Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Origin of outbound WAN connection

    Scheduled Pinned Locked Moved General pfSense Questions
    3 Posts 3 Posters 689 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P Offline
      pvols1979
      last edited by

      I know this is probably much more simple than I am trying to make it, but I could use someone to help clarify this.  I am seeing traffic originating from my firewalls WAN address and making outbound connections to adware sites.  I know for a fact that this traffic is from a machine on the LAN.  I am not currently running a proxy on the firewall.  Without a proxy, is there anyway to tie that traffic back to the originating host on my LAN?

      Let Your Geek Hangout
      Geekzweb.com

      1 Reply Last reply Reply Quote 0
      • B Offline
        Biscuitsntea
        last edited by

        Go to Diagnostics>pfTop

        You can view your active connections by IP Pair. You may need to increase the "Maximum # of States"

        Also, consider installing pfTopNG package. It will give you a GUI of your traffic flow and logging capability.

        1 Reply Last reply Reply Quote 0
        • K Offline
          kpa
          last edited by

          The state table (Diagnostics -> States) will also show the assocations between the WAN interface states and the LAN interface states.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.