Network Architecture & Design
Three-Zone Architecture
WAN ZONE (Upstream Internet - Disconnected) | pfSense Firewall (Suricata IDS) | LAN ZONE (192.168.1.0/24)
- Kali (192.168.1.105)
- Ubuntu (192.168.1.110)
Zone Definitions
WAN Zone
- Purpose: Upstream connectivity (disconnected during testing)
- Devices: External networks (disconnected for isolation)
- Access: None during testing
Firewall Zone
- Purpose: Network perimeter defense and intrusion detection
- Devices: pfSense 2.8.1 running Suricata 7.0
- Function: Packet inspection, rule enforcement, alert generation
LAN Zone
- Purpose: Isolated lab environment for attack-defend simulation
- Devices:
- Kali Linux (192.168.1.105) - Attacker
- Ubuntu 22.04 (192.168.1.110) - Target with Juice Shop
- Network: 192.168.1.0/24 with pfSense as gateway
Access Control Policies
From Kali to Ubuntu: All traffic allowed (unrestricted for attack simulation)
Suricata IDS: Sees all LAN traffic, generates alerts on rule matches
Firewall Rules: Minimal (lab environment), focused on detection rather than blocking
Principle of Least Privilege
- Each VM has only necessary services running
- Kali: Attack tools only (no production services)
- Ubuntu: Juice Shop only (no unnecessary applications)
- pfSense: Firewall + IDS only (no extra services)
- Network isolation: Lab separated from host network via bridged interface
Defense-in-Depth
Application Layer: Input validation, extension whitelists, access control checks
Network Layer: Firewall rules, traffic inspection, anomaly detection
Detection Layer: Custom Suricata signatures, behavioral thresholds, alert correlation
Environmental Notes
Platform: macOS Apple Silicon M1, UTM virtualization
Network Mode: Bridged (allows VM-to-VM communication while maintaining isolation)
Operational Security: WAN adapter disabled during testing to prevent lab traffic reaching production
Last Updated: August 2, 2026 Platform: macOS Apple Silicon M1, UTM virtualization
Network Mode: Bridged (allows VM-to-VM communication while maintaining isolation)
Operational Security: WAN adapter disabled during testing to prevent lab traffic reaching production
Last Updated: August 2, 2026