Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Improving of Firewall Change log

    General pfSense Questions
    2
    6
    337
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lnovak
      last edited by

      Re: Firewall Change log

      In this topic was mentioned really good way how to log changes on firewall, log_config_write.patch:
      http://files.atx.pfsense.org/jimp/patches/log_config_write.patch

      Many thanks for it! However, it would be really great to know which rule has been changed or at least on which interface.

      Does anybody have an idea how to achieve this funcionality?

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        You can see that locally on the config history tab already.
        Or you can just diff the config files if you are backing them up.

        Do you need more than that?

        Steve

        1 Reply Last reply Reply Quote 0
        • L
          lnovak
          last edited by

          But I can only see, that a firewall rule was changed. I can´t see which one has been changed or at least on which interface.

          Or am I looking wrong?

          Lukas

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            You can see exactly what was changed by diffing the two configs:

            Selection_598.png

            Steve

            1 Reply Last reply Reply Quote 0
            • L
              lnovak
              last edited by

              You´re right, but when I enable some rule, even from this tab I don´t know, which one I enabled.
              d6440b02-960b-4d11-bd34-1cedcd9ea566-image.png

              Maybe I could find it in config file in highlighted rows but that is not appropriate for next automated evaluation. That is the reason why it would be nice to have this information directly in the log.

              Lukas

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                The diff is against the current config version so you can see exactly what changed.

                That's the only config record there is though. If you need something more you can open a feature request:
                https://redmine.pfsense.org

                Steve

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.