{"id":393,"date":"2020-04-03T15:22:08","date_gmt":"2020-04-03T18:22:08","guid":{"rendered":"https:\/\/www.tonev.pro.br\/?p=393"},"modified":"2020-04-03T18:57:08","modified_gmt":"2020-04-03T21:57:08","slug":"firewall-pfsense-em-ambiente-cloud-da-amazon-aws","status":"publish","type":"post","link":"https:\/\/www.tonev.pro.br\/?p=393","title":{"rendered":"Firewall pfSense em ambiente cloud da Amazon AWS"},"content":{"rendered":"<p>Muitas pessoas acham que a solu\u00e7\u00e3o m\u00e1gica para os problemas de infra estrutura \u00e9 a migra\u00e7\u00e3o para &#8220;a nuvem&#8221;.\u00a0 A realidade n\u00e3o \u00e9 bem essa. Quando voc\u00ea migra os servidores da sua rede para a nuvem a unica coisa que o provedor se responsabiliza \u00e9 a estrutura f\u00edsica que inclui o local, energia, resfriamento e a comunica\u00e7\u00e3o de dados. O que vai rodar na infra do provedor \u00e9 responsabilidade do cliente. Uma boa leitura para esclarecer as duvidas \u00e9 o artigo &#8220;<a href=\"https:\/\/aws.amazon.com\/pt\/compliance\/shared-responsibility-model\/\" target=\"_blank\" rel=\"noopener noreferrer\">Modelo de responsabilidade compartilhada<\/a>&#8221; da AWS.<\/p>\n<p>Seria bastante simples se simplesmente fosse poss\u00edvel colocar todos os servidores em uma unica rede, todos eles com endere\u00e7os validos atribu\u00eddos ,mas em muitas situa\u00e7\u00f5es isso n\u00e3o \u00e9 poss\u00edvel e nem recomend\u00e1vel. \u00c9 poss\u00edvel restringir a comunica\u00e7\u00e3o usando ACLs e grupos de seguran\u00e7a, porem esse tipo de gerencia n\u00e3o \u00e9 f\u00e1cil de ser mantida. Quando \u00e9 necess\u00e1rio ter hist\u00f3rico de log do que foi aceito e o que foi negado ai fica bastante complicado. Sem mencionar que n\u00e3o \u00e9 poss\u00edvel implementar um <a href=\"https:\/\/en.wikipedia.org\/wiki\/Intrusion_detection_system#Intrusion_prevention\" target=\"_blank\" rel=\"noopener noreferrer\">IPS<\/a> sem ter um ponto central por onde passa o trafego.<\/p>\n<p><b>Antes de come\u00e7ar \u00e9 importante deixar claro que a AWS cobra os recursos alocados por hora, m\u00eas ou ano. Portanto cuidado, pois o uso pode gerar cobran\u00e7as. Se criar um recurso, exclua ele no fim do teste se n\u00e3o for usar mais! N\u00e3o deixe instancias rodando enquanto n\u00e3o estiver usando!<\/b><\/p>\n<p>A rede para esse artigo \u00e9 bem simples e segue, no meu entender, a arquitetura tradicional de ambiente &#8220;on premise&#8221; que conta com um link de Internet conectando no firewall juntamente com todas as redes privadas e o firewall sendo o respons\u00e1vel por controlar a comunica\u00e7\u00e3o de todos os segmentos da rede.<\/p>\n<p>Nesse caso escolhi criar duas redes privadas que est\u00e3o ligadas no firewall e precisam de regras de libera\u00e7\u00e3o para se comunicarem ou sa\u00edrem para a Internet. Apenas lembrando que o tr\u00e1fego entre duas m\u00e1quinas na mesma subnet n\u00e3o passam pelo firewall e se precisar restringir tem que usar as funcionalidades de ACLs ou grupos de seguran\u00e7a.<\/p>\n<p>&nbsp;<\/p>\n<figure id=\"attachment_404\" aria-describedby=\"caption-attachment-404\" style=\"width: 300px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/04\/pfSense-AWS.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-404 size-medium\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/04\/pfSense-AWS-300x127.jpg\" alt=\"Exemplo de rede de teste\" width=\"300\" height=\"127\" srcset=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/04\/pfSense-AWS-300x127.jpg 300w, https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/04\/pfSense-AWS-700x295.jpg 700w, https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/04\/pfSense-AWS-768x324.jpg 768w, https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/04\/pfSense-AWS.jpg 1131w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><figcaption id=\"caption-attachment-404\" class=\"wp-caption-text\">Exemplo de rede de teste<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>Como a Amazon realiza mudan\u00e7as e lan\u00e7a novos servi\u00e7os muito rapidamente, algumas telas podem n\u00e3o ser exatamente iguais \u00e0s que s\u00e3o apresentadas nesse tutorial. Se tiver qualquer duvida, no final do post vou adicionar alguns links da documenta\u00e7\u00e3o da AWS que considero importantes.<\/p>\n<p>Os passos abaixo podem ser usados para implementar qualquer tipo de firewall. Se for criar ambiente de produ\u00e7\u00e3o, verifique na documenta\u00e7\u00e3o qual a instancia recomendada, pois o numero m\u00e1ximo de interfaces de rede muda de acordo com o tipo escolhido.<\/p>\n<p>1 &#8211; Assim que se logar no console do AWS procure pela op\u00e7\u00e3o de &#8220;VPC&#8221;. Clique nela e na primeira tela clique no bot\u00e3o &#8220;Launch VPC Wizard&#8221;. Deixe selecionada a primeira op\u00e7\u00e3o que \u00e9 &#8220;VPC with a Single Public Subnet&#8221; e clique no &#8220;Select&#8221;. Apos isso escolha um bloco IPv4 privado, defina o nome da VPC, o bloco IPv4 da rede que ser\u00e1 a publica e a zona da AWS onde ser\u00e1 criada a rede. Repare que a zona selecionada \u00e9 a &#8220;us-east-1c&#8221;. <strong>\u00c9 importante que todos os recursos usados sejam criados na mesma zona<\/strong>:<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-001.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-001-700x394.png\" alt=\"\" width=\"700\" height=\"394\" srcset=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-001-700x394.png 700w, https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-001-300x169.png 300w, https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-001-768x432.png 768w, https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-001.png 1366w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>2 &#8211; Ap\u00f3s completar a cria\u00e7\u00e3o da VPC ela aparecera como dispon\u00edvel no menu de &#8220;Your VPCs&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-002.