0, puis renseignez les param\u00e8tres de r\u00e8gle suivants :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Action&nbsp;<\/strong>: Pass<\/li>\n\n\n\n<li><strong>Interface&nbsp;<\/strong>: LAN<\/li>\n\n\n\n<li><strong>Address Family<\/strong>&nbsp;: IPv4<\/li>\n\n\n\n<li><strong>Protocol&nbsp;<\/strong>: TCP<\/li>\n\n\n\n<li><strong>Source&nbsp;<\/strong>: LAN net<\/li>\n\n\n\n<li><strong>Destination&nbsp;<\/strong>: Single host or alias &#8211; 192.168.200.2<\/li>\n\n\n\n<li><strong>Description&nbsp;<\/strong>: Acc\u00e8s serveur Web en DMZ depuis le LAN<\/li>\n<\/ul>\n\n\n\n<p>Ce qui donne :<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"658\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-47-800x658-1.png\" alt=\"\" class=\"wp-image-2950\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-47-800x658-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-47-800x658-1-300x247.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-47-800x658-1-768x632.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">9.C DMZ &#8211; Bloquer les flux vers le LAN :<\/h3>\n\n\n\n<p>Cette fois-ci, s\u00e9lectionnez l&rsquo;interface&nbsp;<strong>DMZ&nbsp;<\/strong>puis cliquez sur \u00ab\u00a0<strong>Add<\/strong>\u00ab\u00a0, puis renseignez les param\u00e8tres de r\u00e8gle suivants :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Action&nbsp;<\/strong>: Block<\/li>\n\n\n\n<li><strong>Interface&nbsp;<\/strong>: DMZ<\/li>\n\n\n\n<li><strong>Address Family<\/strong>&nbsp;: IPv4+IPv6<\/li>\n\n\n\n<li><strong>Protocol&nbsp;<\/strong>: any<\/li>\n\n\n\n<li><strong>Source&nbsp;<\/strong>: DMZ net<\/li>\n\n\n\n<li><strong>Destination&nbsp;<\/strong>: LAN net<\/li>\n\n\n\n<li><strong>Description&nbsp;<\/strong>: Bloquer les flux de la DMZ vers le LAN<\/li>\n<\/ul>\n\n\n\n<p>Ce qui donne :<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"672\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-48-800x672-1.png\" alt=\"\" class=\"wp-image-2953\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-48-800x672-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-48-800x672-1-300x252.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-48-800x672-1-768x645.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">9.D DMZ &#8211; Autoriser l&rsquo;acc\u00e8s \u00e0 internet (HTTP) :<\/h3>\n\n\n\n<p>S\u00e9lectionnez l&rsquo;interface&nbsp;<strong>DMZ&nbsp;<\/strong>puis cliquez sur&nbsp;<strong>Add<\/strong>, puis renseignez les param\u00e8tres de r\u00e8gle suivants :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Action&nbsp;<\/strong>: Pass<\/li>\n\n\n\n<li><strong>Interface&nbsp;<\/strong>: DMZ<\/li>\n\n\n\n<li><strong>Address Family<\/strong>&nbsp;: IPv4<\/li>\n\n\n\n<li><strong>Protocol&nbsp;<\/strong>: TCP<\/li>\n\n\n\n<li><strong>Source&nbsp;<\/strong>: DMZ net<\/li>\n\n\n\n<li><strong>Destination&nbsp;<\/strong>: any &#8211; HTTP (80)<\/li>\n\n\n\n<li><strong>Description&nbsp;<\/strong>: Autoriser l&rsquo;acc\u00e8s \u00e0 internet depuis la DMZ<\/li>\n<\/ul>\n\n\n\n<p>Ce qui donne :<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"658\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-49-800x658-1.png\" alt=\"\" class=\"wp-image-2954\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-49-800x658-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-49-800x658-1-300x247.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-49-800x658-1-768x632.