[Network] OPNsense ์„ค์น˜ ๋ฐ ๊ตฌ์„ฑ

2023. 7. 7. 17:17ใ†System ์ž‘์—…์‹ค/Server ๊ด€๋ จ

728x90
๋ฐ˜์‘ํ˜•

 




 

 

 

๐Ÿš€ OPNsense ์„ค์น˜ ๋ฐ ๊ตฌ์„ฑ

    ๐Ÿ”ฝ ๊ฐœ์š”

        ๐Ÿ“ฆ ์†Œ๊ฐœ

๋ฌด๋ฃŒ๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” UTM(Unfied Threat Management)์€ ๊ต‰์žฅํžˆ ๋งŽ์•„์š”.

๊ทธ ์ค‘ PFsense, OPNsense, Untagle์ด ๋Œ€ํ‘œ์ ์œผ๋กœ ๊ฐ€์žฅ ์ธ๊ธฐ๊ฐ€ ๋งŽ์€ ์ œํ’ˆ์ด์—์š”.


PFsense๋Š” ๊ฐ€์žฅ ์œ ๋ช…ํ•˜๊ณ , ์ค€ ์ „๋ฌธ๊ฐ€๋“ค ์‚ฌ์ด์—์„œ๋„ PFsense + snort ์กฐํ•ฉ์œผ๋กœ ๋งŽ์ด ์“ฐ๊ณ  ์žˆ๋‹ค๊ณ  ํ•ด์š”.

๋Œ€ํ‘œ์ ์ด ๊ธฐ๋Šฅ์€ ์•„๋ž˜์™€ ๊ฐ™์•„์š”.


๊ธฐ๋Šฅ ์ด๋ฆ„ ๊ธฐ๋Šฅ ์ƒ์„ธ
Firewall SPI / GeoIP Blocking / Anti-Spoofing / Captive portal guest network / Time-based rules / Connection Limits / NAT mapping(inbound/outbound)
Router Policy-based routing / Concurrent IPv4 and IPv6 Support / Configurable static routing / IPv6-to-IPv6 Network Prefix Translation / IPv6 router advertisements / Multiple IP addresses per network interface / PPPoE Server
Attack Prevention IDS/IPS / Snort-based packet analyzer / Layer 7 application detection / Multiple rules / sources / and categories / Emerging threats database / IP blacklist database / Pre-set rule profiles / Per-interface configuration / False positive alert suppression / Deep Packet Inspection (DPI) / Application blocking
VPN IPsec / OpenVPN / Wireguard / Site-to-site and remote access VPN / SSL encryption / VPN client for multiple operating systems / L2TP/IPsec for mobile devices / IPv6 support / Split tunneling / Multiple tunnels / VPN tunnel failover / NAT support / Automatic or custom routing / Local user authentication or RADIUS/LDAP
Proxy and Content Filtering HTTP and HTTPS proxy / Non Transparent or Transparent caching proxy / Domain/URL filtering / Anti-virus filtering / SafeSearch for search engines / HTTPS URL and content screening / Website access reporting / Domain Name blacklisting (DNSBL) / Usage reporting
Network Services Dynamic DNS(DDNS) / DHCP Server / DNS forwarding
Configuration Management Web-based configuration / Setup wizard for initial configuration / Remote web-based administration / Customizable dashboard / Easy configuration backup/restore / Configuration export/import / Encrypted automatic backup to Netgate server / Variable level administrative rights / Multi-language support / Simple updates / Forward-compatible configuration / Serial console for shell access and recovery options / Wake-on-LAN
User Authentication Management Local user and group database / User and group-based privileges / Optional automatic account expiration / External RADIUS authentication / Automatic lockout after repeated attempts
System Security Management Web interface security protection / CSRF protection / HTTP Referer enforcement / DNS Rebinding protection / HTTP Strict Transport Security / Optional key-based SSH access
Resilience / Reliability Management Optional multi-node High Availability Clustering / Multi-WAN for load balancing and failover / Reverse Proxy / Automatic connection failover / Bandwidth throttling / Traffic Shaping Wizard / Reserve or restrict bandwidth based on traffic priority / Fair sharing bandwidth / User data transfer quotas
System Reporting and Monitoring Dashboard with configurable widgets / Local logging / Remote logging / Local monitoring graphs / Real-time interface traffic graphs / SNMP monitoring / Notifications via web interface, SMTP, or Growl / Hardware monitoring / Networking diagnostic tools

 

PFsense Fork Version์ด๊ณ , ๋ณด์•ˆ์— ๋” ํŠนํ™”๋œ HardenedBSD ๊ธฐ๋ฐ˜์ธ OPNsense๋ผ๋Š” ๊ฒƒ์„ ์ฃผ๋‹ˆ๋Š” ์‚ฌ์šฉํ•˜๊ธฐ๋กœ ํ•˜์˜€์–ด์š”.

PFSense์— ๋น„ํ•ด ๋”์šฑ ๊น”๊ธˆํ•œ ์ •๋ฆฌ๋œ UI๋ฅผ ๊ฐ€์ง€๊ณ  ์žˆ๊ณ , OPNsense User๋“ค์ด PFsense๋ณด๋‹ค ๋” ์ด ์ œํ’ˆ์„ ์„ ํ˜ธํ•˜๋Š” ์ด์œ ๋Š” ๋น ๋ฅธ Update๊ฐ€ ์žˆ์–ด์š”.


