  • I am using PFSense as a firewall/gateway for a fairly large wireless system.  All of my customers have static NAT address behind it.

    Well I received a subpoena today, someone behind it was doing something they shouldn't have been.  All they can provide me is the IP of the PFSense machine, and date/times.  I am trying to see if there is any kind of log file I can provide that may help them.


  • Rebel Alliance Developer Netgate

    Unless you have something else tracking your internal usage (squid, netflow, etc) there isn't likely to be any kind of record you can refer to for that.

    pfSense doesn't keep a log of every incoming/outgoing connection, and even if you made the rules log every connection it may not give you the info that you would need to match up the information they gave with internal activity.

