Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Logging for PCI DSS

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 5 Posters 744 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Stewart
      last edited by

      PCI Compliance requires logging to be stored for 1 year for firewalls with the last 3 months to be readily available.  How do we keep logging history for pfSense and be able to search through it for that long?

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by

        @Stewart:

        PCI Compliance requires logging to be stored for 1 year for firewalls with the last 3 months to be readily available.  How do we keep logging history for pfSense and be able to search through it for that long?

        Set up a syslog server and send the logs there.

        Status -> System Logs -> Settings -> Remote Logging Options

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • S
          Stewart
          last edited by

          @NogBadTheBad:

          @Stewart:

          PCI Compliance requires logging to be stored for 1 year for firewalls with the last 3 months to be readily available.  How do we keep logging history for pfSense and be able to search through it for that long?

          Set up a syslog server and send the logs there.

          Status -> System Logs -> Settings -> Remote Logging Options

          That's what I was afraid of.  It would be nice to just have the logs store locally.  A bonus would be to be able to search it through the interface that's already there but we could always just grep from the cli.

          1 Reply Last reply Reply Quote 0
          • H
            Harvy66
            last edited by

            If you NEED logging to be saved securely, saving it on your firewall is a horrible place. What you want is to save it to another write-only server with regular backups.

            1 Reply Last reply Reply Quote 0
            • S
              Stewart
              last edited by

              @Harvy66:

              If you NEED logging to be saved securely, saving it on your firewall is a horrible place. What you want is to save it to another write-only server with regular backups.

              The issue is when dealing with small networks.  For example, I did a PCI self-audit of a deli yesterday.  Their network consists of the pfSense router, 2 Clover POS stations, and a MacBook that uses Quickbooks online.  To be compliant they need a years worth of firewall logs.  It seems a bit over the top to require them to purchase a separate server to store those logs when the firewall has 120GB of storage sitting there to be filled and an interface that is able to search the existing logs already.  If that's the way it is, then fine, but it sure would be nice to be able to store them locally.

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                It's a firewall not a log server.

                I would think you would also want to log machine data from all of the local devices to accomplish the same PCI compliance goals.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • The Computer GuyT
                  The Computer Guy
                  last edited by

                  Raspberry PI can run as a Syslog Server.

                  So very little costs  ;D

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.