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">9.E DMZ &#8211; Autoriser l&rsquo;acc\u00e8s \u00e0 internet (HTTPS) :<\/h3>\n\n\n\n<p>S\u00e9lectionnez l&rsquo;interface&nbsp;<strong>DMZ&nbsp;<\/strong>puis cliquez sur&nbsp;<strong>Add<\/strong>, puis renseignez les param\u00e8tres de r\u00e8gle suivants :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Action&nbsp;<\/strong>: Pass<\/li>\n\n\n\n<li><strong>Interface&nbsp;<\/strong>: DMZ<\/li>\n\n\n\n<li><strong>Address Family<\/strong>&nbsp;: IPv4<\/li>\n\n\n\n<li><strong>Protocol&nbsp;<\/strong>: TCP<\/li>\n\n\n\n<li><strong>Source&nbsp;<\/strong>: DMZ net<\/li>\n\n\n\n<li><strong>Destination&nbsp;<\/strong>: any &#8211; HTTPS (443)<\/li>\n\n\n\n<li><strong>Description&nbsp;<\/strong>: Autoriser l&rsquo;acc\u00e8s \u00e0 internet depuis la DMZ (HTTPS)<\/li>\n<\/ul>\n\n\n\n<p>Ce qui donne :<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"659\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-50-800x659-1.png\" alt=\"\" class=\"wp-image-2955\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-50-800x659-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-50-800x659-1-300x247.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-50-800x659-1-768x633.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">9.F DMZ &#8211; Autoriser la r\u00e9solution DNS :<\/h3>\n\n\n\n<p>Pour que notre serveur web puisse acc\u00e9der \u00e0 Internet, il doit pouvoir effectuer de la r\u00e9solution de noms vers Internet (si l&rsquo;on utilise un r\u00e9solveur DNS externe). S\u00e9lectionnez l&rsquo;interface&nbsp;<strong>DMZ&nbsp;<\/strong>puis cliquez sur \u00ab\u00a0<strong>Add<\/strong>\u00ab\u00a0, puis renseignez les param\u00e8tres de r\u00e8gle suivants :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Action&nbsp;<\/strong>: Pass<\/li>\n\n\n\n<li><strong>Interface&nbsp;<\/strong>: DMZ<\/li>\n\n\n\n<li><strong>Address Family<\/strong>&nbsp;: IPv4<\/li>\n\n\n\n<li><strong>Protocol&nbsp;<\/strong>: TCP\/UDP<\/li>\n\n\n\n<li><strong>Source&nbsp;<\/strong>: DMZ net<\/li>\n\n\n\n<li><strong>Destination&nbsp;<\/strong>: any &#8211; DNS (53)<\/li>\n\n\n\n<li><strong>Description&nbsp;<\/strong>: Autoriser la r\u00e9solution DNS depuis la DMZ<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"660\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-51-800x660-1.png\" alt=\"\" class=\"wp-image-2956\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-51-800x660-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-51-800x660-1-300x248.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-51-800x660-1-768x634.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">10. La r\u00e8gle de NAT pour le serveur Web :<\/h3>\n\n\n\n<p>Dans cette derni\u00e8re partie, nous allons mettre en place<strong>&nbsp;une r\u00e8gle de NAT<\/strong>&nbsp;pour permettre l&rsquo;acc\u00e8s au serveur Web h\u00e9berg\u00e9 sur notre DMZ depuis l&rsquo;ext\u00e9rieur du r\u00e9seau local de notre lab virtuel, au travers de l&rsquo;interface WAN. Cette r\u00e8gle doit \u00eatre adapt\u00e9e en fonction de l&rsquo;adresse IP du serveur web et du port utilis\u00e9 (HTTP \/ HTTPS \/ ou num\u00e9ro de port exotique).<\/p>\n\n\n\n<p>Si vous avez besoin d&rsquo;approfondir la notion de NAT, lisez cet article :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.it-connect.fr\/le-nat-et-le-pat-pour-les-debutants\/\" target=\"_blank\" rel=\"noreferrer noopener\">Le NAT pour les d\u00e9butants<\/a><\/li>\n<\/ul>\n\n\n\n<p>Pour ce faire, naviguez dans le menu \u00ab\u00a0<strong>Firewall &gt; NAT<\/strong>\u00a0\u00bb puis cliquez sur \u00ab\u00a0<strong>Add<\/strong>\u00ab\u00a0.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"273\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-52-800x273-1.png\" alt=\"\" class=\"wp-image-2957\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-52-800x273-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-52-800x273-1-300x102.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-52-800x273-1-768x262.