Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec login logs

    Scheduled Pinned Locked Moved IPsec
    6 Posts 3 Posters 351 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      josey
      last edited by

      Hi guys,
      can i get ip sec user logins ?
      but only user logins.
      if do can you guide me how?

      thanks

      also

      what is maximum number of users connected over IPsec?
      32? more?

      if matters
      link is 100/100mbps

      jimpJ 1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate @josey
        last edited by

        @josey said in IPsec login logs:

        Hi guys,
        can i get ip sec user logins ?
        but only user logins.
        if do can you guide me how?

        No. Unfortunately, strongSwan doesn't have a good way of marking just the login events so we can't filter them out in syslogd (See #9754). But if you have a central log system (off the firewall) to which pfSense can send logs you may be able to filter them on there.

        what is maximum number of users connected over IPsec?
        32? more?

        There is no set limit. It's mostly up to your settings and hardware (CPU, etc). Someone posted a couple weeks ago that they had almost 1,000 clients connected.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • J
          josey
          last edited by josey

          @jimp thanks

          where is log file of ipsec?
          is it /var/log/ipsec.log
          is it logging more than 500 events which we can se under Status: System logs: IPsec VPN ?
          i see there is 5000 lines but its only 1 day logged.
          is it possible to log last for example 100 000 events?

          regards

          viktor_gV 1 Reply Last reply Reply Quote 0
          • viktor_gV
            viktor_g Netgate @josey
            last edited by

            @josey you can change IPsec log file size on the Status / System Logs page:
            Screenshot from 2020-04-24 11-13-14.png

            J 1 Reply Last reply Reply Quote 0
            • J
              josey @viktor_g
              last edited by

              @viktor_g
              thanks
              set to 20000000
              it will be for 35 days aprox

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                Since it's a binary circular log, there is no guarantee about how long any record will be there. They will be rotated out as new entries come in.

                Storing large logs on the firewall is not a good practice. You should setup a dedicated syslog server and have pfSense deliver the logs there, where they can be properly stored/processed/archived.

                Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.