ASLR(Address Space Layout Randomizaion) ๋“ฑ FreeBSD์— ๋น„ํ•ด ๋ณด์•ˆ ์ด์ ์ด ์žˆ๋‹ค๋Š” ์˜๊ฒฌ, ๋” ์ž์œ ๋กญ๊ณ  ๋งŽ์€ ๊ธฐ๋Šฅ, ์‚ฌ์šฉ์ด ๋น„๊ต์  ๋” ์šฉ์ดํ•œ ์ ๊ณผ Zerotier, LibreSSL ์‚ฌ์šฉ ๊ฐ€๋Šฅ๊ณผ ๋ฆฌ์–ผํ… Driver ๋‚ด์žฅ, Web GUI๊ฐ€ ๋” ๋น ๋ฅด๊ณ  ์ž˜ ๋งŒ๋“ค์—ˆ๋‹ค๋Š” ๋“ฑ์˜ ์ด์œ ๊ฐ€ ์žˆ๊ณ , PFsense Plus ์ถœ์‹œ ์ดํ›„๋กœ PFsense CE(๋ฌด๋ฃŒ ๋ฒ„์ „)์— ๋Œ€ํ•œ ์ง€์›์ด ์ค„์–ด๋“ค ๊ฒƒ์ด๋ผ๋Š” ์˜ˆ์ธก ๋“ฑ์— ์ด์œ ๋กœ OPNSense๋ฅผ ์„ ํƒํ•˜๊ฒŒ ๋˜์—ˆ์–ด์š”.

PFsense์˜ ๊ฐ•๋ ฅํ•จ์— ํ›จ์”ฌ ๋‚˜์•„์ง„ GUI๋ฅผ ๊ฐ–์ถ˜ ์ œํ’ˆ์ด๋ฉฐ, 2FA ์ธ์ฆ๋„ ์ œ๊ณตํ•˜๋Š” ์žฅ์ ๋„ ์žˆ์–ด์š”.
์ฐจ์„ธ๋Œ€ ๋ฐฉํ™”๋ฒฝ์ธ Sensei๋ฅผ ๊ฐ„๋‹จํ•˜๊ฒŒ Plug In ๋ฐฉ์‹์œผ๋กœ ์ถ”๊ฐ€ํ•  ์ˆ˜ ์žˆ๊ณ , Python Open Source ๊ธฐ๋ฐ˜์œผ๋กœ ์•…์„ฑ์ฝ”๋“œ ํƒ์ง€ System์ธ Maltrail, Adguard Home ์—ญ์‹œ ์‰ฝ๊ฒŒ ์ถ”๊ฐ€ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์™€์ด์–ด๊ฐ€๋“œ VPN, Zerotire, Geo IP, suricata ๋“ฑ ๊ฐ€์ •์šฉ, ๊ฐœ์ธ์šฉ์œผ๋กœ๋Š” ์ฐจ๊ณ  ๋„˜์น˜๋Š” ํˆด์„ ๋ฌด๋ฃŒ๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ์— ์ด๊ฑธ ์‚ฌ์šฉํ•˜๊ธฐ๋กœ ํ•˜์˜€์–ด์š”.

 

Hardware ์‚ฌ์–‘

1. ์ตœ์†Œ ์‚ฌ์–‘

OPNsense ํ‘œ์ค€ ๊ธฐ๋Šฅ์„ ์‹คํ–‰ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ์•„๋ž˜์™€ ๊ฐ™์ด ์ตœ์†Œ ์‚ฌ์–‘์„ ๋งž์ถฐ์ค˜์•ผ ํ•ด์š”.

Hardware ์ข…๋ฅ˜ ๋‚ด         ์šฉ
CPU 1 GHz Dual Core CPU
RAM 2 GB
Install Method Serial console or video (VGA)
Install target ์ตœ์†Œ 4GB์˜ SD Card ๋˜๋Š” CF Card๋ฅผ ํ†ตํ•ด
Nono Imate๋ฅผ ์ด์šฉํ•˜์—ฌ ์„ค์น˜ ๊ฐ€๋Šฅ




2. ๊ถŒ์žฅ ์‚ฌ์–‘

Hardware ์ข…๋ฅ˜ ๋‚ด         ์šฉ
CPU 1 GHz Dual Core CPU
RAM 4 GB
Install Method Serial console or video (VGA)
Install target 120GB SSD,
์„ค์น˜ ํ”„๋กœ๊ทธ๋žจ์„ ์‹คํ–‰ํ•˜๋ ค๋ฉด ์ตœ์†Œ 2GB RAM ํ•„์š”.

 

 

 

    ๐Ÿ”ฝ OPNsense

        ๐Ÿ“ฆ ๋‚ด๋ ค๋ฐ›๊ธฐ

OPNsense๋Š” ์ด ๊ณณ์—์„œ ๋‚ด๋ ค ๋ฐ›๊ธฐ ํ•  ์ˆ˜ ์žˆ์–ด์š”.

