Netgate SG-1000 microFirewall

Author Topic: data loss prevention with pfsense  (Read 173 times)

0 Members and 1 Guest are viewing this topic.

Offline cehviet

  • Newbie
  • *
  • Posts: 1
  • Karma: +0/-0
    • View Profile
data loss prevention with pfsense
« on: March 04, 2018, 04:20:32 am »
I need to configure pfsense to function against data loss:
Users upload files in their local network to the internet via mediafire, googe drive, email attachments, ... (they can still access the site to download files to work), I do not know pfsense Is there such a function?

Offline JKnott

  • Hero Member
  • *****
  • Posts: 1368
  • Karma: +60/-13
    • View Profile
Re: data loss prevention with pfsense
« Reply #1 on: March 04, 2018, 08:44:19 am »
PfSense is a firewall/router.  It has no such function as protecting user data.
This page unintentionally left blank.

Offline johnpoz

  • Hero Member
  • *****
  • Posts: 15731
  • Karma: +1467/-210
  • Not a pfSense employee, they cannot fire me...
    • View Profile
Re: data loss prevention with pfsense
« Reply #2 on: March 04, 2018, 09:08:25 am »
you could do some rules with snort.. But you have to make sure all traffic going through snort was in the clear.. So you would have to do mitm on all https sort connection.. Your best bet is just block services if your worried about users posting stuff up on say dropbox, etc.

You have to make sure user can not just throw the data on their usb stick.  Or for that matter just email the data to outside addresses, and blocking of encrypted attachments, etc.  Or I could just zip my confidential data and leak it out

An actual viable DLP program is very difficult to implement.. First place to start which is difficult for many companies is even classification of their data.  So while you could build your own sort of system using with opensource tools and software.. It will a long and drawn process with many many hours of configuration and setup and then maintaining..

Not something you click install on pfsense package system and look here boss we have a fully functional DLP ;)
- An intelligent man is sometimes forced to be drunk to spend time with his fools.
- Please don't PM me for personal help
- if you want to say thanks applaud or
1x SG-2440 2.4.3-RELEASE (work)
1x SG-3100 2.4.3-RELEASE (work)
1x SG-4860 2.4.3-RELEASE (home)