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-002-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>3 &#8211; Clique no menu de &#8220;Subnets&#8221; para criar as redes privadas. J\u00e1 vai aparecer a &#8220;VPC_PUBLIC_SUBNET&#8221; como dispon\u00edvel:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-003.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-003-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>4 &#8211; Clique no bot\u00e3o de &#8220;Create subnet&#8221;. Defina um nome, selecione a VPC, a zona e defina um bloco de IPv4:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-004.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-004-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>5 &#8211; Apos completar a cria\u00e7\u00e3o a primeira rede privada vai aparecer juntamente com a rede publica.<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-005.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-005-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>6 &#8211; Clique novamente no bot\u00e3o &#8220;Create subnet&#8221; para criar a segunda rede. Repita os passos do item 4, trocando apenas o valor do bloco de IPv4:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-006.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-006-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>7 &#8211; Apos completar a cria\u00e7\u00e3o a todas as redes necess\u00e1rias estar\u00e3o dispon\u00edveis para uso;<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-007.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-007-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>8 &#8211; Apos terminada a cria\u00e7\u00e3o das redes, volte a tela principal do console do AWS e entre na op\u00e7\u00e3o de &#8220;EC2&#8221;. Aqui ser\u00e3o criados os recursos computacionais das VMs. Escolha no lado esquerdo o menu de &#8220;Security Groups&#8221; para criar as regras de trafego dentro da AWS. clique no bot\u00e3o &#8220;Create security group&#8221;. Na tela de cria\u00e7\u00e3o coloque uma descri\u00e7\u00e3o em &#8220;Security group name&#8221; ( sem espa\u00e7os ) e &#8220;Description&#8221;. Deixe marcado &#8220;VPC&#8221; no escopo e selecione a VPC na lista.<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-008.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-008-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>9 &#8211; Em seguida em &#8220;Inbound rules&#8221; clique no bot\u00e3o de &#8220;Add rule&#8221; e altere o &#8220;Type&#8221; para &#8220;All traffic&#8221;. Em &#8220;Source&#8221; deixe em &#8220;Custom&#8221; e informe &#8220;0.0.0.0\/0&#8221; no campo de origem. Tamb\u00e9m pode especificar o &#8220;Source&#8221; como &#8220;Anywhere&#8221;. O resultado ser\u00e1 o mesmo. Repita o mesmo processo para o &#8220;Outbound rules&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-009.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-009-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>10 &#8211; Apos a cria\u00e7\u00e3o do grupo de seguran\u00e7a, escolha o menu de &#8220;Instances&#8221; e clique no bot\u00e3o &#8220;Launch Instance&#8221;. Agora vamos criar uma VM em cada subnet privada. Ser\u00e1 apresentada a tela a seguir. Deixe selecionada a primeira op\u00e7\u00e3o &#8220;Amazon Linux 2 AMI (HVM), SSD Volume Type&#8221; e clique no &#8220;Select&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-010.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-010-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>11 &#8211; Em seguida \u00e9 necess\u00e1rio informar o tipo de instancia que ser\u00e1 criada. Pode deixar em &#8220;t2.micro&#8221; que pode ser executada sem custos e clique no &#8220;Next: Configure Instance Details&#8221;.<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-019.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-019-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>12 &#8211; Altere o campo de &#8220;Subnet&#8221; para selecionar a primeira rede privada. Repare que o segundo campo \u00e9 o nome que foi definido para a rede. O &#8220;Auto-assign Public IP&#8221; deve ficar em &#8220;Disable&#8221; por se tratar de rede privada e pode marcar a op\u00e7\u00e3o de &#8220;Enable termination protection&#8221; para n\u00e3o excluir a VM durante os testes em vez de desligar. Finalizado isso, clique em &#8220;Next: Add Storage&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-011.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-011-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>13 &#8211; Nessa tela pode deixar no padr\u00e3o. Os 8GB de disco j\u00e1 s\u00e3o suficientes para os testes. Clique no &#8220;Next: Add Tags&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-012.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-012-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>14 &#8211; Para ambiente de testes n\u00e3o precisa adicionar nenhuma tag a VM. Clique no &#8220;Next: Configure Security Group&#8221;<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-013.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-013-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>15 &#8211; Escolha o grupo de seguran\u00e7a que criamos. Ele vai permitir todo o trafego de entrada e sa\u00edda. Ao finalizar, clique no &#8220;Review and Launch&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-014.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-014-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>16 &#8211; Ser\u00e1 apresentada uma tela com as informa\u00e7\u00f5es da instancia a ser criada\/lan\u00e7ada. Clique no &#8220;Launch&#8221;;<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-015.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-015-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>17 &#8211; Antes de iniciar a instancia \u00e9 necess\u00e1rio escolher uma chave SSH que ser\u00e1 usada para efetuar login remoto. Se j\u00e1 tiver uma chave, use ela. Caso contrario pode criar uma. Ap\u00f3s salvar a chave de acesso clique no &#8220;Launch Instances&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-016.