Setting up a Firewall for IoT Lab Network

Much of this article was inspired by the following video from NetworkChuck:

This New Device is 10x Better Than Your Router

I test ethernet capabilities of IoT devices daily. This involves loading firmware that may contain vulnerable code still in development. I needed a way for my Hardware-In-The-Loop (HIL) test equipment to access and talk to these IoT devices (i.e. ssh onto these devices, access web protocols, etc.) without exposing these devices to the internet. Additionally, as I am working out of my home, I also needed to separate my work network from my home network. This meant I needed 3 networks: 

  1.  IoT devices that should not have internet access.
  2. Work and test equipment that need internet access to maintain updates.
  3. My home network which mainly uses Wi-Fi.

After some searching I found the perfect router. Note this might be overkill for most network but for my purposes it met my needs:

CWWK Firewall 

This router/bare-metal pc has 4 ethernet ports. While VLANs could be used through a managed switch this setup is better as it allows me to separate networks at the physical layer instead of the data link layer. This will make the networks more secure (i.e. these networks are effectively air-gapped and eliminate VLAN Hoping attacks). All it needs now is OPNSense.

Much of loading OPNSense onto this baremetal pc is discussed in NetworkChucks video but essentially you need to do the following:

  1.  Download OPNSense ISO for amd64 System Architecture, vga image type, using any mirror. At the time of writing the default settings are fine.
  2. Use balenaEtcher or other any other flasher to flash a ExFAT formatted USB drive.
  3. Plug in the USB drive into the firewall.
  4. Get into the BIOS/UEFI and set the primary boot device to the USB drive.
  5. Continue with boot and follow the install instructions.

It may be best to experiment with all of this by plugging your router into your existing router. Note this means your network will be double NATed so you might need to unblock bogon and private networks on the WAN port for the time being until you effectively replace your current router or set your current router into bridge mode.

Now comes the port interface setup. In my case I am using all 4 ports so I setup a WAN port with IPv4 and IPv6 Configuration Types as DHCP. I also setup the other 3 interfaces. Once all 3 interfaces are setup, now comes the exciting part. Configuring the firewall. Without giving too much of my network topology away I have the following general rules:

  1. I block web admin access on both my work and lab network.
  2. I block off access between my home and the work and lab networks but allow my work network to access the lab network.
  3. I block all lab network traffic to WAN to prevent leaks from the lab network out onto the internet.

Effectively, I now have a home network that is on a completely separate network (a ping sweep and port scan from nmap can prove this). My work network has access to the lab network and the ethernet but no administration privileges of my router (yea I'm onto you Bob from IT). This should secure me though additional external and internal pen tests shall be performed.

In conclusion, I believe the money from this router is worth it; especially if you are in IoT security. Having 4 ethernet ports has proved useful in isolating my networks and placing stricter rules on certain networks while having more relaxed rules on others. I have gained peace of mind with this firewall and I recommend setting one up if you are doing IoT testing.

 

Comments

Popular posts from this blog

Setting Up a Proxy to Protect Your Public IP (An Introduction to Proxies)

Reverse Shell with Ncat

LDAP Vulnerabilities