Project

General

Profile

Actions

Correction #9618

closed

Feedback on System Monitoring — Firewall Logs

Added by Louis B almost 5 years ago. Updated over 3 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Logging
Target version:
-
Start date:
07/07/2019
Due date:
% Done:

0%

Estimated time:

Description

Page: https://docs.netgate.com/pfsense/en/latest/monitoring/logs/firewall.html

Feedback:
- I assume that an Arrow in the interface field indicates that it is an outgoing rule (but that is not described)

traffic can be stopped due to multiple reasons:
  • the defined rule
  • incorrect tcp status (as shown in the log)
but also due to things like:
  • ttl
  • not allowed IP options
  • and perhaps other thinks

I have no idea if that kind of blocking is shown in the log and how the cause is indicated

My remarks above refer to visible / user defined rules. But there seems/my impression is that there are also predefined invisible rules. So I wonder if those rules can be made visible and if it is posible to show the result "block, pass or reject" can be made visible.

Hope this helps to improve documentation and perhaps the gui.

Sincerely,

Louis

Actions #1

Updated by Louis B almost 5 years ago

Sorry for the remark on default rules. I noticed that the logfile settings have options for that.

Log packets matched from the default block rules in the ruleset
Log packets that are blocked by the implicit default block rule. - Per-rule logging options are still respected.

Log packets matched from the default pass rules put in the ruleset
Log packets that are allowed by the implicit default pass rule. - Per-rule logging options are still respected.

Actions #2

Updated by Jim Pingle over 3 years ago

  • Category set to Logging
Actions #3

Updated by Jim Pingle over 3 years ago

  • Description updated (diff)
Actions #4

Updated by Jim Pingle over 3 years ago

  • Status changed from New to Resolved

Relevant parts should be covered by the latest round of doc updates.

Actions

Also available in: Atom PDF