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-016-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>18 &#8211; Ser\u00e1 apresentada a tela abaixo confirmando que a instancia est\u00e1 sendo criada e iniciada.<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-017.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-017-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>19 &#8211; Repita os passos de 10 a 18 para criar a segunda instancia na segunda rede privada. Deixe selecionada a primeira op\u00e7\u00e3o \u201cAmazon Linux 2 AMI (HVM), SSD Volume Type\u201d e clique no \u201cSelect\u201d:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-018.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-018-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>20 &#8211; Deixe o tipo em \u201ct2.micro\u201d e clique no \u201cNext: Configure Instance Details\u201d<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-019.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-019-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>21 &#8211;\u00a0 . Altere o campo de \u201cSubnet\u201d para selecionar a segunda rede privada. Repare que o segundo campo \u00e9 o nome que foi definido para a rede. O \u201cAuto-assign Public IP\u201d deve ficar em \u201cDisable\u201d por se tratar de rede privada e pode marcar a op\u00e7\u00e3o de \u201cEnable termination protection\u201d para n\u00e3o excluir a VM durante os testes em vez de desligar. Finalizado isso, clique em \u201cNext: Add Storage\u201d:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-020.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-020-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>22 &#8211; Nessa tela pode deixar no padr\u00e3o. Os 8GB de disco ja s\u00e3o suficientes para os testes. Clique no \u201cNext: Add Tags\u201d:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-021.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-021-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>23 &#8211; Para ambiente de testes n\u00e3o precisa adicionar nenhuma tag a VM. Clique no \u201cNext: Configure Security Group\u201d<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-022.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-022-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>24 &#8211; \u00a0Escolha o grupo de seguran\u00e7a que criamos. Ele vai permitir todo o trafego de entrada e sa\u00edda. Ao finalizar, clique no \u201cReview and Launch\u201d:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-023.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-023-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>25 &#8211; Ser\u00e1 apresentada uma tela com as informa\u00e7\u00f5es da instancia a ser criada \/ lan\u00e7ada. Clique no \u201cLaunch\u201d;<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-024.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-024-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>26 &#8211; Antes de iniciar a instancia \u00e9 necess\u00e1rio escolher uma chave SSH que ser\u00e1 usada para efetuar login remoto. Se j\u00e1 tiver uma chave, use ela. Caso contrario pode criar uma. Ap\u00f3s salvar a chave de acesso clique no \u201cLaunch Instances\u201d:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-025.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-025-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>27 &#8211; Ser\u00e1 apresentada a tela abaixo confirmando que a instancia est\u00e1 sendo criada e iniciada.<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-026.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-026-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>28 &#8211; Apos as duas instancias criadas, ambas aparecer\u00e3o no menu de &#8220;Instances&#8221; com o status &#8220;running&#8221; e &#8220;Status Checks&#8221; verde:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-027.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-027-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>29 &#8211; Clique no bot\u00e3o de &#8220;Launch Instance&#8221; novamente. Clique no &#8220;AWS Marketplace&#8221; e na barra de procura digite &#8220;pfsense&#8221;. Ao apertar o &#8220;Enter&#8221; ser\u00e1 exibido o resultado da busca. Clique no bot\u00e3o &#8220;Select&#8221; da op\u00e7\u00e3o &#8220;pfSense&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-028.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-028-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>30 &#8211; Ser\u00e1 exibida a tela com as instancias sugeridas pelo fabricante, o valor por hora do software, infra da AWS e total ser\u00e3o apresentados. clique no &#8220;Continue&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-029.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-029-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>31 &#8211; Para efeito desse tutorial o tipo minimo que atende \u00e9 o &#8220;t2.small&#8221; que \u00e9 a menor instancia que suporta 3 interfaces de rede &#8211; uma publica e duas privadas. Selecione o tipo desejado e clique no Next: Configure Instance Details\u201d:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-030.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-030-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>32 &#8211; Altere o campo de \u201cSubnet\u201d para selecionar a rede publica. Repare que o segundo campo \u00e9 o nome que foi definido para a rede. O \u201cAuto-assign Public IP\u201d deve ficar em \u201cEnable\u201d por se tratar da rede publica e pode marcar a op\u00e7\u00e3o de \u201cEnable termination protection\u201d para n\u00e3o excluir a VM durante os testes em vez de desligar. Finalizado isso, clique em \u201cNext: Add Storage\u201d:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-031.