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p>Voici la configuration de notre r\u00e8gle de NAT :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Type de r\u00e8gle<\/strong>&nbsp;: Port Forward<\/li>\n\n\n\n<li><strong>Interface&nbsp;<\/strong>: WAN<\/li>\n\n\n\n<li><strong>Adress Family<\/strong>&nbsp;: IPv4<\/li>\n\n\n\n<li><strong>Protocol&nbsp;<\/strong>: TCP<\/li>\n\n\n\n<li><strong>Destination&nbsp;<\/strong>: WAN address<\/li>\n\n\n\n<li><strong>Destination port range<\/strong>&nbsp;: HTTP (80)<\/li>\n\n\n\n<li><strong>Redirect target IP<\/strong>&nbsp;: Adress or Alias &#8211; 192.168.200.2<\/li>\n\n\n\n<li><strong>Redirect target port<\/strong>&nbsp;: HTTP<\/li>\n<\/ul>\n\n\n\n<p>Ce qui donne :<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"654\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-53-800x654-1.png\" alt=\"\" class=\"wp-image-2958\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-53-800x654-1.png 800w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-53-800x654-1-300x245.png 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/pfSense_VMWare_Workstation-53-800x654-1-768x628.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/figure>\n\n\n\n<p>Suite \u00e0 la mise en place de cette r\u00e8gle de NAT,&nbsp;<strong>une machine situ\u00e9e \u00e0 l&rsquo;ext\u00e9rieur du r\u00e9seau de notre Lab (c\u00f4t\u00e9 WAN, donc votre machine physique, par exemple) doit pouvoir acc\u00e9der au serveur Web<\/strong>&nbsp;! Dans le navigateur, il faut indiquer l&rsquo;<strong>adresse IP de l&rsquo;interface WAN du Pfsense<\/strong>&nbsp;et gr\u00e2ce \u00e0 la r\u00e8gle de NAT, le flux sera redirig\u00e9 vers le serveur Web.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">11. Serveur DHCP et DNS Filtrant :<\/h3>\n\n\n\n<p>Mise en place d&rsquo;un filtrage de contenu au niveau du DNS via le serveur DHCP sur le r\u00e9seau LAN <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Dans le menu service s\u00e9lectionnez DHCP Server<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"566\" height=\"215\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/DHCP-DNS.jpg\" alt=\"\" class=\"wp-image-2962\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/DHCP-DNS.jpg 566w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/DHCP-DNS-300x114.jpg 300w\" sizes=\"auto, (max-width: 566px) 100vw, 566px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"795\" src=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/DHCP-DNS-2-1024x795.jpg\" alt=\"\" class=\"wp-image-2963\" srcset=\"https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/DHCP-DNS-2-1024x795.jpg 1024w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/DHCP-DNS-2-300x233.jpg 300w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/DHCP-DNS-2-768x597.jpg 768w, https:\/\/hinakuu.xyz\/wp-content\/uploads\/2024\/04\/DHCP-DNS-2.jpg 1071w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Dans ce tutoriel, nous allons apprendre \u00e0 installer Pfsense au sein d&rsquo;une VM VMWare Workstation dans le but<\/p>\n","protected":false},"author":1,"featured_media":2865,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,5,1],"tags":[],"class_list":["post-2858","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux","category-reseau","category-non-classe"],"_links":{"self":[{"href":"https:\/\/hinakuu.xyz\/index.php?rest_route=\/wp\/v2\/posts\/2858","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hinakuu.xyz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hinakuu.xyz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hinakuu.xyz\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hinakuu.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2858"}],"version-history":[{"count":34,"href":"https:\/\/hinakuu.xyz\/index.php?rest_route=\/wp\/v2\/posts\/2858\/revisions"}],"predecessor-version":[{"id":2964,"href":"https:\/\/hinakuu.xyz\/index.php?rest_route=\/wp\/v2\/posts\/2858\/revisions\/2964"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hinakuu.xyz\/index.php?rest_route=\/wp\/v2\/media\/2865"}],"wp:attachment":[{"href":"https:\/\/hinakuu.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2858"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hinakuu.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2858"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hinakuu.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2858"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}