OPNsense Forum

Archive => 20.7 Legacy Series => Topic started by: lshantz on July 28, 2020, 03:37:50 am

Title: Firewall Live View filtering
Post by: lshantz on July 28, 2020, 03:37:50 am
Something has either broken or changed.

The live view is an incredibly useful troubleshooting log because I was able to filter on Interface port and even down to an IP address. Filtering by IP address allows me to view a particular device I'm having issues with.

All of a sudden since the last update, (possibly the one before the last one) I can no longer filter on IP address. it ignores the filter and shows all.

Is this a bug that was introduced or has the way it worked changed?
Title: Re: Firewall Live View filtering
Post by: mimugmail on July 28, 2020, 06:21:02 am
The UI changed with 20.1.8. The default search condition is "Action", just check the dropdown field
Title: Re: Firewall Live View filtering
Post by: lshantz on July 28, 2020, 05:36:49 pm
I saw that, but I can't seem to figure it out. For instance. Say I want to ONLY see one IP address.

Let's say it is 192.168.1.12 and it is on interface LAN. I would think the default of "action" "contains" with the IP address typed in, should yield the desired results no? If I click the + sign, it drops it down to a little box and NOTHING shows. Is it the UI is confusing, or is it borked?
Title: Re: Firewall Live View filtering
Post by: gpb on July 28, 2020, 07:15:53 pm
For IP addresses I think only SRC or DST are valid, not "action".  Action I think is for allow, reject and block but using those words doesn't filter anything...not sure what valid values for Action are.

Edit: "pass" is one of the valid actions.  Clicking the "i" to the right of each line probably reveals other valid values.
Title: Re: Firewall Live View filtering
Post by: cguilford on July 28, 2020, 07:19:33 pm
change to SRC and Contains whatever ip should get what you want
Title: Re: Firewall Live View filtering
Post by: lshantz on July 28, 2020, 09:39:39 pm
Okay, kind of sort of works like the old way. I'm sure this is far more granular. Just not very intuitive. Thanks much
Title: Re: Firewall Live View filtering
Post by: franco on July 29, 2020, 01:40:52 pm
Ironic, a number of people complained it wasn't intuitive before. Some found it not flexible. It's hard to get this right for everyone I guess...

That being said, it might be nice to have a select box if the filter is actually a fixed set of values just to make it more clear and less error-prone.


Cheers,
Franco
Title: Re: Firewall Live View filtering
Post by: lshantz on July 29, 2020, 05:25:26 pm
HA! That is the rub. You can't please all people all the time. The tip you gave me DID help and I'm almost making it work now. It may be buggy still since it is a recent roll out? I still have the static log I can use and packet traces, so all is good.
Title: Re: Firewall Live View filtering
Post by: siga75 on July 30, 2020, 04:03:12 pm
I would just add:

Another issue I have is I usually flag the resolve DNS box, which means I have no IP to use as a filter, maybe a tooltip on the DNS field that show the actual IP address
Title: Re: Firewall Live View filtering
Post by: Simser on July 31, 2020, 09:32:58 am
To make basic filtering fast and easy again, I would just add "any" in the first dropdown, which works just like the old filter, and make it default. If someone wishes advanced filtering, then they could use the dropdowns.
Title: Re: Firewall Live View filtering
Post by: d0zr on August 03, 2020, 03:27:46 pm
+1 to that, the options aren't immediately clear, once you realise how to use the parameters, it works. 

IIRC the filter dialogue popped over the list, so hard to reference the columns (or maybe they were blank at the beginning), so made it a bit harder when choosing what to filter.

Needs a few of the options in the dialogue, and/or the help.