Firewall system log

  • Hi,

    I am new in pfsense and I am not sure if the log I am getting need attention. I don't remember from my previous log before that I saw that some IP address was successfully pass on our internal IP address for our mail server HTTPS 443. I just want to know if this log is normal if somebody from our organization log-in successfully on our webmal. what if somebody is trying to forcely login to our webmail that means they are allowed too?

    Please see attached screenshot.

  • since theres a log of that it means that you have set up a rule to log all access to that ip,
    the log is showing that somebody from OUTSIDE the firewall is accessing that server (hence the if =WAN)
    comes back to: United States Charlottesville Embarq Corporation
    Resolve Host:

Log in to reply