Some questions while trying out DynFi FW Manager
Moderator: gregober
Some questions while trying out DynFi FW Manager
Hi, I have just started testing the dynfi FW Manager.
The installation was done quickly and the look and feel is great.
I manage about 78 firewalls, mainly pfSense CE, but also some Plus, OPNsense CE and an OPNsense Business.
From what I've read on the forum, the manager does not support the paid versions of pfSense and OPNsense. Is this still the case?
What about high availability?
Does the Manager support clustered firewalls?
Most of the 78 FW are set up in high availability with two nodes in the clusters.
I have set up the on-premise version and added my two test FWs which are clustered, but I see no indication that these firewalls are connected in any way.
Are virtual IPs supported?
We have a lot of CARP addresses as we are routing public networks to the firewalls and adding them as virtual IPs.
So far I have only been able to find the interface subnets and gateway IPs.
Is there an overview of the planned features?
Thanks for any answer.
The installation was done quickly and the look and feel is great.
I manage about 78 firewalls, mainly pfSense CE, but also some Plus, OPNsense CE and an OPNsense Business.
From what I've read on the forum, the manager does not support the paid versions of pfSense and OPNsense. Is this still the case?
What about high availability?
Does the Manager support clustered firewalls?
Most of the 78 FW are set up in high availability with two nodes in the clusters.
I have set up the on-premise version and added my two test FWs which are clustered, but I see no indication that these firewalls are connected in any way.
Are virtual IPs supported?
We have a lot of CARP addresses as we are routing public networks to the firewalls and adding them as virtual IPs.
So far I have only been able to find the interface subnets and gateway IPs.
Is there an overview of the planned features?
Thanks for any answer.
Re: Some questions while trying out DynFi FW Manager
Well, we can't guarantee long term support for firewall which have a closed source policy.I manage about 78 firewalls, mainly pfSense CE, but also some Plus, OPNsense CE and an OPNsense Business.
From what I've read on the forum, the manager does not support the paid versions of pfSense and OPNsense. Is this still the case?
So while we do our best to support these OS, we can't guarantee that Netgate or OPNsense won't change their policy or inside code with major shift. This is the reason why we are providing "limited support" for these OS.
Absolutely, clustered firewall from our point of view are just "two firewalls".What about high availability?
Does the Manager support clustered firewalls?
In order for DynFi Manager to be working seamlessly, you will have to make sure that the manager can access both devices.
That might be a good idea for improvement, at this stage we have no sign letting you know that your devices are clustered.Most of the 78 FW are set up in high availability with two nodes in the clusters.
I have set up the on-premise version and added my two test FWs which are clustered, but I see no indication that these firewalls are connected in any way.
But we will try to see with the team how to make that happen - shouldn't be too difficult.
VIP might not be drawn in the interface schema presented.Are virtual IPs supported?
We have a lot of CARP addresses as we are routing public networks to the firewalls and adding them as virtual IPs.
So far I have only been able to find the interface subnets and gateway IPs.
But you surely can connect devices using these IPs.
Progresses are being made to further integrate firewall rule management at this stage.Is there an overview of the planned features?
Thanks for any answer.
We are also trying to see how to add support for LDAP within Manager's users.
Other small improvement are on their way and we have regular app upgrades.
Re: Some questions while trying out DynFi FW Manager
Many thanks for the quick reply.
It would be ok not to be able to manage the paid versions as there are not that many.
About the VIPs.
What I am looking for is the ability to switch the CARP IPs and also see the current status. Are the IPs master or backup on the different nodes.
It would also be nice to be able to trigger a configuration synchronization between the master and the slave.
I am looking for a centralized way to update the firewalls.
But for clustered firewalls, I would like to be able to synchronize the configuration before the update and after updating the slave, switch the vIPs to the slave and then perform the update on the master.
The ability to manage firewall rules and also NAT rules centrally would be a big advantage and would make the Dynfi FW Manager even more interesting for me.
It would be ok not to be able to manage the paid versions as there are not that many.
About the VIPs.
What I am looking for is the ability to switch the CARP IPs and also see the current status. Are the IPs master or backup on the different nodes.
It would also be nice to be able to trigger a configuration synchronization between the master and the slave.
I am looking for a centralized way to update the firewalls.
But for clustered firewalls, I would like to be able to synchronize the configuration before the update and after updating the slave, switch the vIPs to the slave and then perform the update on the master.
The ability to manage firewall rules and also NAT rules centrally would be a big advantage and would make the Dynfi FW Manager even more interesting for me.
