跳至正文

pfSense Integration

Overview

pfSense is a popular open-source firewall and router platform based on FreeBSD. KYRA MDR collects pfSense filter logs, system events, and package logs via syslog for security monitoring. Supports pfSense CE and pfSense Plus.

Prerequisites

  • A KYRA MDR Collector installed and running
  • pfSense with administrative web interface access
  • Network connectivity from pfSense to the collector on port 514
  • pfSense 2.6 or later recommended

Configuration

Configure remote syslog in pfSense:

  1. Navigate to Status > System Logs > Settings
  2. Under Remote Logging Options, check Enable Remote Logging
  3. Configure:
SettingValue
Source AddressDefault (any)
IP ProtocolIPv4
Remote Syslog Servers<collector-ip>:514
Remote Syslog ContentsEverything
  1. Click Save

Enable firewall log forwarding by ensuring Log packets matched from the default block rules is enabled under Status > System Logs > Settings.

Example pfSense Syslog Output

# Firewall filter log (CSV format)
<134>1 2025-01-15T10:23:45+09:00 pfsense filterlog 12345 - - 5,,,1000000103,igb0,match,block,in,4,0x0,,64,12345,0,DF,6,tcp,60,192.168.1.100,10.0.0.1,54321,443,0,S,123456789,,65535,,mss;nop;wscale
# System event
<86>1 2025-01-15T10:24:00+09:00 pfsense sshguard - - - Attack from 203.0.113.50 on service SSH
# Suricata IDS alert (if installed)
<133>1 2025-01-15T10:25:00+09:00 pfsense suricata[6789]: [1:2024897:3] ET MALWARE Known RAT Command and Control Traffic

CLI Verification (from pfSense Shell)

Terminal window
# Test syslog forwarding from pfSense shell
logger -p local0.info "KYRA MDR test from pfSense"
# Check if syslog is configured in the config
grep -A5 "syslog" /conf/config.xml | head -20
# Verify remote syslog daemon status
sockstat -4 | grep syslog
# On the KYRA Collector, verify incoming pfSense logs
sudo tcpdump -i any port 514 -A | grep "filterlog\|pfsense"

Collected Log Types

Log TypeDescriptionSecurity Use
FirewallFilter rule match eventsIntrusion attempts, policy violations
SystemOS-level events and servicesHost integrity monitoring
DHCPIP address assignmentsAsset tracking, rogue device detection
OpenVPNVPN tunnel eventsRemote access monitoring
Suricata/SnortIDS/IPS alerts (if installed)Threat detection
DNS ResolverDNS query logsDNS tunneling, C2 detection

Troubleshooting

No logs forwarded: Confirm that remote logging is enabled and the correct IP and port are configured. Test with logger -p local0.info test from the pfSense shell.

Missing firewall logs: By default, pfSense only logs blocked traffic. To log passed traffic, edit individual firewall rules and enable logging.

High volume: pfSense can generate significant log volume with default block logging. Consider filtering to specific interfaces or rules.

Contact kyra@seekerslab.com for support.