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-031-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>33 \u2013 Nessa tela pode deixar no padr\u00e3o. Os 8GB de disco j\u00e1 s\u00e3o suficientes at\u00e9 para ambiente de produ\u00e7\u00e3o a n\u00e3o ser que sejam usadas algumas fun\u00e7\u00f5es mais avan\u00e7adas como log, cache ou captura de trafego. Clique no \u201cNext: Add Tags\u201d:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-032.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-032-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>34 &#8211; Para ambiente de testes n\u00e3o precisa adicionar nenhuma tag a VM. Clique no \u201cNext: Configure Security Group\u201d<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-033.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-033-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>35 &#8211; Escolha o grupo de seguran\u00e7a que criamos. Ele vai permitir todo o trafego de entrada e sa\u00edda. Ao finalizar, clique no \u201cReview and Launch\u201d:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-034.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-034-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>36 &#8211; Ser\u00e1 apresentada uma tela com as informa\u00e7\u00f5es da instancia a ser criada\/lan\u00e7ada. Clique no \u201cLaunch\u201d;<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-035.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-035-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>37 &#8211; Antes de iniciar a instancia \u00e9 necess\u00e1rio escolher uma chave SSH que ser\u00e1 usada para efetuar login remoto. Se j\u00e1 tiver uma chave, use ela. Caso contrario pode criar uma. Ap\u00f3s salvar a chave de acesso clique no \u201cLaunch Instances\u201d:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-036.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-036-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>38 &#8211; Ser\u00e1 apresentada a tela abaixo confirmando que a instancia est\u00e1 sendo criada e iniciada.<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-037.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-037-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>39 &#8211; Ao finalizar a cria\u00e7\u00e3o da instancia o pfSense vai aparecer na lista com o status &#8220;running&#8221;. Anote os endere\u00e7os IPv4 de cada instancia que aparecem na coluna &#8220;Private IP Address&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-038.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-038-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>40 &#8211; Aguarde aproximadamente 5 minutos e clique na instancia do pfSense. Observe nas propriedades que s\u00e3o exibidas na parte de baixo da tela o campo &#8220;IPv4 Public IP&#8221;. Este endere\u00e7o \u00e9 atribu\u00eddo dinamicamente a instancia toda vez que ela \u00e9 iniciada. Nos passos posteriores vamos fixar o IP. Por agora apenas clique o bot\u00e3o direito na instancia do pfSense, escolha o &#8220;Instance Settings&#8221; e depois &#8220;Get System Log&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-039.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-039-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>41 &#8211; Na tela do &#8220;System Log&#8221; v\u00e1 ate o final e anote a senha informada do &#8220;ec2-user&#8221;.\u00a0 Esta senha \u00e9 gerada aleatoriamente toda vez que a instancia \u00e9 iniciada enquanto n\u00e3o for realizada a primeira configura\u00e7\u00e3o:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-040.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-040-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>42 &#8211; Abra um browser e acesse o IP que aparece no &#8220;IPv4 Public IP&#8221; do passo 40 via https. Vai ser apresentada a tela informando que o certificado n\u00e3o \u00e9 confi\u00e1vel:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-041.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-041-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>43 &#8211; Ao aceitar o certificado ser\u00e1 exibida a tela de login. No primeiro login entre com &#8220;ec2-user&#8221; e a senha que foi anotada no passo 41. Se nesse meio tempo a instancia foi reiniciada \u00e9 necess\u00e1rio verificar novamente qual a senha que foi gerada:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-042.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-042-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>44 &#8211; Apenas clique no &#8220;Next&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-043.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-043-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>45 &#8211; Apenas clique no &#8220;Next&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-044.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-044-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>46 &#8211; Informe hostname, dom\u00ednio e servidores de DNS que quer usar. Se deixar o &#8220;Override DNS&#8221; ser\u00e3o usados os DNSs que o DHCP da AWS fornecer. Clique no &#8220;Next&#8221;::<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-045.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-045-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>47 &#8211; Selecione o timezone que deseja usar e clique no &#8220;Next&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-046.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-046-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>48 &#8211; Defina uma senha para o usu\u00e1rio &#8220;admin&#8221; e clique no &#8220;Next&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-047.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-047-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>49 &#8211; Clique no &#8220;Reload&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-048.