pfSense: Firewall, Routing & Hybrid Network Gateway

At the center of the on-premises network is pfSense, running as a virtual machine on the VMware ESXi host. It provides the primary firewall and routing layer for the lab, connecting the internal VM network to the upstream network while controlling traffic between the different infrastructure components.

The firewall is also the IPsec endpoint for the DigitalOcean environment, allowing the private on-premises networks to communicate securely with the cloud infrastructure.

Firewall & Network Segmentation

The firewall rules are designed around explicit access requirements rather than allowing unrestricted traffic between networks.

For example, the LAN rules control traffic leaving the internal network toward the DigitalOcean VPN and IPsec networks, while the IPsec rules define which services remote VPN clients can access.

This provides an opportunity to work with practical firewall concepts including:

  • Stateful firewall rules
  • Network segmentation
  • Least-privilege access
  • Service-specific rules
  • IPsec traffic filtering
  • Inter-network routing
  • Firewall logging and troubleshooting

IPsec Gateway

pfSense maintains the site-to-site IPsec connection to the DigitalOcean server.

The configuration provides separate Phase 2 definitions for the different networks that need to communicate across the tunnel.

This allows the cloud and on-premises environments to remain logically separated while still providing controlled connectivity between them.

The same architecture supports access to multiple private networks, including the on-premises LAN and the VPN client networks hosted by the DigitalOcean server.

Routing & Infrastructure Integration

Because pfSense sits between the upstream network and the internal lab, it provides a useful point for controlling how different infrastructure components communicate.

The overall path is:

Internet / Upstream Network
          │
          ▼
      pfSense
     Firewall
          │
          ├── On-Premises LAN
          │       │
          │       ├── Windows Server
          │       ├── Linux VMs
          │       └── Applications
          │
          └── IPsec
                │
                ▼
        DigitalOcean Ubuntu
                │
        ┌───────┴────────┐
        │                │
     VPN Clients      Web Services

This makes pfSense an important integration point between the physical network, virtual machines, cloud infrastructure, and remote-access services.

Practical Skills

This environment provides hands-on experience with:

  • pfSense administration
  • Firewall policy design
  • Network segmentation
  • IPv4 routing
  • IPsec site-to-site VPNs
  • VPN client network integration
  • NAT and gateway configuration
  • Firewall logging and troubleshooting
  • Virtualized network appliances
  • Cloud-to-on-premises connectivity

The value of the pfSense deployment is less about running a firewall in isolation and more about using it as the network security and routing layer that ties the rest of the lab together.