Architecture๋Š” amd64 ํ•˜๋‚˜ ๋ฐ–์— ์—†์Šต๋‹ˆ๋‹ค. ๊ทธ ์•„๋ž˜ Image Type์€ 4๊ฐœ์—์š”.

Image Type ๋‚ด     ์šฉ
DVD VGA Mode์—์„œ ์‹คํ–‰๋˜๋Š” Live System ๊ธฐ๋Šฅ์ด ์žˆ๋Š” ISO ์„ค์น˜ ํ”„๋กœ๊ทธ๋žจ ์ด๋ฏธ์ง€. amd64์—์„œ๋Š” UEFI Booting ์ง€์›.
VGA GPT Booting์œผ๋กœ VGA Mode์—์„œ ์‹คํ–‰๋˜๋Š” Live System ๊ธฐ๋Šฅ์ด ์žˆ๋Š” USB ์„ค์น˜ ํ”„๋กœ๊ทธ๋žจ ์ด๋ฏธ์ง€.
amd64์—์„œ๋Š” UEFI Booting ์—ญ์‹œ ์ง€์›.
Serial MBR Booting์œผ๋กœ ์ง๋ ฌ Console(115200) Mode์—์„œ ์‹คํ–‰๋˜๋Š” Live System ๊ธฐ๋Šฅ์ด ์žˆ๋Š” USB ์„ค์น˜ ํ”„๋กœ๊ทธ๋žจ ์ด๋ฏธ์ง€.
Nano MBR Booting์œผ๋กœ USB Stick. SD, CF Card์šฉ ์‚ฌ์ „ ์„ค์น˜๋œ ์ง๋ ฌ Image.
์ด ์ด๋ฏธ์ง€๋Š” ํฌ๊ธฐ๊ฐ€ 3G์ด๋ฉฐ, ์ฒ˜์Œ Bootingํ•œ ๋’ค ์„ค์น˜๋œ Media ํฌ๊ธฐ์— ์ž๋™ ์ ์‘.


์ฃผ๋‹ˆ๋Š” Hyper-V์— ์„ค์น˜ํ•  ๊ฒƒ์ด๊ธฐ ๋•Œ๋ฌธ์— DVD๋ฅผ ๋ฐ›๋„๋ก ํ•  ๊ฑฐ์—์š”.

 

 

 

    ๐Ÿ”ฝ Hyper-V

        ๐Ÿ“ฆ ๊ฐ€์ƒ ๋จธ์‹  ์ค€๋น„

Hyper-V์— ISO๋ฅผ Importํ•˜๊ณ  ์„ค์น˜๋ฅผ ์ง„ํ–‰ํ•ด ๋ณผ๊ฒŒ์š”.


์ตœ์ดˆ Hyper-V ๊ด€๋ฆฌ์ž์—์„œ HOST์ด๋ฆ„์„ ์šฐํด๋ฆญํ•˜๊ณ  ์œ„์™€ ๊ฐ™์ด ๊ฐ€์ƒ ์ปดํ“จํ„ฐ๋ฅผ ์„ ํƒํ•ด ์ค„๊ฒŒ์š”.




๊ทธ๋Ÿฐ ๋’ค ๋งŒ๋“ค๊ฒŒ ๋  ๊ฐ€์ƒ ๋จธ์‹ ์˜ ์ด๋ฆ„์„ ์œ„์™€ ๊ฐ™์ด ์ง€์ •ํ•ด ์ฃผ์—ˆ์–ด์š”.
๊ทธ๋ฆฌ๊ณ , ํ•ด๋‹น ๊ฐ€์ƒ ๋จธ์‹ ์ด ์„ค์น˜๋  ์ €์žฅ์†Œ๋ฅผ ์„ ํƒํ•ด ์ฃผ์—ˆ์–ด์š”.



1์„ธ๋Œ€๋ฅผ ์„ ํƒํ•˜๊ณ  ๋„˜์–ด๊ฐˆ๊ฒŒ์š”.


 

Memory๋Š” 4GB๋ฅผ ์‚ฌ์šฉํ•˜๊ฒŒ ํ•˜๊ณ , ๋™์  Memory๋ฅผ ์‚ฌ์šฉํ•˜๊ฒŒ ํ•˜์—ฌ ํ•„์š” ์‹œ Memory๊ฐ€ ๋Š˜์–ด๋‚  ์ˆ˜ ์žˆ๋„๋ก ํ•ด ์ค„๊ฒŒ์š”.

 

 

 


์ด๋ฒˆ์—๋Š” ๋„คํŠธ์›Œํฌ ๊ตฌ์„ฑ ๋‹จ๊ณ„์—์š”.
์ค€๋น„๋œ vSwitch๋ฅผ ์„ ํƒํ•˜์—ฌ ์ธํ„ฐ๋„ท์ด ๋˜๋„๋ก ๊ตฌ์„ฑํ•ด ์ฃผ๋Š” ๋ถ€๋ถ„์ด์—์š”.




