Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Get the time a connection is established to a destination IP? Detect VPN?

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 2 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N Offline
      Nachtfalke
      last edited by

      Hi,

      is there a possibility to get the time how long a connection to a destination IP is established ?
      I think this could make it possible for me to find connections which are VPN connections.

      So lets say a connection which is established to the same destination IP longer than 5min is not a common http or https connection. There could be of course some exception.

      So is there a way from pfsense webGUI or some freebsd command line code ?

      Thanks

      1 Reply Last reply Reply Quote 0
      • B Offline
        babtras
        last edited by

        Perhaps you can use the firewall log to see when a connection is established, then check the state table (Diagnostics->States) to see if the connection is still open and do the math.

        But I wouldn't make the assumption that an http/https connection open longer than 5 minutes is inappropriate. Dowloading a large file, for example.

        1 Reply Last reply Reply Quote 0
        • N Offline
          Nachtfalke
          last edited by

          @babtras:

          Perhaps you can use the firewall log to see when a connection is established, then check the state table (Diagnostics->States) to see if the connection is still open and do the math.

          Would be hardly possible I think because I have to check many many https connections and that would be really hard. But in theory this would work.  :)

          @babtras:

          But I wouldn't make the assumption that an http/https connection open longer than 5 minutes is inappropriate. Dowloading a large file, for example.

          Generally you are right. But then I would have regularyly a look on this connection and if this will be there every day then I can take a deeper look at that.

          I thought about a "top ten" of the longest established connections somewhere on pfsense GUI or on command line.

          1 Reply Last reply Reply Quote 0
          • N Offline
            Nachtfalke
            last edited by

            I did some more search on the internet and some tips for the command line or other tools but I did not find anything useful.

            So if there is someone who could give me some tips it would be really great.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.