pfSense Firewall Connectivity Pattern
Last updated on
Overview
Section titled “Overview”This asset describes how the STACKIT Quick Deployment pfSense firewall can be used as a reusable connectivity control point in migration landing zones.
It is especially relevant for hub-and-spoke network designs where multiple projects connect through a central security and routing layer.
Primary use context
Section titled “Primary use context”- Network Area governance: A shared enterprise network is centrally governed and projects are attached in a controlled way.
- Routing Tables design: Routing behavior between projects is explicitly steered through approved route patterns.
- Connectivity controls: Security domains, inspection points, and north-south / east-west flow controls are defined before onboarding workloads.
Product reference
Section titled “Product reference”- STACKIT Quick Deployments pfSense firewall: Documentation
Review the STACKIT deployment inputs before using the appliance in a migration landing zone. Protect service-account key files and review the required permissions against your automation policy. Deployment preparation does not replace route design or firewall-rule approval.
For the pfSense installation please download the GitHub repository containing the deployment scripts for Terraform.
Terraform is going to create these networks vpc_network and wan_network the subnets for the VPC and WAN network get provisioned automatically.
In the file [01-config.tf](http://01-config.tf/) are settings such as the Availability Zone, Network ranges or the VM size (Machine Type) which can all be changed.
Configuration options:
- Project ID (required)
- Availability Zone
- Machine Type
- Network Range & IP Address
To create a service account and grant admin permissions refer to the Service account documentation.
You also need to Create a service account key as described and save the output as JSON into the secrets.json (overwrite all the content in the file).
The versions can be retrieved from the image repository: https://pfsense.object.storage.eu01.onstackit.cloud/index.html
What is this?
This section is copied from the STACKIT docs automatically, several times a day. It cannot be changed here. Changes belong in the STACKIT docs.
When to use
Section titled “When to use”- Central firewall requirement: You need an explicit inspection and control point between spokes and shared services.
- Migration phase isolation: Different migration waves require controlled inter-project communication.
- Hybrid integration path: Connectivity to external environments must be structured and auditable.
Implementation note
Section titled “Implementation note”Use this asset as a connectivity building block within the broader landing zone network architecture, together with Network Area, Routing Tables, DNS, and VPN standards.
Asset historyActive 5 of the last 12 weeksTMUpdatedNo updates · 1 bar = 1 week i
- LWLukas WeberrußHead of STACKIT Cloud Migration Framework · STACKITOwner
Lukas WeberrußHead of STACKIT Cloud Migration Framework · STACKITOwnerActive 10 of the last 12 weeks · 47 updateswww.linkedin.com/in/lukas-weberruß-a360b081