Interns will gain in-depth exposure to network security, firewall configuration, routing, and monitoring enterprise network traffic through the pfSense operating system.


Required knowledge to grasp


  • Network Knowledge: OSI Model, TCP/IP, Subnetting, DHCP, DNS, NAT (Port Forwarding, Outbound NAT).

  • Firewall Rules Concepts: Mechanism for blocking/filtering packets based on IP, Port, Protocol, state (Stateful Inspection).

  • Virtual Private Network: Understand the operating principles of OpenVPN, IPsec, or WireGuard.


Execution sequence


  1. Device/Lab Environment Registration: Access https://dev.mdcgroup.vn to request a virtualized environment (Proxmox) with at least 2 network cards (WAN and LAN) to install pfSense.

  2. Initial Installation: Proceed with pfSense installation from an ISO file, configure WAN network card (receive IP from MDC Group) and LAN network card (assign IP to your internal network).

  3. Core Services Configuration: Set up DHCP Server configuration for the LAN network, configure DNS Resolver for stable domain name resolution.

  4. Firewall Rules & NAT Setup: Create Rules to control data: Allow LAN to Internet, block specific IPs/Websites, configure Port Forwarding to expose services from the LAN to the WAN.

  5. VPN Configuration: Deploy WireGuard or OpenVPN service on pfSense, configure Client on personal computer to securely connect remotely to the internal LAN network.

  6. System Monitoring: Install and configure Packages such as ntopng for bandwidth monitoring or Suricata for IDS/IPS intrusion detection.


Result Acceptance


  • Quiz: Take a network and pfSense theory test on the internal system.

  • Questions & Proposals: Propose solutions to optimize internal network security based on learned rules.

  • Report Results: Capture the logical network diagram, Firewall Rules table, and demonstrate successful VPN connection to send to management.

  • Weekend Discussion: Participate in the intern discussion session, sharing how to handle network loss issues when configuring rules incorrectly.