Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Alias Native Logging

    Scheduled Pinned Locked Moved pfBlockerNG
    38 Posts 3 Posters 4.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RonpfSR
      RonpfS @MORGiON
      last edited by

      @morgion I guess the reports only search for Auto Rules as it has no way to figure out what are the FWRule TrackerIDs of your rules 😞

      2.4.5-RELEASE-p1 (amd64)
      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

      MORGiONM 1 Reply Last reply Reply Quote 1
      • MORGiONM
        MORGiON @RonpfS
        last edited by MORGiON

        @ronpfs That would be my guess, though It used to work pre development version, you just had to ensure logging was enabled for that rule. Im hoping its a bug that BBcan117 will get around to one day. if not it still works great and pfSense/pfBlocker is a fantastic product.

        here is a pic of the pfBlocker reports fyi

        0_1527468571390_Untitled 2.png

        RonpfSR 1 Reply Last reply Reply Quote 0
        • RonpfSR
          RonpfS @MORGiON
          last edited by RonpfS

          @morgion You can check that the 77.72.82.71 (or 77.72.82 or 77.72.) is in you Permit/Deny/Match/Native db with something like

          grep "^77.72.82" /var/db/pfblockerng/permit/*.txt  /var/db/pfblockerng/original/*.orig
          

          2.4.5-RELEASE-p1 (amd64)
          Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
          Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

          MORGiONM 1 Reply Last reply Reply Quote 1
          • RonpfSR
            RonpfS
            last edited by RonpfS

            @BBcan17 said in [Email] :
            In Extra Options, change the Description to something that start with "pfb_"

            2.4.5-RELEASE-p1 (amd64)
            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

            MORGiONM 1 Reply Last reply Reply Quote 1
            • MORGiONM
              MORGiON @RonpfS
              last edited by

              @ronpfs said in Alias Native Logging:

              grep “^77.72.82” /var/db/pfblockerng/permit/.txt /var/db/pfblockerng/original/.orig

              grep: /var/db/pfblockerng/permit/.txt: No such file or directory
              grep: /var/db/pfblockerng/original/.orig: No such file or directory

              RonpfSR 1 Reply Last reply Reply Quote 0
              • RonpfSR
                RonpfS @MORGiON
                last edited by RonpfS

                @morgion said in Alias Native Logging:

                @ronpfs said in Alias Native Logging:

                grep “^77.72.82” /var/db/pfblockerng/permit/.txt /var/db/pfblockerng/original/.orig

                grep: /var/db/pfblockerng/permit/.txt: No such file or directory
                grep: /var/db/pfblockerng/original/.orig: No such file or directory

                Oups missing 2 "*" because I did'nt use a </> Code block 😮

                grep “^77.72.82” /var/db/pfblockerng/permit/*.txt  /var/db/pfblockerng/original/*.orig
                

                2.4.5-RELEASE-p1 (amd64)
                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                MORGiONM 1 Reply Last reply Reply Quote 1
                • MORGiONM
                  MORGiON @RonpfS
                  last edited by

                  @ronpfs said in Alias Native Logging:

                  rep “^77.72.82” /var/db/pfblockerng/permit/.txt /var/db/pfblockerng/original/.orig

                  No output

                  RonpfSR 2 Replies Last reply Reply Quote 0
                  • MORGiONM
                    MORGiON @RonpfS
                    last edited by

                    @ronpfs said in Alias Native Logging:

                    @BBcan17 said in [Email] :
                    In Extra Options, change the Description to something that start with "pfb_"

                    No effect

                    RonpfSR 1 Reply Last reply Reply Quote 0
                    • RonpfSR
                      RonpfS @MORGiON
                      last edited by RonpfS

                      @morgion said in Alias Native Logging:

                      @ronpfs said in Alias Native Logging:

                      @BBcan17 said in [Email] :
                      In Extra Options, change the Description to something that start with "pfb_"

                      No effect

                      Maybe do a Force Reload IP 😖

                      Restart the pfBlockerNG firewall filter service 😕

                      2.4.5-RELEASE-p1 (amd64)
                      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                      1 Reply Last reply Reply Quote 1
                      • RonpfSR
                        RonpfS @MORGiON
                        last edited by RonpfS

                        @morgion said in Alias Native Logging:

                        @ronpfs said in Alias Native Logging:

                        rep “^77.72.82” /var/db/pfblockerng/permit/.txt /var/db/pfblockerng/original/.orig

                        No output

                        grep “^77.72.” /var/db/pfblockerng/permit/*.txt  /var/db/pfblockerng/original/*.orig
                        

                        It maybe in a big block range.

                        If you go further down in the Alerts Tab (maybe change the settings to get more alerts) was it in a table as some point in time?