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-048-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>50 &#8211; Aguarde ate a configura\u00e7\u00e3o seja aplicada:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-049.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-049-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>51 &#8211; Clique no &#8220;Finish&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-050.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-050-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>52 &#8211; Ser\u00e1 exibido o dashboard do pfSense. Repare que existe somente uma interface que \u00e9 a &#8220;WAN&#8221;.<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-051.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-051-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>53 &#8211; Volte ao console da AWS e na lista de instancias clique o bot\u00e3o direito no pfSense, clique em &#8220;Instance State&#8221; e depois em &#8220;Stop&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-052.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-052-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>54 &#8211; Confirme o desligamento:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-053.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-053-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>55 &#8211; Clique no menu &#8220;Network Interfaces&#8221; e em seguida no bot\u00e3o &#8220;Create Network Interface&#8221;. Especifique um nome em &#8220;Description&#8221; e escolha a primeira rede privada:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-054.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-054-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>56 &#8211; Em &#8220;IPv4 Private IP&#8221; escolha &#8220;Custom&#8221; e informe o endere\u00e7o IP que vai atribuir a interface do firewall nessa rede. N\u00e3o podem ser usados os endere\u00e7os .1, .2 e .3 pois s\u00e3o reservados para uso da pr\u00f3pria AWS. Em &#8220;Security groups&#8221; escolha o grupo criado no passo 8:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-055.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-055-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>57 &#8211; A interface aparecera na lista com o campo &#8220;Instance ID&#8221; vazio. Repita os passos para cria\u00e7\u00e3o da segunda interface privada a ser adicionada no pfSense. Clique no bot\u00e3o \u201cCreate Network Interface\u201d:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-056.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-056-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>58 &#8211; Especifique um nome em \u201cDescription\u201d e escolha a segunda rede privada:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-057.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-057-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>59 &#8211; Em \u201cIPv4 Private IP\u201d escolha \u201cCustom\u201d e informe o endere\u00e7o IP que vai atribuir a interface do firewall nessa rede. N\u00e3o podem ser usados os endere\u00e7os .1, .2 e .3 pois s\u00e3o reservados para uso da pr\u00f3pria AWS. Em \u201cSecurity groups\u201d escolha o grupo criado no passo 8:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-058.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-058-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>60 &#8211; Volte no console da AWS na op\u00e7\u00e3o de &#8220;VPC&#8221; e entre no menu de &#8220;Elastic IPs&#8221;. Clique no bot\u00e3o &#8220;Allocate new address&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-059.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-059-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>61 &#8211; Deixe selecionado em escopo &#8220;VPC&#8221; e &#8220;Amazon pool&#8221;. Clique no &#8220;Allocate&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-060.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-060-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>62 &#8211; Ser\u00e1 alocado um IPv4 v\u00e1lido e exibido na lista. Clique o bot\u00e3o direito nele e escolha a op\u00e7\u00e3o de &#8220;Associate address&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-061.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-061-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>63 &#8211; Deixe marcado o &#8220;Resource type&#8221; como &#8220;Instance&#8221; e escolha o pfSense na lista das instancias:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-062.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-062-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>64 &#8211; no campo &#8220;Private IP&#8221; escolha o \u00fanico IP que deve aparecer:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-063.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-063-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>65 &#8211; Clique no bot\u00e3o &#8220;Associate&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-064.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-064-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>66 &#8211; O endere\u00e7o valido vai aparecer como associado ao IP da interfaces publica do pfSense:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-065.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-065-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>67 &#8211; Volte para o menu &#8220;Network Interfaces&#8221; da op\u00e7\u00e3o EC2 e clique o bot\u00e3o direito na interface da primeira rede privada. Repare e anote o &#8220;MAC address&#8221; da interface. Clique em &#8220;Attach&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-066.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-066-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>68 &#8211; Escolha a instancia do pfSense e clique no bot\u00e3o &#8220;Attach&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-067.