Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
Tracking down logged rule
« previous
next »
Print
Pages: [
1
]
Author
Topic: Tracking down logged rule (Read 988 times)
Taomyn
Sr. Member
Posts: 444
Karma: 20
Tracking down logged rule
«
on:
July 10, 2020, 09:05:20 am »
I just finished setting up my replacement firewall and one of the additions was to create a DMZ using a dedicated NIC - I only have one public IP, the DMZ will only have one device hosted on it (a honeypot). So far everything looks good and I have created some NAT rules: one that diverts a specific set of IPs (an alias I created) to the DMZ'd device, and a second NAT rule to catch anything not already diverted to other internal hosts to the same. I also enabled logging for the time being so I can check on things, to be disabled later.
While monitoring the firewall logs with the live view I have noticed traffic logged that is being sent to the DMZ'd host as expected, but it's not from my rules. There is nothing in the description and I cannot find where this rule is. I did try looking up the rule, 64, but it mentions IPv6 which is not what this is at least I shouldn't be.
Hopefully the attached screenshots can show what I mean.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
Tracking down logged rule