Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Log everything from 1 IP address

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 3 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cdub808
      last edited by

      Is it possible to log all traffic to and from one particular IP address?  I want to see everything that goes through the firewall and everything that is blocked.  I would like to selectively do this for certain computers for limited periods of time for testing purposes.  I have an SG-4860 device, how do I do this?  Thanks.

      1 Reply Last reply Reply Quote 0
      • M
        mer
        last edited by

        firewall rules, on the interface you're interested in (LAN?), pass or block rule src addr the IP(s) in question select log option.  be careful as to "pass or block" because order becomes important.

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          If you really want to log all TRAFFIC to/from a particular host, you need to find a way to simultaneously capture all the traffic on both interfaces WAN and LAN.  A switch mirror port on your modem and your LAN host going into a couple ports capturing with tcpdump would work.  pfSense's built-in capture can only capture one port at a time I think.  You can probably do multiple interfaces simultaneously by calling tcpdump from the shell.

          Then you have to problem of matching the traffic on WAN after NAT has happened (if that's the case).

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.