本文にスキップ

OPNsense

Overview

OPNsense is a FreeBSD-based open-source firewall and routing platform with enterprise-grade features including Suricata IDS/IPS, web proxy, and VPN. KYRA MDR collects OPNsense firewall filter logs, Suricata intrusion detection events, and system authentication logs via syslog for network security monitoring.

Prerequisites

  • KYRA MDR account (MDR tier or above)
  • KYRA Collector installed and reachable from the OPNsense appliance
  • OPNsense 23.1 or later with administrative web interface access
  • Network connectivity from OPNsense to the Collector on TCP/UDP port 514

Configuration

Step 1: Configure Remote Syslog Target

  1. Navigate to System > Settings > Logging / Targets
  2. Click the + button to add a new remote syslog destination
  3. Configure the target:
SettingValue
EnabledChecked
TransportTCP(4)
ApplicationsLeave empty (sends all)
LevelsLeave default (sends all severity levels)
FacilitiesLeave empty (sends all facilities)
Hostname<COLLECTOR_IP>
Port514
RFC5424Checked (structured syslog format)
Certificate(Optional: select a CA for TLS transport)
  1. Click Save and then Apply

Step 2: Enable Detailed Filter Logging

Configure which firewall rules generate log entries:

  1. Navigate to Firewall > Settings > Normal
  2. Enable Log packets matched from the default block rules
  3. Enable Log packets matched from the default pass rules (if needed for full visibility)
  4. Click Save

For individual rules, edit each rule and check Log packets that are handled by this rule.

OPNsense filter log format (CSV-style via /var/log/filter.log):

rulenr,subrulenr,anchorname,ridentifier,interface,reason,action,direction,
ipversion,tos,ecn,ttl,id,offset,flags,proto,protoid,length,
src,dst,srcport,dstport

Step 3: Configure Suricata IDS Logging

  1. Navigate to Services > Intrusion Detection > Administration
  2. Ensure Enabled is checked
  3. Set IPS mode as needed (IDS for monitoring, IPS for blocking)
  4. Under General tab, verify:
    • Pattern matcher: Aho-Corasick
    • Log level: Info
    • EVE output: Enabled (JSON-formatted event log)

Download and enable rulesets:

  1. Go to Services > Intrusion Detection > Administration > Download tab
  2. Enable rulesets:
    • ET open/emerging-* (Emerging Threats open rules)
    • abuse.ch (malware/botnet IOCs)
  3. Click Download & Update Rules
  4. Go to the Rules tab to enable/disable specific rule categories

Suricata EVE JSON output is written to /var/log/suricata/eve.json:

{
"timestamp": "2024-01-15T10:30:00.000000+0900",
"event_type": "alert",
"src_ip": "192.168.1.100",
"dest_ip": "203.0.113.50",
"alert": {
"action": "allowed",
"signature_id": 2024897,
"signature": "ET MALWARE Trickbot Checkin",
"category": "A Network Trojan was Detected",
"severity": 1
}
}

Step 4: Configure Syslog via CLI (Alternative)

For advanced syslog configuration, use the OPNsense shell:

Terminal window
# SSH into OPNsense
ssh root@<OPNSENSE_IP>
# Edit syslog configuration
vi /usr/local/etc/syslog.d/kyra-remote.conf
# Add remote syslog target (RFC 5424 over TCP)
*.* @@<COLLECTOR_IP>:514;RFC5424fmt
Terminal window
# Restart syslog service
service syslogd restart
# Verify syslog is sending
sockstat -4l | grep syslog

For encrypted log transport:

  1. Navigate to System > Trust > Authorities and import the KYRA Collector CA certificate
  2. Navigate to System > Settings > Logging / Targets
  3. Edit the remote target and set Transport to TLS(6)
  4. Select the imported Certificate for the target
  5. Click Save and Apply

Step 6: Forward Suricata EVE Logs

If Suricata EVE logs need separate forwarding:

/usr/local/etc/syslog.d/suricata-eve.conf
# Use a file watcher to forward EVE JSON
module(load="imfile" PollingInterval="5")
input(type="imfile"
File="/var/log/suricata/eve.json"
Tag="suricata-eve"
Facility="local6"
Severity="info")
local6.* @@<COLLECTOR_IP>:514

Verify on KYRA Collector

Terminal window
kyra-collector status
kyra-collector logs --source opnsense --tail 10

Collected Log Types

Log TypeDescriptionSecurity Use
Filter LogFirewall pass/block decisions with source, destination, port, protocolNetwork access monitoring
Suricata AlertsIDS/IPS signature matches with severity and classificationThreat detection
Suricata EVEFull JSON event log including DNS, HTTP, TLS, file transactionsDeep protocol inspection
System AuthLogin, logout, sudo, SSH events on the OPNsense hostManagement plane security
OpenVPNVPN tunnel connect, disconnect, authentication eventsRemote access monitoring
Unbound DNSDNS query and response logsDNS security, C2 detection
Web ProxyHTTP/HTTPS proxy access logsWeb filtering, data exfiltration
DHCPDHCP lease eventsIP address tracking

Key OPNsense Syslog Facilities

FacilitySourceDescription
filterlogpf firewallFirewall filter decisions
suricataSuricata IDSIntrusion detection alerts
openvpnOpenVPNVPN connection events
unboundUnbound DNSDNS resolver logs
configdConfiguration daemonConfiguration change events
auditAuthenticationLogin and privilege events

Troubleshooting

  • No syslog received: Verify the logging target is enabled and the transport matches the Collector expectation (TCP vs UDP). Check System > Settings > Logging / Targets for status.
  • Filter logs missing: Ensure individual firewall rules have Log enabled, or enable default block/pass logging under Firewall > Settings > Normal.
  • Suricata not alerting: Verify Suricata is running under Services > Intrusion Detection > Administration. Check that rulesets are downloaded and rules are enabled.
  • Timestamps incorrect: Enable RFC5424 format in the syslog target for ISO 8601 timestamps. Verify NTP is configured under Services > Network Time > General.
  • TLS connection failing: Verify the CA certificate is imported and the Collector supports TLS syslog on the configured port. Check OPNsense logs under System > Log Files > General.
  • High filter log volume: Exclude noisy rules (e.g., broadcast traffic) from logging by unchecking Log on those specific firewall rules.

Contact kyra@seekerslab.com for integration support.