OS๊ฐ€ ์„ค์น˜๋  ๊ฐ€์ƒ HDD๋ฅผ ์–ด๋–ค Storage์— ์ €์žฅํ• ์ง€ ์„ ํƒํ•˜๋Š” ๊ณณ์ด์—์š”.
์ฃผ๋‹ˆ์“ฐ๋Š” ์œ„์™€ ๊ฐ™์ด 232GB๋ฅผ ์ฃผ๊ณ , SSD๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๊ฒŒ ์„ค์ •ํ•ด ์ฃผ์—ˆ์–ด์š”.



์ตœ์ดˆ OPNsense ISO File์„ ๋‚ด๋ ค ๋ฐ›์œผ๋ฉด BZ2๋กœ ์••์ถ•์ด ๋˜์–ด ์žˆ์–ด์š”.
๋ฐ˜๋””์ง‘์„ ํ†ตํ•ด ์œ„์™€ ๊ฐ™์ด ์••์ถ•์„ ํ•ด์ œ ํ•ด ์ค„๊ฒŒ์š”.




๊ทธ๋Ÿฐ ๋’ค ๊ฐ€์ƒ CD ROM์— ISO File์ด Mount ๋˜๋„๋ก ํ•ด ์ฃผ์—ˆ์–ด์š”.



์„ค์ •ํ•œ ๋‚ด์šฉ์ด ๋งž๋Š”์ง€ ํ™•์ธํ•˜๊ณ , ๋งž๋‹ค๋ฉด ๋งˆ์นจ์„ ๋ˆŒ๋Ÿฌ ์„ค์ •์„ ๋งˆ์น  ์ˆ˜ ์žˆ์–ด์š”.



์ถ”๊ฐ€์ ์œผ๋กœ Disk๋ฅผ ์ถ”๊ฐ€ํ•˜๊ณ , CPU, RAM ๋“ฑ์— ์„ค์ •์„ ์œ„ํ•ด ๋‹ค์‹œ ํ•œ๋ฒˆ ์„ค์ •์„ ๋“ค์–ด๊ฐˆ๊ฒŒ์š”.



๋จผ์ € RAM์„ ์œ„์™€ ๊ฐ™์ด ์„ค์ •ํ•ด ์ค„๊ฑด๋ฐ, ํ‰์†Œ์—๋Š” 4GB๋ฅผ ์‚ฌ์šฉํ•˜๋‹ค๊ฐ€ ํ•„์š”ํ•˜๋ฉด 8GB๊นŒ์ง€ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด ์ค„๊ฑฐ์—์š”.

๊ทธ๋ฆฌ๊ณ , Memory ๊ฐ€์ค‘์น˜๋ฅผ ์ตœ๋Œ€ํ•œ ๋†’์—ฌ์ฃผ์–ด์„œ ๋‹ค๋ฅธ Server๋ณด๋‹ค RAM ์‚ฌ์šฉ ์šฐ์„ ๊ถŒ์„ ๊ฐ–๊ฒŒ ํ•ด์ค„๊ฑฐ์—์š”.


์ง€๊ธˆ ์„ค์น˜ํ•˜๋Š” UTM OPNsense๋Š” ๋ฐฉํ™”๋ฒฝ ์—ญํ• ๋„ ํ•  ๊ฒƒ์ด๊ธฐ ๋•Œ๋ฌธ์— ํ•˜๋‚˜์˜ Network Adaptor๋งŒ ๊ฐ€์ง€๊ณ  ์žˆ์œผ๋ฉด ์•ˆ๋˜์š”.

Network Adaptor ์ฆ‰, Network Port๋ฅผ ์ถ”๊ฐ€ํ•˜์—ฌ ๋‚ด๋ถ€๋ง๊ณผ ์™ธ๋ถ€๋ง์„ ๋‚˜๋ˆŒ ์ˆ˜ ์žˆ๋„๋ก ๊ตฌํ˜„ํ•  ๊ฒƒ์ด์—์š”.

๊ธฐ์กด์— ์—ฐ๊ฒฐํ–ˆ๋˜ Port๋Š” ์™ธ๋ถ€๋ง์œผ๋กœ ์‚ฌ์šฉ๋  Port์ด๊ณ , ์—ฐ๊ฒฐ๋œ VDI๋“ค๊ณผ ์—ฐ๊ฒฐํ•  Port๋ฅผ ํ•˜๋‚˜ ๋” ๋งŒ๋“ค์–ด ์ค˜์•ผํ•ด์š”.



Hyper-V ๊ด€๋ฆฌ์ž์—์„œ ๊ฐ€์ƒ ์Šค์œ„์น˜ ๊ด€๋ฆฌ์ž๋ฅผ ์—ด๋„๋ก ํ• ๊ฒŒ์š”.



๋‚ด๋ถ€๋ฅผ ์„ ํƒํ•˜๊ณ , ๊ฐ€์ƒ ์Šค์œ„์น˜ ๋งŒ๋“ค๊ธฐ๋ฅผ ๋ˆŒ๋Ÿฌ์ค„๊ฒŒ์š”.



์ด๋ ‡๊ฒŒ ๋‚ด๋ถ€์—์„œ ์—ฐ๊ฒฐ๋  vSwitch๋ฅผ ํ•˜๋‚˜ ๋งŒ๋“ค์–ด ์ค„๊ฑฐ์—์š”.


