Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to check your outgoing traffic is encrypted

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 4 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tigerblue12
      last edited by

      Hi,

      does any one knows how to check (ensure) your outgoing traffic is encrypted with Pfsense FW?

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        Do a packet capture on WAN (Diagnostics - Packet Capture), download the .cap file and then use Wireshark to check the traffic.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          why would your traffic be encrypted?  Are you going to https site, are you using a vpn?  But yes you can easy look to what pfsense puts on the wire out its wan with simple packet capture

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • T
            tigerblue12
            last edited by

            and if it's encrypted how will I see it's encrypted in the packet capture?

            1 Reply Last reply Reply Quote 0
            • KOMK
              KOM
              last edited by

              Well, that part is up to you to recognize your traffic.  Is it a web page?  An image like a jpg?  What is your specific concern?

              1 Reply Last reply Reply Quote 0
              • T
                tigerblue12
                last edited by

                ok let's do if from the beginning

                I setup an IPsec tunnel with my company and a partner and create both bidirectionnel (in/out) IPSec rules in the IPSec tab
                -tunnel is up
                -I can see outgoing IPSec traffic in the logs on the enc0 interface
                but
                but

                I dont see outgoing IPSec traffic in the logs on the enc0 interface but see it in the LAN interface

                any idea why I dont see my outgoing IPSec traffic in the logs on the enc0 as for incoming IPSec traffic?

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Because traffic is allowed out of an interface by default, without a firewall rule. Thus there is no rule capturing the traffic to log it.
                  It requires a rule on LAN because it's going in on that interface and hence is logged (assuming you've enabled logging on whatever rule you have there).

                  You should see that traffic arriving over the IPSec tunnel is logged on the IPSec interface and not the LAN.

                  The only exception to this are the floating rules which can operate both in and out.

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.