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-067-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>69 &#8211; Repita a opera\u00e7\u00e3o para a segunda interface. Clique o bot\u00e3o direito na interface da segunda rede privada. Repare e anote o &#8220;MAC address&#8221; da interface. Clique em &#8220;Attach&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-068.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-068-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>70 &#8211; Escolha a instancia do pfSense e clique no bot\u00e3o &#8220;Attach&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-069.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-069-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>71 &#8211; Ambas as interfaces privadas agora estar\u00e3o associadas com a instancia do pfSense.<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-070.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-070-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>72 &#8211; Volte para o menu &#8220;Instances&#8221;, clique o bot\u00e3o direito no pfSense, v\u00e1 em &#8220;Instance State&#8221; e clique no &#8220;Start&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-071.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-071-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>73 &#8211; Clique o bot\u00e3o direito do mouse na instancia da primeira rede privada, v\u00e1 em &#8220;Networking&#8221; e selecione a op\u00e7\u00e3o de &#8220;Change Source\/Dest. Check&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-072.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-072-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>74 &#8211; Clique no &#8220;Yes, Disable&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-073.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-073-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>75 &#8211; Clique o bot\u00e3o direito do mouse na instancia da segunda rede privada, v\u00e1 em &#8220;Networking&#8221; e selecione a op\u00e7\u00e3o de &#8220;Change Source\/Dest. Check&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-074.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-074-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>76 &#8211; Clique no &#8220;Yes, Disable&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-075.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-075-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>77 &#8211; Clique o bot\u00e3o direito do mouse na instancia do pfSense, v\u00e1 em &#8220;Networking&#8221; e selecione a op\u00e7\u00e3o de &#8220;Change Source\/Dest. Check&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-076.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-076-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>78 &#8211; Clique no &#8220;Yes, Disable&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-077.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-077-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>79 &#8211; Inicie a instancia do pfSense clicando o bot\u00e3o direito nela e escolhendo &#8220;Start&#8221; no &#8220;Instance State&#8221;. Aguarde at\u00e9 o status mudar para &#8220;running&#8221; e &#8220;Status Checks&#8221; ficar verde. Apos isso abra um browser e acesse o IP que foi alocado no passo 62. Apos logar v\u00e1 em &#8220;Interfaces&#8221; e depois em &#8220;Assignments&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-078.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-078-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>80 &#8211; Em &#8220;Available network ports&#8221; escolha a interface com o MAC address do passo 67 e clique no &#8220;Add&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-079.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-079-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>81 &#8211; Sera criada a interface &#8220;LAN&#8221;. Repita o passo anterior para adicionar a segunda interface. Em &#8220;Available network ports&#8221; escolha a interface com o MAC address do passo 69 e clique no &#8220;Add&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-080.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-080-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>81 &#8211; Sera criada a interface &#8220;OPT1&#8221;.<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-081.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-081-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>82 &#8211; Clique na interface &#8220;LAN&#8221;. Ative a interface marcando &#8220;Enable Interface&#8221;, troque o nome para &#8220;LAN1&#8221; e em &#8220;IPv4 Configuration Type&#8221; escolha &#8220;Static IPv4&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-082.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-082-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>83 &#8211; Em &#8220;IPv4 Address&#8221; informe o ip\u00a0 do passo 56 e cloque no bot\u00e3o &#8220;Save&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-083.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-083-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>84 &#8211; Volte para a tela de &#8220;Assignments&#8221; e clique na interface &#8220;OPT1&#8221;. Ative a interface marcando &#8220;Enable Interface&#8221;, troque o nome para &#8220;LAN2&#8221; e em &#8220;IPv4 Configuration Type&#8221; escolha &#8220;Static IPv4&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-084.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-084-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>85 &#8211; Em &#8220;IPv4 Address&#8221; informe o ip\u00a0 do passo 59 e cloque no bot\u00e3o &#8220;Save&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-085.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-085-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>86 &#8211; Cloque no logo do pfSense para voltar para o dashboard. Repare que na lista de interfaces agora aparecem as 3 interfaces de rede:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-086.