Re: Some questions while trying out DynFi FW Manager
We would be able to push this forward quite rapidly since it is a quite basic task.Many thanks for the quick reply.
It would be ok not to be able to manage the paid versions as there are not that many.
About the VIPs.
What I am looking for is the ability to switch the CARP IPs and also see the current status. Are the IPs master or backup on the different nodes.
This would allow you to have infos about Primary / Backup nodes in the GUI of the Manager (probably with a crossed link from each node).
Normally this part is automatically triggered in pfSense and has to be manually triggered in OPNsense.It would also be nice to be able to trigger a configuration synchronization between the master and the slave.
So, It might be interesting to have such "sync feature" for OPN, can you confirm the scope you had in mind ?
Is indeed feasible, but shall require more work…I am looking for a centralized way to update the firewalls.
But for clustered firewalls, I would like to be able to synchronize the configuration before the update and after updating the slave, switch the vIPs to the slave and then perform the update on the master.
This is our main focus at the time.The ability to manage firewall rules and also NAT rules centrally would be a big advantage and would make the Dynfi FW Manager even more interesting for me.
We prioritize requests coming from our customers first, so we strongly encourage you to start subscribing to our offer.
Re: Some questions while trying out DynFi FW Manager
Indeed, it's on pfSense and can be automated on OPNsense as well.Normally this part is automatically triggered in pfSense and has to be manually triggered in OPNsense.
I guess it's just my inner Monk wanting to make absolutely sure the firewalls are synchronized before I start the update
That would be awesome.We would be able to push this forward quite rapidly since it is a quite basic task.
This would allow you to have infos about Primary / Backup nodes in the GUI of the Manager (probably with a crossed link from each node).
It's a chicken and egg problem.This is our main focus at the time.
We prioritize requests coming from our customers first, so we strongly encourage you to start subscribing to our offer.
I need to convince my boss to spend the money, but I need the features to do that
Can you give an estimate of when these features will be available?
Re: Some questions while trying out DynFi FW Manager
Hello Gregory,
I am currently in the process of building a PoC for one of our customers. Part of the PoC is to centrally manage the firewall rules. I would like to do this with DFM – and I have currently installed version 24.1.0 in a test setup. As far as I can see, the management of the rules has not yet been implemented, or at least it is not yet usable. Is there any time frame you can give us for when you might release a first functional version of the rule management?
Thank you in advance!
Kind regards,
Hagen
I am currently in the process of building a PoC for one of our customers. Part of the PoC is to centrally manage the firewall rules. I would like to do this with DFM – and I have currently installed version 24.1.0 in a test setup. As far as I can see, the management of the rules has not yet been implemented, or at least it is not yet usable. Is there any time frame you can give us for when you might release a first functional version of the rule management?
Thank you in advance!
Kind regards,
Hagen
gregober wrote: ↑11 Jun 2024, 12:14This is our main focus at the time.The ability to manage firewall rules and also NAT rules centrally would be a big advantage and would make the Dynfi FW Manager even more interesting for me.
We prioritize requests coming from our customers first, so we strongly encourage you to start subscribing to our offer.
Re: Some questions while trying out DynFi FW Manager
The way to handle firewall rules at this stage is through the use of aliases.Hello Gregory,
I am currently in the process of building a PoC for one of our customers. Part of the PoC is to centrally manage the firewall rules. I would like to do this with DFM – and I have currently installed version 24.1.0 in a test setup. As far as I can see, the management of the rules has not yet been implemented, or at least it is not yet usable. Is there any time frame you can give us for when you might release a first functional version of the rule management?
Thank you in advance!
Kind regards,
Hagen
Aliases can be used extensively and managed centrally, allowing you to create some custom settings easily replicable on many devices.
We will start working soon on some new features and handling firewall rules is very high on the priority list.
Will certainly be available in 2025.
We are actually finishing LDAP integration.
Re: Some questions while trying out DynFi FW Manager
Hello Gregory,gregober wrote: ↑22 Nov 2024, 15:29 The way to handle firewall rules at this stage is through the use of aliases.
Aliases can be used extensively and managed centrally, allowing you to create some custom settings easily replicable on many devices.
We will start working soon on some new features and handling firewall rules is very high on the priority list.
Will certainly be available in 2025.
We are actually finishing LDAP integration.
thank you for the time frame. If I understand you correctly, your input is that the design of the rules from the outset (in which case we could start a new setup) should be set up in such a way that the aspects of source, destination and ports are assigned and controlled by aliases?
Kind regards,
Hagen