Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Monitoring traffic on new installation

    Scheduled Pinned Locked Moved Firewalling
    2 Posts 2 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cpk
      last edited by

      I recently installed my first pfSense and configured NAT and the Firewall.  I'm monitoring the firewall log to see what traffic is blocked, and I'd like to watch that to determine if the traffic is expected or not.  Has there been any discussion (I could not find any) of blocked traffic and specifics on log entries?  If so, can you point me in that direction?

      For example, I see many of these:
      Sep 8 20:44:30 WAN 213.248.117.214:3478 192.168.1.226:61827 UDP
      Sep 8 20:42:52 WAN 124.40.51.151:3478 192.168.1.226:61827 UDP

      Since many of the source IP addresses are AKAMAI, I wonder if this is traffic I should be accepting.

      Carl

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        There is some info in the doc wiki, but really what ports are "good" or what traffic is "bad" depends on the network and the type of traffic you're using. It's far too subjective to generalize with much accuracy.

        You can lookup what ports those are, but if those are part of a legitimate connection, it's probably just a variation of this:
        http://doc.pfsense.org/index.php/Logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection,_why%3F

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.