Nah, nothing that I'd know of…. pfctl -d disabled, pfctl -e re-enables. This would be done automagically anyway after a while.
https://doc.pfsense.org/index.php/Locked_out_of_the_WebGUI#Remotely_Circumvent_Firewall_Lockout_by_Temporarily_Changing_the_Firewall_Rules
Well, I'm not sure what happened, I added a 3rd host to see if I could get that one to work and immediately after doing that, all 3 hosts sync'd successfully.
hey vito for ELK server logs disable first all log capture by default and let pfblockerNG do all the log reporting. Then on Kibana (ELK) you will see the rule it will be filtering for ex: rule 85 is blocking all top IPv4 list while rule 92 is blocking youtube. see pictures
hope this helps im working now on filtering the syslog (system logs for pfsense) but seems hopeless :-[
[image: Clipboarder.2015.09.03-003.png]
[image: Clipboarder.2015.09.03-003.png_thumb]
[image: Clipboarder.2015.09.03-004.png]
[image: Clipboarder.2015.09.03-004.png_thumb]
[image: Clipboarder.2015.09.03-005.png]
[image: Clipboarder.2015.09.03-005.png_thumb]
[image: Clipboarder.2015.09.03-006.png]
[image: Clipboarder.2015.09.03-006.png_thumb]