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-086-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>87 &#8211; Clique no menu de &#8220;Diagnostics&#8221; e escolha\u00a0 op\u00e7\u00e3o de &#8220;Ping&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-087.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-087-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>88 &#8211; Informe o IP da instancia da primeira rede privada do passo 39 e clique no bot\u00e3o &#8220;Ping&#8221;. Em &#8220;Results&#8221; deve aparecer a resposta:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-088.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-088-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>89 &#8211; Informe o IP da instancia da segunda rede privada do passo 39 e clique no bot\u00e3o &#8220;Ping&#8221;. Em &#8220;Results&#8221; deve aparecer a resposta:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-089.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-089-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>90 &#8211; As instancias das redes privadas n\u00e3o podem ser acessadas diretamente da Internet. Para isso deve ser usada a chave de conex\u00e3o do passo 17. Primeiramente acesse o pfSense usando a chave:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-090.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-090-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>91 &#8211; Copie a chave para o pfSense e depois acesse a instancia da primeira rede privada. Para alterar as configura\u00e7\u00f5es de rede, edite o arquivo da interface:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-091.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-091-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>92 &#8211; Ajuste o arquivo de acordo com a necessidade, informando no par\u00e2metro &#8220;GATEWAY&#8221; o IP do pfSense. No &#8220;IPADDR&#8221; use o IP que a maquina pegou no DHCP:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-092.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-092-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>93 &#8211; Assim que terminar a altera\u00e7\u00e3o da configura\u00e7\u00e3o da interface recarregue a rede com o comando &#8220;service network restart&#8221;, confira a tabela de roteamento com &#8220;route -n&#8221; e os IPs da interfaces de rede com &#8220;ip addr&#8221;. Repita o mesmo procedimento na VM da segunda rede privada:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-093.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-093-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>94 &#8211; Volte para o pfSense, entre no menu &#8220;Firewall&#8221;, escolha &#8220;NAT&#8221; e por fim o &#8220;Outbound&#8221;. Selecione a op\u00e7\u00e3o &#8220;Manual Outbound NAT rule generation. (AON &#8211; Advanced Outbound NAT)&#8221; e clique no bot\u00e3o &#8220;Save&#8221;. Exclua todas as regras de NAT que existirem.<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-094.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-094-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>95 &#8211; Clique em um dos bot\u00f5es &#8220;Add&#8221; e preencha os campos de acordo com os dois screenshots abaixo:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-095.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-095-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-096.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-096-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>96 &#8211; Ao finalizar a cria\u00e7\u00e3o, a tela de NAT exibir\u00e1 apenas a regra rec\u00e9m criada:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-097.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-097-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>97 &#8211; Entre no menu \u201cNetwork Interfaces\u201d e desabilite o \u201cChange Source\/Dest. Check\u201d das interface do pfSense que foram criadas para as redes privadas. Para isso clique o bot\u00e3o direito na interface, em seguida clique no \u201cChange Source\/Dest. Check\u201d e depois marque &#8220;Disabled&#8221;.\u00a0 Por fim clique no &#8220;Save&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-098.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-098-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-099.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-099-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-100.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-100-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-101.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-101-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>98 &#8211; Volte para o console da AWS, Entre no &#8220;VPC&#8221; e depois no &#8220;Route Tables&#8221;. Clique no &#8220;Create route table&#8221;. Defina um nome e selecione a sua VPC. Clique no &#8220;Create&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-102.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-102-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>99 &#8211; Apos criada a tabela de roteamento, clique na aba &#8220;Routes&#8221; e em &#8220;Edit routes&#8221;<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-103.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-103-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>100 &#8211; Clique no &#8220;Add route&#8221;, em &#8220;Destination&#8221; informe &#8220;0.0.0.0\/0&#8221; e em &#8220;Target&#8221; selecione &#8220;Network Interface&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-104.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-104-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>101 &#8211; Ser\u00e1 exibida a lista de interfaces existentes. Como essa tabela de roteamento ser\u00e1 para a primeira rede privada ( 10.255.1.0\/24 ), selecione a interface do pfSense correspondente a esta rede. Clique em &#8220;Save routes&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-105.