• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Making sense of the firewall log?

Scheduled Pinned Locked Moved General pfSense Questions
4 Posts 3 Posters 1.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    Mr. Jingles
    last edited by Jun 30, 2013, 10:16 AM

    G'day all  ;D

    My PFS has been running extremely smooth for weeks now; I am again so happy to have gone this route; everything simply works. So once again thank you very much to the community  :P

    I do have a question: when I used the old, retail, firewall/routers in my home, there was always some sort of categorization of firewall log messages that I, a noob in this matters, could simply understand. I don't recall which old machine had it, but one clearly showed 'attack' or 'non-attack'. The current firewall logs (status/system logs/firewall) show information about blocked connections, but no more. Is there a way (preferably via the GUI, as I am a noob  ;D) to see when I am attacked, or port scanned, and such?

    Thank you in advance for your answer  ;),

    Bye,

    6 and a half billion people know that they are stupid, agressive, lower life forms.

    1 Reply Last reply Reply Quote 0
    • D
      doktornotor Banned
      last edited by Jun 30, 2013, 10:53 AM

      There is no way for the packet filter to know what is an attack. The traffic is (basically) allowed or blocked depending on the rules. There are packages to do what you want, such as Snort, coming with loads of false positives, constant babysitting and huge resource consumption. Definitely suitable for "noob".

      1 Reply Last reply Reply Quote 0
      • S
        stephenw10 Netgate Administrator
        last edited by Jun 30, 2013, 12:06 PM

        It's hard to say quite how soho routers determine what is an 'attack' rather than the odd stray packet. pfSense only logs blocked packets by default. Technically you could consider all unsolicited incoming traffic as an attack. Like Doktornotor said a tool like Snort would usually be used to detect traffic patterns that might indicate unwanted activity. You could export the logs to a syslog server and run a log analyser, say fwanalog or hatchet. I'm sure there are other more GUI friendly alternatives. It may be possible to run fwanalog on the pfSense box.  :-\

        Steve

        1 Reply Last reply Reply Quote 0
        • M
          Mr. Jingles
          last edited by Jul 2, 2013, 3:07 PM

          Thank you both for your answer, I will digest it  ;D

          6 and a half billion people know that they are stupid, agressive, lower life forms.

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received