Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Improving of Firewall Change log

    General pfSense Questions
    2
    6
    142
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lnovak last edited by

      Re: Firewall Change log

      In this topic was mentioned really good way how to log changes on firewall, log_config_write.patch:
      http://files.atx.pfsense.org/jimp/patches/log_config_write.patch

      Many thanks for it! However, it would be really great to know which rule has been changed or at least on which interface.

      Does anybody have an idea how to achieve this funcionality?

      1 Reply Last reply Reply Quote 0
      • stephenw10
        stephenw10 Netgate Administrator last edited by

        You can see that locally on the config history tab already.
        Or you can just diff the config files if you are backing them up.

        Do you need more than that?

        Steve

        1 Reply Last reply Reply Quote 0
        • L
          lnovak last edited by

          But I can only see, that a firewall rule was changed. I can´t see which one has been changed or at least on which interface.

          Or am I looking wrong?

          Lukas

          1 Reply Last reply Reply Quote 0
          • stephenw10
            stephenw10 Netgate Administrator last edited by

            You can see exactly what was changed by diffing the two configs:

            Selection_598.png

            Steve

            1 Reply Last reply Reply Quote 0
            • L
              lnovak last edited by

              You´re right, but when I enable some rule, even from this tab I don´t know, which one I enabled.
              d6440b02-960b-4d11-bd34-1cedcd9ea566-image.png

              Maybe I could find it in config file in highlighted rows but that is not appropriate for next automated evaluation. That is the reason why it would be nice to have this information directly in the log.

              Lukas

              1 Reply Last reply Reply Quote 0
              • stephenw10
                stephenw10 Netgate Administrator last edited by

                The diff is against the current config version so you can see exactly what changed.

                That's the only config record there is though. If you need something more you can open a feature request:
                https://redmine.pfsense.org

                Steve

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post