๋‹ค์‹œ OPNsense ์„ค์ •์— ๋“ค์–ด๊ฐ€์„œ ๋„คํŠธ์›Œํฌ ์–ด๋Œ‘ํ„ฐ๋ฅผ ์œ„์—์„œ ๋งŒ๋“  VDI-๋‚ด๋ถ€๋ง vSwitch์™€ ์—ฐ๊ฒฐํ•ด ์ค„๊ฒŒ์š”.

์ฃผ๋‹ˆ๋Š” ์ด๋ ‡๊ฒŒ ์ด 3๊ฐœ์˜ vPort๋ฅผ ๋งŒ๋“ค์–ด ์ฃผ์—ˆ๋Š”๋ฐ, VDI์—์„œ ์™ธ๋ถ€๋ž‘ ํ†ต์‹ ์ด ๋˜์–ด์•ผ ํ•˜๊ณ ,
๋‚ด๋ถ€ VDI๋Š” OPNsense์™€ ํ†ต์‹ ๋งŒ ํ•˜๋ฉด ๋˜๊ณ , ๋˜ Server Zone๊ณผ๋„ ์—ฐ๊ฒฐ๋˜์–ด์•ผ ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์ด๋ ‡๊ฒŒ ๊ตฌ์„ฑ์„ ํ•ด ์ฃผ์—ˆ์–ด์š”.








    ๐Ÿ”ฝ OPNsense

        ๐Ÿ“ฆ ์„ค์น˜ํ•˜๊ธฐ

์ด์ œ ๋ณธ๊ฒฉ์ ์œผ๋กœ OPNsense๋ฅผ ์„ค์น˜ํ•ด ๋ณด๋„๋ก ํ• ๊ฒŒ์š”.


์ตœ์ดˆ ์œ„์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜ค๋ฉด Enter๋ฅผ ๋ˆŒ๋Ÿฌ ์„ค์น˜๋ฅผ ์‹œ์ž‘ํ•  ์ˆ˜ ์žˆ์–ด์š”.




๊ทธ๋Ÿฐ ๋’ค ์œ„์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜ค๋ฉด ์•„๋ฌด Key๋‚˜ ๋ˆŒ๋Ÿฌ ์ฃผ์„ธ์š”.


์œ„์™€ ๊ฐ™์ด LAGs์™€ VLANs ์„ค์ •์„ ํ•  ๊ฒƒ์ด๋ƒ๊ณ  ๋ฌผ์–ด๋ณด๋ฉด n์„ ๋ˆŒ๋Ÿฌ ๋„˜์–ด๊ฐ‘๋‹ˆ๋‹ค.

๊ทธ๋Ÿฐ ๋’ค Enter the WAN interface .... ๊ฐ€ ๋‚˜์˜ค๋ฉด ์ธํ„ฐ๋„ท๊ณผ ํ†ต์‹ ์ด ๋˜๋Š” Network Port ์ด๋ฆ„ ์ฆ‰, WAN Port ์ด๋ฆ„์„ ์ ์–ด์ฃผ๋ฉด ๋˜์š”.


์ฃผ๋‹ˆ๋Š” hn0๋ฅผ ์„ ํƒํ•ด ์ค„๊ฒŒ์š”.


728x90


๊ทธ ๋‹ค์Œ์œผ๋กœ๋Š” ๋‚ด๋ถ€์—์„œ ์‚ฌ์šฉํ•  Port๋“ค์„ ์„ค์ •ํ•˜๋Š” ๊ณณ์ด์—์š”.
์ฆ‰, LAN Port๋ฅผ ์„ค์ •ํ•˜๋Š” ๊ณณ์ด์—์š”.




์ฃผ๋‹ˆ๋Š” hn1์„ ์„ ํƒํ•ด ์ค„๊ฒŒ์š”.


 

๊ทธ๋Ÿฐ ๋’ค Server์™€ ์—ฐ๊ฒฐ๋  Port hn2๋ฅผ ๋งˆ์ง€๋ง‰์œผ๋กœ ์„ค์ •ํ•ด ์ค„๊ฑฐ์—์š”.


๋งŒ์•ฝ ์„ค์ •ํ•  ๊ฒƒ์ด ๋” ์—†์œผ๋ฉด Enter๋ฅผ ๋ˆŒ๋Ÿฌ ์ฃผ๋ฉด ๋ฉ๋‹ˆ๋‹ค.


์„ค์ •ํ•œ Network Interface๊ฐ€ ์œ„์™€ ๊ฐ™์€์ง€ ํ™•์ธํ•˜๊ณ  ์žˆ์–ด์š”.

๋งž๋‹ค๋ฉด y๋ฅผ ์ž…๋ ฅํ•˜๊ณ , Enter๋ฅผ ๋ˆŒ๋Ÿฌ ๋„˜์–ด๊ฐ€๋ฉด ๋ฉ๋‹ˆ๋‹ค.



๊ทธ๋Ÿผ ์—ด์‹ฌํžˆ ์„ค์น˜๋ฅผ ์ง„ํ–‰ํ•  ๊ฑฐ์—์š”.




