Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Domain Logging Per Client

    Traffic Monitoring
    3
    7
    586
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      Lockie
      last edited by

      Hey,

      I'd like to monitor the traffic on my network, I've blocks in place via pfBlockerNG but I'd still like to review the domains accessed (not the specific URLs, only the high level domain). I was hoping ntopng could help me, the flow feature displays the domains hit by a specific client which is what I need. The only issue is it's only live traffic and what I require is a historical view. From what I can see ntopng provides this option in their very expensive ntopng Enterprise M addition, but that's a bit to price for a household so I'm hoping for other options. Does anyone know of other ways I can achieve this and also have a guide I can reference for step by step setup.

      Many Thanks

      johnpozJ keyserK 2 Replies Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @Lockie
        last edited by johnpoz

        @Lockie pfblocker may be able to do this?? I am not sure I don't use it for blocking, I only use it for aliases that I use in my rules.

        Sounds like your wanting to see what dns client A does, what client B does and what C does and be able to easy filter on a specific client. If so pihole does that very well. And the eyecandy (graphs and such) is pretty. I had been using that since it came out and never switched to pfblocker for my blocking needs because pihole does it so well.

        I know pfblocker can block like pihole, just not clear on the specific reports you can get, etc. nice thing with pfblocker is just runs right on your pfsense.. With pihole you need something else to run it on, either a pi or sim sort of little device, or a vm/docker you run on something else on your network.. I run it on pi, because well I have a few of them ;)

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 0
        • keyserK
          keyser Rebel Alliance @Lockie
          last edited by

          @Lockie You can enable DNS reply logging in pfBlockerNG. That will log all DNS requests done by clients, but nothing is obviosly recorded about traffic and interactions with the requested names. Be aware DNS reply logging created a very active logfile on your disk. It this is a big SSD - no issues, but if you are using a device with a small eMMC or orther less durable flash device, it will wear out rather quickly.

          Love the no fuss of using the official appliances :-)

          L 2 Replies Last reply Reply Quote 0
          • L
            Lockie
            last edited by

            @johnpoz said in Domain Logging Per Client:

            . If so pihole does that very well.

            I did wonder if it did, so on Pihole you can see a clear list of text addresses (domains) that each devices has visited? Perhaps I should try that then. I think I've seen that you can couple it with pfSense.

            1 Reply Last reply Reply Quote 0
            • L
              Lockie @keyser
              last edited by

              @keyser It is running on a SSD so I think this might be ok. Worth a go atleast before I look at pihole.

              Is the setting required "DNS Reply"? Mine is currently set to 20,000. If so, where do I go from there to view the domains?

              Many Thanks

              1 Reply Last reply Reply Quote 0
              • L
                Lockie @keyser
                last edited by

                @keyser I think I might have it. I switched pfblockerng >DNSBL > DNSBL Mode to Unbound python mode. As it notes this will allow logging of DNS Replies, Then in Reports > DNS Reply > Alert Filter. I can define a device by IP to view the domains and times. Perfect! Thanks very much

                keyserK 1 Reply Last reply Reply Quote 0
                • keyserK
                  keyser Rebel Alliance @Lockie
                  last edited by

                  @Lockie happy to help

                  Love the no fuss of using the official appliances :-)

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.