                        2.4.5-RELEASE-p1 (amd64)
                        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                        MORGiONM 1 Reply Last reply Reply Quote 1
                        • MORGiONM
                          MORGiON @RonpfS
                          last edited by MORGiON

                          @ronpfs

                          Still no output from grep

                          Alerts tab

                          May 28 11:41:32 WAN pfB_PRI1_v4
                          (1770009104) TCP-S 77.72.82.71:59854
                          hostby.ups-gb.co.uk     xxx.xxx.xxx.xxx:59599 
                          GB ET_Block_v4
                          77.72.82.0/24

                          get hit by this one a lot so didn't have to look far, not unknown anymore. also doing full reload now

                          EDIT: Full reload didn't help ☹

                          RonpfSR 1 Reply Last reply Reply Quote 0
                          • RonpfSR
                            RonpfS @MORGiON
                            last edited by RonpfS

                            @morgion said in Alias Native Logging:

                            doing full reload now

                            If your Permit rules don't generate alerts, try to restart the pfBlockerNG firewall filter service.

                            You can also peek at the ip_permit.log file.

                            2.4.5-RELEASE-p1 (amd64)
                            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                            MORGiONM 1 Reply Last reply Reply Quote 1
                            • MORGiONM
                              MORGiON @RonpfS
                              last edited by

                              @ronpfs said in Alias Native Logging:

                              @morgion said in Alias Native Logging:

                              doing full reload now

                              If your Permit rules don't generate alerts, try to restart the pfBlockerNG firewall filter service.

                              You can also peek at the ip_permit.log file.

                              Restarted pfBlocker Firewall Filter service, ip_permit.log empty

                              RonpfSR 1 Reply Last reply Reply Quote 0
                              • RonpfSR
                                RonpfS @MORGiON
                                last edited by

                                @morgion said in Alias Native Logging:

                                @ronpfs said in Alias Native Logging:

                                rep “^77.72.82” /var/db/pfblockerng/permit/.txt /var/db/pfblockerng/original/.orig

                                No output

                                Looks like you don't need the "

                                grep ^77.72.82 /var/db/pfblockerng/*/*.txt  /var/db/pfblockerng/original/*.orig
                                

                                2.4.5-RELEASE-p1 (amd64)
                                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                MORGiONM 1 Reply Last reply Reply Quote 1
                                • MORGiONM
                                  MORGiON @RonpfS
                                  last edited by

                                  @ronpfs said in Alias Native Logging:

                                  grep ^77.72.82 /var/db/pfblockerng//.txt /var/db/pfblockerng/original/*.orig

                                  /var/db/pfblockerng/deny/CINS_army_v4.txt:77.72.82.101
                                  /var/db/pfblockerng/deny/CINS_army_v4.txt:77.72.82.14
                                  /var/db/pfblockerng/deny/CINS_army_v4.txt:77.72.82.19
                                  /var/db/pfblockerng/deny/CINS_army_v4.txt:77.72.82.22
                                  /var/db/pfblockerng/deny/CINS_army_v4.txt:77.72.82.31
                                  /var/db/pfblockerng/deny/ET_Block_v4.txt:77.72.82.0/24
                                  /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.19 # Malicious Host
                                  /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.22 # Malicious Host
                                  /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.72 # Malicious Host
                                  /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.88 # Malicious Host
                                  /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.125 # Malicious Host
                                  /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.59 # Malicious Host
                                  /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.101 # Malicious Host
                                  /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.14 # Malicious Host
                                  /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.48 # Malicious Host
                                  /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.91 # Malicious Host
                                  /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.31 # Malicious Host
                                  /var/db/pfblockerng/original/BDS_Ban_v4.orig:77.72.82.15
                                  /var/db/pfblockerng/original/BDS_Ban_v4.orig:77.72.82.19
                                  /var/db/pfblockerng/original/BlockListDE_All_v4.orig:77.72.82.15
                                  /var/db/pfblockerng/original/BlockListDE_SSH_v4.orig:77.72.82.15
                                  /var/db/pfblockerng/original/CINS_army_v4.orig:77.72.82.101
                                  /var/db/pfblockerng/original/CINS_army_v4.orig:77.72.82.14
                                  /var/db/pfblockerng/original/CINS_army_v4.orig:77.72.82.19
                                  /var/db/pfblockerng/original/CINS_army_v4.orig:77.72.82.22
                                  /var/db/pfblockerng/original/CINS_army_v4.orig:77.72.82.31
                                  /var/db/pfblockerng/original/DangerRulez_v4.orig:77.72.82.15 # 2018-05-27 10:23:33 21 1486391
                                  /var/db/pfblockerng/original/ET_Block_v4.orig:77.72.82.0/24
                                  /var/db/pfblockerng/original/ET_Comp_v4.orig:77.72.82.15
                                  /var/db/pfblockerng/original/GreenSnow_v4.orig:77.72.82.56
                                  /var/db/pfblockerng/original/GreenSnow_v4.orig:77.72.82.14
                                  /var/db/pfblockerng/original/ISC_Block_v4.orig:77.72.82.0 77.72.82.255 24 1342 NETUP-AS , RU aospan@netup.ru
                                  /var/db/pfblockerng/original/SuspectNetworks_v4.orig:77.72.82.0/24

                                  RonpfSR 1 Reply Last reply Reply Quote 0
                                  • RonpfSR
                                    RonpfS @MORGiON
                                    last edited by

                                    @morgion said in Alias Native Logging:

                                    ip_permit.log empty

                                    And you see the Permits in FW Logs ?

