• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Solid monitoring and rule problem finding

Scheduled Pinned Locked Moved Firewalling
10 Posts 4 Posters 3.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    tacfit
    last edited by May 10, 2007, 3:55 PM

    Hi all,

    I've moved from Microsoft's ISA 2004 to pfSense, and I'm loving it. It's solved a host of problems I had. However, there's one thing I haven't found an easy way to do, that's slowing me down a little.

    In ISA, there's a great tool to see what traffic is being allowed and blocked, you can watch a specific IP, or a specific port (plus various other filters) and see everything that's being allowed, blocked, etc, and what rule is causing it. So far, I've only seen the Firewall Log, which is nowhere near as useful as the feature in ISA.

    Is there an addon that can help with this, or should I look at syslogging to another server that could offer me this realtime filtering?

    1 Reply Last reply Reply Quote 0
    • T
      trendchiller
      last edited by May 10, 2007, 4:10 PM

      did you try the firewall-log-filter ?

      1 Reply Last reply Reply Quote 0
      • T
        tacfit
        last edited by May 10, 2007, 4:55 PM

        Do you mean selecting "Show raw filter logs" on the settings page? That doesn't seem much better.

        1 Reply Last reply Reply Quote 0
        • G
          GruensFroeschli
          last edited by May 10, 2007, 5:25 PM

          i think what trendchiller meant was the:
          diagnostic –> states --> upper right corner "Filter"-field

          We do what we must, because we can.

          Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

          1 Reply Last reply Reply Quote 0
          • T
            trendchiller
            last edited by May 10, 2007, 6:22 PM

            correct  ;)

            1 Reply Last reply Reply Quote 0
            • T
              tacfit
              last edited by May 10, 2007, 7:42 PM

              Yeah, I have seen that, but thanks for reminding me. However, connections that have been refused will not show here, naturally… which is part of the equation.

              1 Reply Last reply Reply Quote 0
              • T
                trendchiller
                last edited by May 10, 2007, 7:45 PM

                well, thats correct…
                you're right...

                1 Reply Last reply Reply Quote 0
                • C
                  cmb
                  last edited by May 11, 2007, 5:00 AM

                  I'm assuming you must be running 1.0. In 1.2, you can switch the firewall log screen to dynamically refresh using AJAX, and if you hover over a rule it has a pop up that shows you what rule is responsible for the block/pass. It also lets you pause the dynamic updates. The only major difference between ISA's real time log display and what pfsense 1.2 will have is the ability to filter the display. That's likely to come in the next version after 1.2.

                  1 Reply Last reply Reply Quote 0
                  • T
                    tacfit
                    last edited by May 11, 2007, 12:24 PM

                    I am using 1.2. I've used the Dynamic refresh, but I don't find it actually refreshed properly. If I hit F5, I get a whole lot more all of a sudden.

                    But… with the ability to filter by hosts and ports, and a better refresh... that tool would be great :) Thanks.

                    1 Reply Last reply Reply Quote 0
                    • C
                      cmb
                      last edited by May 11, 2007, 9:00 PM

                      The dynamic refresh might not work quite right just yet. I'll take a closer look at it.

                      1 Reply Last reply Reply Quote 0
                      1 out of 10
                      • First post
                        1/10
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received