Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Super Dumb Question re Logs

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      BenKenobe
      last edited by

      Been having 'issues' with IPSec so have been paying more attention to the firewall log than usual - and I have come to a conclusion.

      I have no idea how to link a log entry to a particular rule  … I mean rule 179 doesn't exactly tell me much - given that none of my rules have numbers.

      i.e. pf: 124. 995672 rule 179/0(match): block in on ng0:

      sure I know it was blocked, sure I can even identify the IP Addresses and there is a short 'description' i.e igmp query v2 but thats it ....

      This is just an example of the problem for me - can somebody please explain this stuff ...  pf: 124. 995672 rule 179/0(match)

      And tell me how to identify the 'rule' that it thinks matches.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        If you view the logs in the gui, click the red "x" icon and it will show a window with the rule.

        From the CLI, use the output of "pfctl -vvsr"

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • B
          BenKenobe
          last edited by

          I am looking from the web interface and …. what red cross ?????

          There are no red crosses anywhere on my log window.

          And then I changed the view .... there is the red cross on the simple view .... when viewing in raw format there is no red cross - and I've only been using pFsense 2 years  :-[

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.