๊ทธ๋Ÿผ ์œ„์™€ ๊ฐ™์ด Login ํ•˜๋Š” ์ฐฝ์ด ๋‚˜์˜ฌ๊ฑฐ์—์š”.

์—ฌ๊ธฐ์„œ root๋กœ Loginํ•˜๊ฒŒ ๋˜๋ฉด Custom ํ•˜๊ฒŒ ์„ค์น˜๋ฅผ ํ•˜๋Š” ๋ฐฉ์‹์ด ์•„๋‹Œ Live Mode๋กœ ์ด์šฉํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋˜๊ธฐ ๋•Œ๋ฌธ์—
root๋กœ Login ํ•˜๋ฉด ์•ˆ๋˜๋Š” ๊ฒƒ์ด์—์š”.

 


์œ„์— ๊ณ„์ •์œผ๋กœ Login์„ ํ•˜๋ฉด ์œ„์™€ ๊ฐ™์€ ์ฐฝ์„ ๋งŒ๋‚  ๊ฑฐ์—์š”.

 

keyboard Layout ์„ค์ • ๋ถ€๋ถ„์ธ๋ฐ, ํ•œ๊ตญ์€ ์—†์œผ๋‹ˆ Default์ธ US๋กœ ์„ค์ •ํ•˜๊ณ  ๋„˜์–ด๊ฐˆ๊ฒŒ์š”.


Enter๋ฅผ ๋ˆŒ๋Ÿฌ ๋‹ค์Œ์œผ๋กœ ๋„˜์–ด๊ฐ€๋ฉด ์œ„์™€ ๊ฐ™์€ ํ™”๋ฉด์„ ๋งŒ๋‚  ์ˆ˜ ์žˆ์–ด์š”.

์œ„์™€ ๊ฐ™์ด UFS ๋˜๋Š” ZFS๋ฅผ ์„ ํƒํ•  ์ˆ˜ ์žˆ์–ด์š”.

ํ•˜์ง€๋งŒ, ์ดˆ๋ณด์ž ์‚ฌ์šฉ์ž ์ธ ๊ฒฝ์šฐ ZFS๋ฅผ ์„ ํƒํ•˜์ง€ ์•Š๋Š” ๊ฒƒ์ด ์ข‹์„ ์ˆ˜ ์žˆ์–ด์š”.
ZFS๋Š” ๋‹ค๋ฅธ ํŒŒ์ผ ์‹œ์Šคํ…œ๋ณด๋‹ค ๊ฐ•๋ ฅํ•˜๋ฏ€๋กœ ZFS์— ๋Œ€ํ•ด ์•„๋ฌด๊ฒƒ๋„ ์ดํ•ดํ•˜์ง€ ๋ชปํ•œ๋‹ค๋ฉด ์„ค์ •์ด ์–ด๋ ค์šธ ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ์ด์—์š”.

ํ•˜๋“œ์›จ์–ด๊ฐ€ ์ œ๋Œ€๋กœ ์ž‘๋™ํ•˜๋Š” ๊ฒฝ์šฐ ๋‘ ํŒŒ์ผ ์‹œ์Šคํ…œ์˜ ์ฐจ์ด๋ฅผ ์•Œ์ง€ ๋ชปํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค.

์ฃผ๋‹ˆ๋Š” UFS๋ฅผ ์„ ํƒํ•ด์„œ ๋„˜์–ด๊ฐˆ ๊ฑฐ์—์š”.



์„ค์น˜ํ•  Storage(Disk)๋ฅผ ๊ณ ๋ฅด๋Š” ๊ณณ์ด์—์š”.

da0๋ฅผ ์„ ํƒํ•ด์„œ ๋„˜์–ด๊ฐ€ ์ค„๊ฒŒ์š”.



swap prtition์„ 8GB๋กœ ์žก๊ฒ ๋‹ค๊ณ  ๋ฌผ์–ด๋ณด๊ณ  ์žˆ์–ด์š”.

์ฃผ๋‹ˆ์“ฐ๋Š” ํ—ˆ๋ฝ์„ ํ•ด ์ฃผ๋„๋ก ํ• ๊ฑฐ์—์š”.



Disk์— Data๊ฐ€ ๋ชจ๋‘ ์ง€์›Œ์ง„๋‹ค๊ณ  ๊ฒฝ๊ณ ํ•˜๊ณ  ์žˆ์–ด์š”.

YES๋ฅผ ์„ ํƒํ•˜๊ณ  ๋„˜์–ด๊ฐ€ ์ค„๊ฒŒ์š”.


 
๊ทธ๋Ÿผ ์œ„์™€ ๊ฐ™์ด ์—ด์‹ฌํžˆ ์„ค์น˜๋ฅผ ์ง„ํ–‰ํ•  ๊ฑฐ์—์š”.



root ๋น„๋ฐ€๋ฒˆํ˜ธ ๋ณ€๊ฒฝ ๋’ค Complete Install์„ ์„ ํƒํ•ด์„œ ์„ค์น˜๋ฅผ ๋๋‚ผ๊ฒŒ์š”.

