Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    FIREWALL LOGS FOR NAT NOT SHOWING UP

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 3 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E Offline
      edamalie
      last edited by

      I currently have a Firewall rule to enable traffic to port 8181 which I enabled logging {log packets that are handled by this rule option } ticked. There are however no logs for that Firewall rule showing up in the Status>System Logs> Firewall logs.
      However further investigation with a tcpdump command {tcpdump -I <interface>port <port>for that NAT rule show results.
      Can anyone help here
      Pfsense version: 2.3.1- Release (i386)
      Please FIND FIREWALL RULE BELOW

      PLEASE FIND TCPDUMP OUTPUT

      I have reset firewall states. I also checked "Log packets matched from the from the default pass rules put in the ruleset" under Sytem Logs>Firewall>Manage

      I can currently see some pass logs but not on that particular port 8181

      ![tcpdump output.PNG](/public/imported_attachments/1/tcpdump output.PNG)
      ![tcpdump output.PNG_thumb](/public/imported_attachments/1/tcpdump output.PNG_thumb)
      ![firewall rule.PNG](/public/imported_attachments/1/firewall rule.PNG)
      ![firewall rule.PNG_thumb](/public/imported_attachments/1/firewall rule.PNG_thumb)</port></interface>

      1 Reply Last reply Reply Quote 0
      • D Offline
        doktornotor Banned
        last edited by

        Good that you censored the IPs so that it's impossible to verify anything here.  ::) ::) ::)

        P.S. And kindly upgrade to current stable pfSense version before wasting more time.

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator
          last edited by

          Along with what dok says those are acks in your dump not syn.. Your log is not going to log acks that are allowed.  A default deny would log out of state or syn.

          And again restate - get current.

          Are you saying nothing is showing in the logs or only this rule you have?  If there was a state already when you created this log rule no existing traffic would not be logged.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

          1 Reply Last reply Reply Quote 0
          • E Offline
            edamalie
            last edited by

            @johnpoz:

            Along with what dok says those are acks in your dump not syn.. Your log is not going to log acks that are allowed.  A default deny would log out of state or syn.

            And again restate - get current.

            Are you saying nothing is showing in the logs or only this rule you have?  If there was a state already when you created this log rule no existing traffic would not be logged.

            I have reset firewall states. I also checked "Log packets matched from the from the default pass rules put in the ruleset" under Sytem Logs>Firewall>Manage

            I can currently see some pass logs but not on that particular port 8181

            1 Reply Last reply Reply Quote 0
            • E Offline
              edamalie
              last edited by

              @johnpoz:

              Along with what dok says those are acks in your dump not syn.. Your log is not going to log acks that are allowed.  A default deny would log out of state or syn.

              And again restate - get current.

              Are you saying nothing is showing in the logs or only this rule you have?  If there was a state already when you created this log rule no existing traffic would not be logged.

              So i went ahead with to reset states and now i can see traffice from 8181 port i specified. Thank you for your help @ Johnpoz

              1 Reply Last reply Reply Quote 0
              • johnpozJ Offline
                johnpoz LAYER 8 Global Moderator
                last edited by

                Can not tell from your postings.. But is this outbound, or an inbound port forward to 8181

                Without more info and detail its not possible to help point to where your making the mistake.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

                1 Reply Last reply Reply Quote 0
                • E Offline
                  edamalie
                  last edited by

                  @johnpoz:

                  Can not tell from your postings.. But is this outbound, or an inbound port forward to 8181

                  Without more info and detail its not possible to help point to where your making the mistake.

                  I am most grateful was an inbound port forward. Solved now

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.