pfSense Integration
Overview
pfSense is a popular open-source firewall and router platform based on FreeBSD. KYRA MDR collects pfSense filter logs, system events, and package logs via syslog for security monitoring. Supports pfSense CE and pfSense Plus.
Prerequisites
- A KYRA MDR Collector installed and running
- pfSense with administrative web interface access
- Network connectivity from pfSense to the collector on port 514
- pfSense 2.6 or later recommended
Configuration
Configure remote syslog in pfSense:
- Navigate to Status > System Logs > Settings
- Under Remote Logging Options, check Enable Remote Logging
- Configure:
| Setting | Value |
|---|---|
| Source Address | Default (any) |
| IP Protocol | IPv4 |
| Remote Syslog Servers | <collector-ip>:514 |
| Remote Syslog Contents | Everything |
- Click Save
Enable firewall log forwarding by ensuring Log packets matched from the default block rules is enabled under Status > System Logs > Settings.
Example pfSense Syslog Output
# Firewall filter log (CSV format)<134>1 2025-01-15T10:23:45+09:00 pfsense filterlog 12345 - - 5,,,1000000103,igb0,match,block,in,4,0x0,,64,12345,0,DF,6,tcp,60,192.168.1.100,10.0.0.1,54321,443,0,S,123456789,,65535,,mss;nop;wscale
# System event<86>1 2025-01-15T10:24:00+09:00 pfsense sshguard - - - Attack from 203.0.113.50 on service SSH
# Suricata IDS alert (if installed)<133>1 2025-01-15T10:25:00+09:00 pfsense suricata[6789]: [1:2024897:3] ET MALWARE Known RAT Command and Control TrafficCLI Verification (from pfSense Shell)
# Test syslog forwarding from pfSense shelllogger -p local0.info "KYRA MDR test from pfSense"
# Check if syslog is configured in the configgrep -A5 "syslog" /conf/config.xml | head -20
# Verify remote syslog daemon statussockstat -4 | grep syslog
# On the KYRA Collector, verify incoming pfSense logssudo tcpdump -i any port 514 -A | grep "filterlog\|pfsense"Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Firewall | Filter rule match events | Intrusion attempts, policy violations |
| System | OS-level events and services | Host integrity monitoring |
| DHCP | IP address assignments | Asset tracking, rogue device detection |
| OpenVPN | VPN tunnel events | Remote access monitoring |
| Suricata/Snort | IDS/IPS alerts (if installed) | Threat detection |
| DNS Resolver | DNS query logs | DNS tunneling, C2 detection |
Troubleshooting
No logs forwarded: Confirm that remote logging is enabled and the correct IP and port are configured. Test with logger -p local0.info test from the pfSense shell.
Missing firewall logs: By default, pfSense only logs blocked traffic. To log passed traffic, edit individual firewall rules and enable logging.
High volume: pfSense can generate significant log volume with default block logging. Consider filtering to specific interfaces or rules.
Contact kyra@seekerslab.com for support.