Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Is there a way to log all SMTP traffic?

    General pfSense Questions
    3
    6
    2.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jnml
      last edited by

      Our outgoing email traffic seems to be blocked by our ISP and/or by Google, ie. we cannot send to any gmail address. We would like to verify/monitor that none of our company computers is sending spam. I'm looking for advice on getting SMTP traffic logs in our pfSense box. If that needs paid support, we will probably buy it - boss said.

      Thanks in advance for any information.

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by

        Is the switch that connects to your router able to port mirror / span ?

        If it is set it up connect a laptop to the mirror / span port and do a wireshark capture.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          you sure do not need to do this with a spam port.. If you want to log all outbound traffic to smtp (25) then you could either just do the packet capture on pfsense directly.  Or you could just setup a rule that logs smtp 25 and either blocks it which would be the best thing.  Its rare that clients in a work setup would directly need to talk outbound on 25.

          So on your interface(s) that clients talk to pfsense to go to the internet just setup a rule on the top that blocks 25 and logs it.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • J
            jnml
            last edited by

            @johnpoz:

            you sure do not need to do this with a spam port.. If you want to log all outbound traffic to smtp (25) then you could either just do the packet capture on pfsense directly.  Or you could just setup a rule that logs smtp 25 and either blocks it which would be the best thing.  Its rare that clients in a work setup would directly need to talk outbound on 25.

            So on your interface(s) that clients talk to pfsense to go to the internet just setup a rule on the top that blocks 25 and logs it.

            Thank you! Added rules: block+log :25, log :587.

            1 Reply Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad
              last edited by

              I assumed you had a server on site that used SMTP.

              Mentioned a span port as wireshark could just be left to run and save multiple files, you could just leave it running for a week or more.

              But yes blocking and logging will work.

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                "log :587."

                I find it highly unlikely that spam would be using port 587.. Unless the user was sending it on purpose through a smart host and authing to the smart host as well.  This would not be tracked back to your IP.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.