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-105-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>102 &#8211; Ap\u00f3s a tabela de roteamento criada, clique o bot\u00e3o direito nela e selecione &#8220;Edit subnet associations&#8221;<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-106.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-106-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>103 &#8211; Na tela de subnets, selecione a primeira rede privada ( 10.255.1.0\/24 ) e clique em &#8220;Save&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-107.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-107-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>104 &#8211; A tabela de roteamento aparecer\u00e1 como associada na coluna &#8220;Explicit subnet association&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-108.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-108-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>105 &#8211; Repita o processo para a segunda rede privada.. Clique no &#8220;Create route table&#8221;. Defina um nome e selecione a sua VPC. Clique no &#8220;Create&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-109.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-109-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>106 &#8211; Apos criada a tabela de roteamento, clique na aba &#8220;Routes&#8221; e em &#8220;Edit routes&#8221;<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-111.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-111-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>107 &#8211; Clique no \u201cAdd route\u201d, em \u201cDestination\u201d informe \u201c0.0.0.0\/0\u201d e em \u201cTarget\u201d selecione \u201cNetwork Interface\u201d:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-112.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-112-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>108 &#8211; Ser\u00e1 exibida a lista de interfaces existentes. Como essa tabela de roteamento ser\u00e1 para a segunda rede privada ( 10.255.2.0\/24 ), selecione a interface do pfSense correspondente a esta rede. Clique em &#8220;Save routes&#8221;:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-113.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-113-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>109 \u2013 Ap\u00f3s a tabela de roteamento criada, clique o bot\u00e3o direito nela e selecione \u201cEdit subnet associations\u201d<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-116.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-116-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>110 &#8211; Na tela de subnets, selecione a segunda rede privada ( 10.255.2.0\/24 ) e clique em \u201cSave\u201d:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-117.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-117-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>111 &#8211; A tabela de roteamento aparecer\u00e1 como associada na coluna \u201cExplicit subnet association\u201d:<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-118.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-118-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>112 &#8211; Por fim volte no console do pfSense, sno menu &#8220;Firewall&#8221; selecione &#8220;Rules&#8221; e crie as regras de libera\u00e7\u00e3o desejadas nas interfaces LAN1 e LAN2. \u00c9 necess\u00e1rio criar apenas as regras de libera\u00e7\u00e3o, pois por padr\u00e3o o pfSense nega qualquer solicita\u00e7\u00e3o. Nesse exemplo os dois servidores das redes privadas podem sair para qualquer destino.<\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-119.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-119-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-120.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-273 size-large\" src=\"https:\/\/www.tonev.pro.br\/wp-content\/uploads\/2020\/03\/aws_pfsense-120-700x394.png\" alt=\"\" width=\"700\" height=\"394\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Documenta\u00e7\u00e3o sugerida:<\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/pt_br\/AWSEC2\/latest\/UserGuide\/ec2-key-pairs.html\" target=\"_blank\" rel=\"noopener noreferrer\">Pares de chaves do Amazon EC2<\/a><\/p>\n<p><a href=\"https:\/\/docs.aws.amazon.com\/pt_br\/AWSEC2\/latest\/UserGuide\/using-eni.html\" target=\"_blank\" rel=\"noopener noreferrer\">Interfaces de rede el\u00e1stica<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Muitas pessoas acham que a solu\u00e7\u00e3o m\u00e1gica para os problemas de infra estrutura \u00e9 a migra\u00e7\u00e3o para &#8220;a nuvem&#8221;.\u00a0 A realidade n\u00e3o \u00e9 bem essa. Quando voc\u00ea migra os servidores da sua rede para a&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,7,2],"tags":[],"class_list":["post-393","post","type-post","status-publish","format-standard","hentry","category-amazon","category-pfsense","category-rede"],"_links":{"self":[{"href":"https:\/\/www.tonev.pro.br\/index.php?rest_route=\/wp\/v2\/posts\/393","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tonev.pro.br\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tonev.pro.br\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tonev.pro.br\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tonev.pro.br\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=393"}],"version-history":[{"count":41,"href":"https:\/\/www.tonev.pro.br\/index.php?rest_route=\/wp\/v2\/posts\/393\/revisions"}],"predecessor-version":[{"id":436,"href":"https:\/\/www.tonev.pro.br\/index.php?rest_route=\/wp\/v2\/posts\/393\/revisions\/436"}],"wp:attachment":[{"href":"https:\/\/www.tonev.pro.br\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=393"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tonev.pro.br\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=393"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tonev.pro.br\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=393"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}