์ฐธ๊ณ ๋กœ ์ด ๋•Œ ๋“ค์–ด์žˆ๋˜ ISO ๋˜๋Š” CD๋ฅผ ์ œ๊ฑฐํ•ด ์ค˜์•ผํ•ด์š”.

์•ˆ ๊ทธ๋Ÿฌ๋ฉด Live Mode๋กœ ๋™์ž‘ํ•˜๋Š” ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.



์œ„์™€ ๊ฐ™์ด ๋‹ค์‹œ Login ์ฐฝ์„ ๋งŒ๋‚˜๊ฒŒ ๋˜๋ฉด ์•„๋ž˜ ๊ณ„์ •์œผ๋กœ ์ ‘์†์„ ํ•ด์ค˜์•ผ ํ•ด์š”.


Login์ด ์™„๋ฃŒ๋˜๋ฉด ์œ„์™€ ๊ฐ™์€ ํ™”๋ฉด์„ ๋งŒ๋‚  ์ˆ˜ ์žˆ์–ด์š”.

์ฒซ๋ฒˆ์งธ๋กœ ํ•ด์•ผ ํ•˜๋Š” ์ž‘์—…์€ LAN IP ์ฃผ์†Œ๋ฅผ ๋ณ€๊ฒฝํ•˜๋Š” ๊ฒƒ์ด์—์š”.

2๋ฅผ ๋ˆ„๋ฅด๊ณ , Enter๋ฅผ ๋ˆŒ๋Ÿฌ์ค„๊ฒŒ์š”.


LAN ๋ฒˆํ˜ธ๊ฐ€ 1๋ฒˆ์ด๊ธฐ ๋•Œ๋ฌธ์— 1์„ ๋ˆ„๋ฅด๊ณ , Enter๋ฅผ ๋ˆŒ๋Ÿฌ์ค„๊ฒŒ์š”.



์œ„์—์„œ ๋ถ„๋ช… hn0๋ฅผ WAN์œผ๋กœ hn1์„ LAN์œผ๋กœ ์žกํ˜”๋Š”๋ฐ, ๋ฐ˜๋Œ€๋กœ ์žกํžŒ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ์–ด์š”.


์ด ๊ณณ์—์„œ 1๋ฒˆ์„ ๋ˆŒ๋Ÿฌ ๋‹ค์‹œ ์„ค์ •์„ ํ•ด ์ค„๊ฒŒ์š”.

์„ค์ • ๋ฐฉ๋ฒ•์€ ์œ„์—์„œ ์ดˆ๊ธฐ์— ์„ค์ •ํ–ˆ๋˜ ๊ฒƒ๊ณผ ๋™์ผํ•ฉ๋‹ˆ๋‹ค.


์œ„์™€ ๊ฐ™์ด ๋‹ค์‹œ ์„ค์ •์„ ํ•ด์ฃผ์—ˆ์–ด์š”.

๋‹ค๋งŒ ์ด๋ฒˆ์—๋Š” hn2๋Š” ์žก์ง€ ์•Š์•˜์–ด์š”.



์ด๋ฒˆ์—๋Š” ์ž˜ ์žกํžŒ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์–ด์š”.

๋‹ค์‹œ 2๋ฒˆ์„ ํ†ตํ•ด ์ž‘์—…์„ ์ง„ํ–‰ํ•ด ๋ณผ๊ฒŒ์š”.



์œ„์™€ ๊ฐ™์ด ์„ค์ •์„ ํ•ด ์ฃผ๋„๋ก ํ• ๊ฒŒ์š”.




์—ฌ๊ธฐ๊นŒ์ง€ ์™„๋ฃŒ ๋˜์—ˆ๋‹ค๋ฉด 0๋ฒˆ์„ ๋ˆŒ๋Ÿฌ Logout์„ ํ•ด์ฃผ๋ฉด ๋˜์š”.




 

 

        ๐Ÿ“ฆ ์ดˆ๊ธฐ ๊ตฌ์„ฑ

์œ„์—์„œ ์„ค์ •ํ–ˆ๋˜ LAN IP๋ฅผ ํ†ตํ•ด Hyper-V๊ฐ€ ์„ค์น˜๋œ HOST Server ๋ธŒ๋ผ์šฐ์ €๋กœ ์ ‘์†์„ ์‹œ๋„ํ•ด ๋ณด์•˜์–ด์š”.

 

์œ„์™€ ๊ฐ™์ด ์ •์ƒ ์ ‘์† ๋˜๋Š”๊ฑธ ํ™•์ธํ•  ์ˆ˜ ์žˆ์–ด์š”.


๊ณ„์ •(ID): root
๋น„๋ฐ€๋ฒˆํ˜ธ(Password): opnsense


์œ„์˜ ๊ณ„์ • ์ •๋ณด๋ฅผ ์ž…๋ ฅํ•ด์„œ Login์„ ํ•ด ์ค๋‹ˆ๋‹ค.


๊ทธ๋Ÿผ ์œ„์™€ ๊ฐ™์ด ์ดˆ๊ธฐ ๊ตฌ์„ฑ์„ ํ•  ์ˆ˜ ์žˆ๋Š” ํ™”๋ฉด์„ ๋งŒ๋‚  ์ˆ˜ ์žˆ์–ด์š”.

