Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rule name in filter.log

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mki
      last edited by

      Hi all

      Is it possible to get the rule name which is blocking a connection.

      Have a look at this filter.log entry:

      
      Dec 29 01:20:17 x13 pf: 00:00:02.930278 rule 41/0(match): block in on vr2: (tos 0x0, ttl 106, id 22828, offset 0, flags [DF], proto TCP (6), length 48)
      Dec 29 01:20:17 x13 pf:     61.38.162.67.4668 > X.X.X.X.445: Flags [s], cksum 0xdb45 (correct), seq 2986860058, win 65535, options [mss 1460,nop,nop,sackOK], length 0
      
      As you can see, rule 41/0 matched. How can I show the name of the rule (to identify it)?
      
      Thanks in advance
      mki[/s]
      
      1 Reply Last reply Reply Quote 0
      • pttP
        ptt Rebel Alliance
        last edited by

        Try with:

        
        pfctl -vvsr
        
        
        1 Reply Last reply Reply Quote 0
        • M
          mki
          last edited by

          I am sending my filter logs to a syslog server. Is it possible to have the rule name in the log entries?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            No. There is no way to embed that information in the logs directly. The rule number is all you can get, and because that can potentially change periodically, it can be tough to nail down exactly. There are many discussions about this around the forum, search a bit and you'll find them.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.