Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Continuous packet capturing and storing

    Scheduled Pinned Locked Moved General pfSense Questions
    3 Posts 3 Posters 823 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Su30MKI
      last edited by

      Is it possible to do continuous packet capture of an interface and store it in a file storage from pfsense?

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by johnpoz

        So you want to turn pfsense into a gigastore? Or extrahop added it a few years back... There are some alternatives for sure - but this is not something I would do on pfsense..

        Back a few years there was a GREAT product https://www.colasoft.com/nchronos/ that use to be FREE.. for like 1 interface and less than 1 gig.. It was perfect for home monitoring or smb... But they pulled it from their FREE -- you can get a demo though.. Pricing should be way cheaper than appliance way of doing this.

        There are for sure opensource free ways to do this - I just wouldn't do it at your firewall.. Run it via a tap or span port off your switching infrastructure..

        You could use n2disk from ntop for such a thing... They also sell a box nBox I do believe they call it for this sort of thing... There are many ways to skin this cat... Doing it on your firewall would not be one of them.. The packet capture feature of pfsense is great for troubleshooting an issue. But I would not use it for such monitoring of your network.

        I would prob look here
        http://www.openfpc.org/

        I have not had time to play with it yet... But it is on my todo list ;)

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • JKnottJ
          JKnott
          last edited by

          Well, there's Packet Capture, built into pfSense, that can capture all the traffic on a pfSense interface. However, you'd have to manually start & stop it and then download the capture file. If an interface on another device, you'd also need a managed switch, configured to port mirror.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.