                                    2.4.5-RELEASE-p1 (amd64)
                                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                    MORGiONM 1 Reply Last reply Reply Quote 1
                                    • MORGiONM
                                      MORGiON @RonpfS
                                      last edited by

                                      @ronpfs said in Alias Native Logging:

                                      @morgion said in Alias Native Logging:

                                      ip_permit.log empty

                                      And you see the Permits in FW Logs ?

                                      Yes

                                      1 Reply Last reply Reply Quote 0
                                      • RonpfSR
                                        RonpfS @MORGiON
                                        last edited by

                                        @morgion said in Alias Native Logging:

                                        @ronpfs said in Alias Native Logging:

                                        grep ^77.72.82 /var/db/pfblockerng//.txt /var/db/pfblockerng/original/*.orig

                                        /var/db/pfblockerng/deny/CINS_army_v4.txt:77.72.82.101
                                        /var/db/pfblockerng/deny/CINS_army_v4.txt:77.72.82.14
                                        /var/db/pfblockerng/deny/CINS_army_v4.txt:77.72.82.19
                                        /var/db/pfblockerng/deny/CINS_army_v4.txt:77.72.82.22
                                        /var/db/pfblockerng/deny/CINS_army_v4.txt:77.72.82.31
                                        /var/db/pfblockerng/deny/ET_Block_v4.txt:77.72.82.0/24
                                        /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.19 # Malicious Host
                                        /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.22 # Malicious Host
                                        /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.72 # Malicious Host
                                        /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.88 # Malicious Host
                                        /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.125 # Malicious Host
                                        /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.59 # Malicious Host
                                        /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.101 # Malicious Host
                                        /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.14 # Malicious Host
                                        /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.48 # Malicious Host
                                        /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.91 # Malicious Host
                                        /var/db/pfblockerng/original/Alienvault_v4.orig:77.72.82.31 # Malicious Host
                                        /var/db/pfblockerng/original/BDS_Ban_v4.orig:77.72.82.15
                                        /var/db/pfblockerng/original/BDS_Ban_v4.orig:77.72.82.19
                                        /var/db/pfblockerng/original/BlockListDE_All_v4.orig:77.72.82.15
                                        /var/db/pfblockerng/original/BlockListDE_SSH_v4.orig:77.72.82.15
                                        /var/db/pfblockerng/original/CINS_army_v4.orig:77.72.82.101
                                        /var/db/pfblockerng/original/CINS_army_v4.orig:77.72.82.14
                                        /var/db/pfblockerng/original/CINS_army_v4.orig:77.72.82.19
                                        /var/db/pfblockerng/original/CINS_army_v4.orig:77.72.82.22
                                        /var/db/pfblockerng/original/CINS_army_v4.orig:77.72.82.31
                                        /var/db/pfblockerng/original/DangerRulez_v4.orig:77.72.82.15 # 2018-05-27 10:23:33 21 1486391
                                        /var/db/pfblockerng/original/ET_Block_v4.orig:77.72.82.0/24
                                        /var/db/pfblockerng/original/ET_Comp_v4.orig:77.72.82.15
                                        /var/db/pfblockerng/original/GreenSnow_v4.orig:77.72.82.56
                                        /var/db/pfblockerng/original/GreenSnow_v4.orig:77.72.82.14
                                        /var/db/pfblockerng/original/ISC_Block_v4.orig:77.72.82.0 77.72.82.255 24 1342 NETUP-AS , RU aospan@netup.ru
                                        /var/db/pfblockerng/original/SuspectNetworks_v4.orig:77.72.82.0/24

                                        Strange as 77.72.82.0/24 include 77.72.82.1 to 77.72.82.254

                                        Do you have suppression enabled ?

                                        2.4.5-RELEASE-p1 (amd64)
                                        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                        MORGiONM 1 Reply Last reply Reply Quote 1
                                        • MORGiONM
                                          MORGiON @RonpfS
                                          last edited by

                                          @ronpfs Yes but not used (yet)

                                          RonpfSR 1 Reply Last reply Reply Quote 0
                                          • RonpfSR
                                            RonpfS
                                            last edited by RonpfS

                                            Can you run

                                            pfctl -vvsr | grep "pf"
                                            

                                            2.4.5-RELEASE-p1 (amd64)
                                            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                            1 Reply Last reply Reply Quote 1
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.