Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to see logs for specific firewall rule?

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 3 Posters 917 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      seanmcb
      last edited by

      When creating a firewall rule, there's a "Log packets that are handled by this rule" checkbox.

      How can I see the logs related to that particular firewall rule?

      Thanks.

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN Offline
        NogBadTheBad
        last edited by

        Screenshot 2020-03-20 at 07.22.51.png

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        GertjanG 1 Reply Last reply Reply Quote 0
        • S Offline
          seanmcb
          last edited by

          Thanks for your reply. I did end up finding that, and it's helpful, but it's not what I meant. It could be workable if there was a way to filter by rule, but I don't see this in the filter UI, unless I'm blind...?

          1 Reply Last reply Reply Quote 0
          • NogBadTheBadN Offline
            NogBadTheBad
            last edited by

            Most people will forward the logs via syslog to a remote server, it would appear something like this:-

            182,,,1535801592,pppoe0,match,block,in,4,0xc,,249,64183,0,none,6,tcp,40,89.248.168.223,xx.xx.xx.xx,46407,62498,0,S,2950824445,,1024,,

            The bold text is the rule number.

            You could set the rules to display as raw logs then filter on the rule number, the only issue would be the logs aren't that readable if they're set to raw.

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 0
            • S Offline
              seanmcb
              last edited by

              Thanks @NogBadTheBad.

              For anyone else that may find this post, if you SSH to your pfsense, you can find a particular rule being applied like this:

              clog /var/log/filter.log | grep 1535801592

              I also discovered that the default log size is a miniscule 500 KB and so it was wrapping around, in my case, every 3 minutes. This was the main reason even searching in the GUI using port numbers was not finding anything. I thought I was really misunderstanding how the thing worked.

              1 Reply Last reply Reply Quote 0
              • GertjanG Offline
                Gertjan @NogBadTheBad
                last edited by

                @NogBadTheBad said in How to see logs for specific firewall rule?:

                Screenshot 2020-03-20 at 07.22.51.png

                Status > System Logs > Firewall > Normal View

                Your screen doesn't show the same settings as mine :

                10ea1ab4-5445-46fa-a7ea-6b043bbb7add-image.png

                Are you using the latest 2.4.4-p3 RC ?

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                1 Reply Last reply Reply Quote 0
                • NogBadTheBadN Offline
                  NogBadTheBad
                  last edited by

                  I am:-

                  2.4.4-RELEASE-p3 (amd64) built on Thu May 16 06:01:19 EDT 2019 FreeBSD 11.2-RELEASE-p10

                  Screenshot 2020-03-24 at 08.49.25.png

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  1 Reply Last reply Reply Quote 0
                  • GertjanG Offline
                    Gertjan
                    last edited by Gertjan

                    Ok, thanks.
                    That should explain the difference.
                    I'm using the latest pfSense RC version 2.4.5.r.20200318.1500 which will probably be (very close to) two dot four dot five.

                    edit : btw : rock solid - for my usage.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    1 Reply Last reply Reply Quote 1
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.