• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Remote logging and DShield

Scheduled Pinned Locked Moved General pfSense Questions
15 Posts 7 Posters 2.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • F
    firewalluser
    last edited by May 26, 2015, 4:02 PM

    No joy with this then? https://www.dshield.org/linux_clients.html#freebsd

    Capitalism, currently The World's best Entertainment Control System and YOU cant buy it! But you can buy this, or some of this or some of these

    Asch Conformity, mainly the blind leading the blind.

    1 Reply Last reply Reply Quote 0
    • T
      telserv
      last edited by May 26, 2015, 4:26 PM

      Hi Firewalluser.

      I'll try your suggestion immediately, and let you know.

      Thanks

      1 Reply Last reply Reply Quote 0
      • T
        telserv
        last edited by May 26, 2015, 4:36 PM

        Hi Firewalluser:

        I've investigated the FreeBSD choices on the DShield website.

        1.  FreeBSDshield looks like what I want, but is a dead link.  When searching for it on the internet, it does show up, but again the links have gone dead.

        2.  There is a text file with some scripts from 2004, but given their age, and my lack of ability with php,  I've decided not to try them.

        DShield is aware of the problem, and one of their handlers is looking at it.  He hasn't give me any specific analysis of why the existing systems don't work.

        Thanks for your efforts.

        1 Reply Last reply Reply Quote 0
        • Z
          zerodamage
          last edited by May 26, 2015, 4:52 PM May 26, 2015, 4:40 PM

          @Gord:

          Hi Firewalluser:

          I've investigated the FreeBSD choices on the DShield website.

          1.  FreeBSDshield looks like what I want, but is a dead link.  When searching for it on the internet, it does show up, but again the links have gone dead.

          2.  There is a text file with some scripts from 2004, but given their age, and my lack of ability with php,  I've decided not to try them.

          DShield is aware of the problem, and one of their handlers is looking at it.  He hasn't give me any specific analysis of why the existing systems don't work.

          Thanks for your efforts.

          The version that they support on the DShield site is FreeBSD 4.2 and we are now at 10.x so it is unlikely to work. Ideally there would be a package or something available on the pfSense system itself to handle this. I may post a bounty for this as I do not have the time to write one myself. Let me know if you want to contribute to the bounty.

          1 Reply Last reply Reply Quote 0
          • I
            iced
            last edited by Jun 10, 2015, 2:17 PM

            someone done some work to fixing this but seems stalled at added the package https://github.com/Robert-Nelson/dshield-sensor-pfsense hopeful Robert Nelson will get it sorted

            1 Reply Last reply Reply Quote 0
            • R
              robertn
              last edited by Jun 10, 2015, 2:51 PM

              I have all the work done. I fixed the dshield sensor scripts and created a pfsense package.  However after months of waiting for the package to be accepted by pfSense I gave up and closed the ticket and the pull request.

              1 Reply Last reply Reply Quote 0
              • V
                va176thunderbolt
                last edited by Jun 13, 2015, 12:11 PM

                I'd love to be able to submit my logs to dshield to help them - they've helped me a lot in the past. I had even considered sponsoring a bounty.

                Can you share your package?

                1 Reply Last reply Reply Quote 0
                • R
                  robertn
                  last edited by Jun 16, 2015, 5:33 AM

                  Unfortunately its a little more complicated than just sharing a package, you kinda have to go through the package manager which wants to talk to a package repository website.  Plus since its written in perl and pfsense doesn't have perl you need to install a pbi.

                  1 Reply Last reply Reply Quote 0
                  • J
                    johnpoz LAYER 8 Global Moderator
                    last edited by Jun 16, 2015, 11:37 AM

                    Why can you not just send your firewall logs from pfsense to syslog server, and then send the logs from there to dshield?

                    Don't they have a package that runs on windows and uses the kiwi syslog
                    https://www.dshield.org/windows_clients.html

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • V
                      va176thunderbolt
                      last edited by Jun 17, 2015, 2:46 AM

                      I run my installs on physcal hardware, and would prefer to run have to run additional boxes just for logging. Most of my pfsense boxes have plenty of spare cycles to bundle up logs and submit them to Dshield for their analysis.

                      1 Reply Last reply Reply Quote 0
                      • R
                        robertn
                        last edited by Jun 17, 2015, 5:58 AM

                        The problem is not so much one of physically getting the data to dshield although that is part of it.  The main issue is parsing the logs and getting the information reformatted into the proper format for submission.  Remotely logging them just moves the problem to another machine, one that doesn't have the scripts builtin to pfsense to help with the parsing.

                        1 Reply Last reply Reply Quote 0
                        • I
                          iced
                          last edited by Sep 4, 2015, 9:55 AM

                          Any Luck getting pfsense to include it,  looked as if there was a way to manual pull down perl, or maybe just turn it in to zip or tar with perl if pfsense

                          1 Reply Last reply Reply Quote 0
                          • Z
                            zerodamage
                            last edited by Mar 20, 2016, 10:37 PM

                            Just bumping this back up. I think this should happen at some point.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                              [[user:consent.lead]]
                              [[user:consent.not_received]]