Next๋ฅผ ๋ˆŒ๋Ÿฌ ์ง„ํ–‰ํ•ด ๋ณผ๊ฒŒ์š”.



๋„ˆ๋ฌด ์•ˆํƒ€๊น๊ฒŒ๋„ ์–ธ์–ด๋Š” ํ•œ๊ธ€์ด ์—†๋„ค์š”.


๋กœ์ปฌ ๋„๋ฉ”์ธ์„ ๋‹ค๋ฅธ ๋„๋ฉ”์ธ์œผ๋กœ ๋ณ€๊ฒฝํ•  ์ˆ˜ ์žˆ์–ด์š”.
๋„๋ฉ”์ธ ์ด๋ฆ„์„ ์†Œ์œ ํ•˜์ง€ ์•Š๋Š” ํ•œ ์‹ค์ œ ๋„๋ฉ”์ธ ์ด๋ฆ„์ด ์•„๋‹Œ ๋„๋ฉ”์ธ์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

 

 


์ฃผ๋‹ˆ๋Š” ์ด๋ ‡๊ฒŒ ์„ค์ •ํ•˜๊ณ  ๋„˜์–ด๊ฐ€ ์ค„๊ฒŒ์š”.



๋‹ค์Œ์€ ์‹œ๊ฐ„ ์„ค์ •ํ•˜๋Š” ๋ถ€๋ถ„์ด์—์š”.

์ฃผ๋‹ˆ๋Š” Hyper-V Host Server์—์„œ ์‹œ๊ฐ„์„ ๊ฐ€์ ธ์˜ค๋„๋ก ์„ค์ •ํ•ด ์ค„๊ฑฐ์—์š”.



WAN Interface ์„ค์ • ๋ถ€๋ถ„์—์„œ ์ฃผ๋‹ˆ๋Š” ์—ฐ๊ฒฐํ•œ WAN Interface๊ฐ€ ์™ธ๋ถ€์—์„œ DHCP๋กœ IP๋ฅผ ๋ฐ›์•„์˜ค๊ฒŒ ํ•ด๋†จ๊ธฐ ๋•Œ๋ฌธ์— DHCP๋กœ ํ•˜๊ณ  ๋„˜์–ด๊ฐ€ ์ค„๊ฒŒ์š”.



๋‘ ๊ฐœ ๋ชจ๋‘ ๊ธฐ๋ณธ๊ฐ’์œผ๋กœ ํ™œ์„ฑํ™” ์‹œํ‚ค๊ณ  ๋„˜์–ด๊ฐ€ ์ค„๊ฒŒ์š”.


๋ฐ˜์‘ํ˜•


LAN Interface ์„ค์ •๋ถ€๋Š” ์œ„์—์„œ CLI๋กœ ์„ค์ •ํ–ˆ๊ธฐ ๋•Œ๋ฌธ์— ์œ„์™€ ๊ฐ™์ด ๋‘๊ณ , ๋„˜์–ด๊ฐˆ๊ฒŒ์š”.




root Password๋ฅผ ์ž…๋ ฅํ•˜๋Š” ๊ณณ์ด์—์š”.


์ž…๋ ฅํ•˜๊ณ , ๋‹ค์Œ์œผ๋กœ ๋„˜์–ด๊ฐ€ ์ค„๊ฒŒ์š”.



๊ทธ๋Ÿฐ ๋’ค Reload๋ฅผ ๋ˆŒ๋Ÿฌ ์„ค์ •์ด ์ž…๋ ฅ๋˜๊ฒŒ ํ•ด ์ค„๊ฒŒ์š”.



์„ค์ •์ด ์™„๋ฃŒ๋˜๋ฉด ์œ„์™€ ๊ฐ™์€ ํ™”๋ฉด์„ ๋งŒ๋‚  ์ˆ˜ ์žˆ์–ด์š”.



์œ„์— ๋‚ด์šฉ์„ ํด๋ฆญํ•˜์—ฌ Dashboard๋ฅผ ํ•œ๋ฒˆ ํ™•์ธํ•ด ๋ณผ๊ฒŒ์š”.



UI๊ฐ€ ๊ฝค๋‚˜ ๊น”๋”ํ•œ ํŽธ์ด์—์š”.

ํ•œ๊ธ€๋งŒ ์ง€์›๋˜๋ฉด ๋”ํ•  ๋‚˜์œ„ ์—†์„ ๊ฑฐ ๊ฐ™์•„์š”.



์˜ค๋ฅธ์ชฝ์— Add widget์„ ๋ˆŒ๋Ÿฌ widget์„ ๋” ์ถ”๊ฐ€ํ•  ์ˆ˜ ์žˆ์–ด์š”.


์ด ๊ณณ์—์„œ ํ•„์š”ํ•œ ๊ฒƒ๋“ค์„ ์ถ”๊ฐ€ํ•ด ์ฃผ๋ฉด ๋˜๊ฒ ๋„ค์š”.

 

 

 

 

๐Ÿง ์ฐธ๊ณ  ์ž๋ฃŒ

 

 

 

 

 

 

 

728x90
๋ฐ˜์‘ํ˜•