Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Keep More Logs for Firewall Rules

    Scheduled Pinned Locked Moved General pfSense Questions
    9 Posts 3 Posters 975 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      Bambos
      last edited by

      Hello everyone, i would like to keep more firewall logs and i can't find any setting for that besides the log file size. For example:

      This widget is set to show the last 10 logs, and shows only 1.
      74f335c0-700b-4a0f-9745-23a2116854ef-image.png

      This is because there is no more logs, i have checked also in Status -> system logs -> firewall.
      d85a6881-f502-4324-95d1-acf98ffe77dc-image.png

      Any suggestions much appreciated.

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @Bambos
        last edited by

        @bambos did you turn off default logging, what are your firewall rules on your interfaces?

        That is a pass log, maybe that is the only traffic you have seen - source of that traffic is rfc1918.. Did you turn that logging off?

        logs.jpg

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        B 1 Reply Last reply Reply Quote 2
        • B
          Bambos @johnpoz
          last edited by

          @johnpoz hello ! this is ticked (to log) packets matched from default block rules, and also further below is ticked to log from bogon and private networks.

          I don't see how this is a problem, since the logging of this pass rule is happening, (i have enable this by ticking the logging on the firewall rule.

          26436698-9255-4beb-a0be-042c56d71f12-image.png

          As you can see in previous screenshot, we have logged the last entry succesfully but not the previous entry which was 3 hours ago. This is what i'm asking, how to increase this. Is it the log file size under system logs -> firewall -> normal view -> settings icon ?

          2f9ac889-3e41-42a0-a279-ef38fce9b64b-image.png

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @Bambos
            last edited by

            @bambos can we see the rest of your firewall rules? Maybe you put a rule or had a rule that blocked and didn't log.. The source is rfc1918, by default on a wan there is a block rfc1918 rule - if you turned off logging of that - then you wouldn't see that its blocked, etc.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            B 1 Reply Last reply Reply Quote 1
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Yes, you can just increase the log file size there.

              That first screenshot shows only one entry because it's filtered, not because nothing is being logged. In fact enough is being logged that that there are fewer than 3hrs of firewall logs retained by default.

              Steve

              B 1 Reply Last reply Reply Quote 0
              • B
                Bambos @johnpoz
                last edited by

                @johnpoz hello john, yes this is a private APN over 4G , this interface i have it to block bogon but not private, because the use 172.XX range.
                This is all i use

                a98ef45b-4d97-4da5-baf6-8c63977276b0-image.png

                In the logs i have many blocks (bogon) normally.

                28d4cd40-8a89-4eff-9e33-e91bbac7db25-image.png

                There is no issue there. I Just want to have more of that allow rule that i'm interested more.
                If you remember some hours ago we had a log, now there is none.

                4a2d5b26-09d3-473f-84d5-024b9be615c6-image.png

                This is what i'm asking, to get more history of that allow rule.
                (Widget is set to 10), in the firewall logs, if i apply the pass filter on that interface shows none, not even the one we had some hours ago. I hope now is clear.

                1 Reply Last reply Reply Quote 0
                • B
                  Bambos @stephenw10
                  last edited by

                  @stephenw10 Hello Steve, so the blocking logs overflow the maximum file size and then logs start to be overwritten, if i understand correctly ?

                  If we say that we don't care about the blocking logs, can be disabled and keep focus on allow only ?

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @Bambos
                    last edited by

                    @bambos said in Keep More Logs for Firewall Rules:

                    can be disabled and keep focus on allow only ?

                    Yes you can just disable the logging of the bogon and the default.. And then just log via the rules you want.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 1
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      Yes, exactly . The traffic hitting the bogons rule is all going to be that same IGMP I imagine and that's not really at all useful to log. So just stop logging traffic on the bogons rule and you will have far more log space/time.

                      Steve

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.