Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to redirect "portal auth" logs to another destination?

    Scheduled Pinned Locked Moved Captive Portal
    6 Posts 3 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      onlineph
      last edited by

      Hi,

      I wish to continuously save all logs in my "Status: System logs: Portal Auth". I need to have a copy of all authentication via captive portal. Is this possible?

      To my understanding, the max 200 auth record is erase once the box is restarted so, I need to save them in a separate HD, away from being erased when restarted.

      Any advice is much appreciated.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Use a separate syslog server to capture and store the logs.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • O
          onlineph
          last edited by

          Hi jimp,

          Yeah I have though of that and the thing is I don't know how. Is there a package available for this? I mean a feature that would give an option to separate the auth log?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            Status > System Logs, Settings Tab, check "Enable Remote Logging", enter the IP of your syslog server, check "Portal Auth events", Save.

            That's it.

            The server part is up to you, though.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • O
              onlineph
              last edited by

              Hi jimp,

              I hope you could help me on this. I did some research and I found this https://doc.pfsense.org/index.php/Copying_Logs_to_a_Remote_Host_with_Syslog

              I checked with the apps, downloaded the tftp server, installed in my my host (I'm running the pfsense in VM). I thought I can use some space in my hard drive to save the auth logs.

              Following the steps on how to redirect the auth logs, I find myself having trouble on what IP should I input. I tried to run the tftpd server, tried navigating it and I can't get any idea on what IP would I used as target.

              I hope I can still get any idea on how to do it? Thanks in advance jimp.

              1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan
                last edited by

                Hi there.

                As instructed here: https://doc.pfsense.org/index.php/Copying_Logs_to_a_Remote_Host_with_Syslog supply ipSense with the IP of the PC where your log server is running.
                In your case, this IP belongs to the Windows PC where http://tftpd32.jounin.net/ is running on.

                I'm not using tftpd32 myself, but normally it - the tftpd32 log server program - should 'listen' on port 514 UDP (because it's the default value, and if you looked well, pfSense is sending its logs to this IP:port).

                If things don't seem to work, remember one thing: your Windows PC where tftpd32  is running on probably has a firewall.
                So, instruct the firewall to accepts UDP trafic from your pfSense box (his IP !) into the log server and you are ok.

                Btw: this is not a "Captive Portal question", more a General question  :)

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.