Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFSense Firewall Log View - Showing Logs Once ICMP

    Scheduled Pinned Locked Moved Firewalling
    log viewicmp logsping logslog count
    2 Posts 2 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      gethersJ
      last edited by

      Hi there,

      Not sure if anyone can help me, basically we have a PFSense here which is on version 2.4.4 Release P3.

      I am trying to track traffic on the firewall using the log view, but the issues I am having is I only see the traffic hitting the logs once and thats it. An example of this would be:

      If i try and ping google.co.uk on a continuous loop from my PC, I will only see that event in the logs view only once... but I really need to see this for each ICMP request. So if it pings 50 times I would like to see the ping in the logs 50 times.

      We have tried sending the logs to a syslog server and the results are the same there, PFSense only logs things once. Is there any way that we can stop this from happening, even if its only a temporary measure.

      We have a rule active allowing ICMP requests and Logging is enabled on that rule also.

      Thanks

      1 Reply Last reply Reply Quote 0
      • JeGrJ
        JeGr LAYER 8 Moderator
        last edited by

        @gethersJ said in PFSense Firewall Log View - Showing Logs Once ICMP:

        If i try and ping google.co.uk on a continuous loop from my PC, I will only see that event in the logs view only once... but I really need to see this for each ICMP request. So if it pings 50 times I would like to see the ping in the logs 50 times

        You are not tracking traffic if you would see 50 icmp pings in your Logs. Firewall Logs are exactly that - Logs. They are not to be used for traffic analasys. There are other packages that do that job, traffic log isn't the right one. And of course you only see 1 hit in the logs, as only the first state / request is logged, all other pings are matched against the valid state and are passed through because of stateful filtering.

        If you want to log traffic, use ntopNG, bandwithd, darkstat etc. or just install softflowd and send your flows to an internal flow collector and let it parse and beautify your traffic :)

        Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

        If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.