Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to Tell What Application is Responsible for Traffic

    Firewalling
    4
    4
    310
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      ProfessorManhattan
      last edited by

      Hey, I'm currently in the cumbersome process of figuring out what traffic to allow and what to disallow. It would be really great if in the firewall logs they listed the IP address and the application on that IP address that is sending the traffic.

      Is there anyway to accomplish something like this with pfSense? I imagine there would be a service that runs on each machine and staples a piece of meta data to each packet.

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @ProfessorManhattan
        last edited by

        @ProfessorManhattan

        How is pfsense supposed to know what app sent the traffic, when that info is not included in IP? Even though you can know the protocol, you don't always know what app it's from. For example, protocols such as http or ssh are used by several apps.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • H
          heper
          last edited by

          ntopng ?

          1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan
            last edited by Gertjan

            Use the info found here https://forum.netgate.com/topic/156158/what-do-your-firewall-rules-look-like/25?_=1599304505040 and start blocking everything.
            Your LAN users will complain.

            Open up one by one the listed ports (see thread in link). Analyse what start s work. Note the relation between ports and services / programs.

            @ProfessorManhattan said in How to Tell What Application is Responsible for Traffic:

            the cumbersome proces

            You got that part right.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.