Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
20.7 Legacy Series
»
Firewall Live View filtering
« previous
next »
Print
Pages: [
1
]
Author
Topic: Firewall Live View filtering (Read 7570 times)
lshantz
Full Member
Posts: 109
Karma: 3
Firewall Live View filtering
«
on:
July 28, 2020, 03:37:50 am »
Something has either broken or changed.
The live view is an incredibly useful troubleshooting log because I was able to filter on Interface port and even down to an IP address. Filtering by IP address allows me to view a particular device I'm having issues with.
All of a sudden since the last update, (possibly the one before the last one) I can no longer filter on IP address. it ignores the filter and shows all.
Is this a bug that was introduced or has the way it worked changed?
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: Firewall Live View filtering
«
Reply #1 on:
July 28, 2020, 06:21:02 am »
The UI changed with 20.1.8. The default search condition is "Action", just check the dropdown field
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
lshantz
Full Member
Posts: 109
Karma: 3
Re: Firewall Live View filtering
«
Reply #2 on:
July 28, 2020, 05:36:49 pm »
I saw that, but I can't seem to figure it out. For instance. Say I want to ONLY see one IP address.
Let's say it is 192.168.1.12 and it is on interface LAN. I would think the default of "action" "contains" with the IP address typed in, should yield the desired results no? If I click the + sign, it drops it down to a little box and NOTHING shows. Is it the UI is confusing, or is it borked?
Logged
gpb
Full Member
Posts: 234
Karma: 13
Re: Firewall Live View filtering
«
Reply #3 on:
July 28, 2020, 07:15:53 pm »
For IP addresses I think only SRC or DST are valid, not "action". Action I think is for allow, reject and block but using those words doesn't filter anything...not sure what valid values for Action are.
Edit: "pass" is one of the valid actions. Clicking the "i" to the right of each line probably reveals other valid values.
«
Last Edit: July 28, 2020, 11:45:31 pm by gpb
»
Logged
HP T730/AMD RX-427BB/8GB/500GB SSD
HP NC365T 4-PORT
cguilford
Full Member
Posts: 130
Karma: 15
Re: Firewall Live View filtering
«
Reply #4 on:
July 28, 2020, 07:19:33 pm »
change to SRC and Contains whatever ip should get what you want
Logged
lshantz
Full Member
Posts: 109
Karma: 3
Re: Firewall Live View filtering
«
Reply #5 on:
July 28, 2020, 09:39:39 pm »
Okay, kind of sort of works like the old way. I'm sure this is far more granular. Just not very intuitive. Thanks much
Logged
franco
Administrator
Hero Member
Posts: 17656
Karma: 1610
Re: Firewall Live View filtering
«
Reply #6 on:
July 29, 2020, 01:40:52 pm »
Ironic, a number of people complained it wasn't intuitive before. Some found it not flexible. It's hard to get this right for everyone I guess...
That being said, it might be nice to have a select box if the filter is actually a fixed set of values just to make it more clear and less error-prone.
Cheers,
Franco
Logged
lshantz
Full Member
Posts: 109
Karma: 3
Re: Firewall Live View filtering
«
Reply #7 on:
July 29, 2020, 05:25:26 pm »
HA! That is the rub. You can't please all people all the time. The tip you gave me DID help and I'm almost making it work now. It may be buggy still since it is a recent roll out? I still have the static log I can use and packet traces, so all is good.
Logged
siga75
Full Member
Posts: 185
Karma: 11
Re: Firewall Live View filtering
«
Reply #8 on:
July 30, 2020, 04:03:12 pm »
I would just add:
OR clause, the default is and harcoded AND
generic host, that can be both src or dst (just like tcpdump)
filter on rule description (the content not the rule ID)
Another issue I have is I usually flag the resolve DNS box, which means I have no IP to use as a filter, maybe a tooltip on the DNS field that show the actual IP address
Logged
https://www.signorini.ch
Protectli Pfsense Mi7500L6 Intel 7Th Gen Core I7 7500U 16Gb Ddr4 Ram
512Gb Msata Ssd
6 X Intel Gigabit Ethernet
Simser
Newbie
Posts: 7
Karma: 3
Re: Firewall Live View filtering
«
Reply #9 on:
July 31, 2020, 09:32:58 am »
To make basic filtering fast and easy again, I would just add "any" in the first dropdown, which works just like the old filter, and make it default. If someone wishes advanced filtering, then they could use the dropdowns.
Logged
d0zr
Newbie
Posts: 4
Karma: 0
Re: Firewall Live View filtering
«
Reply #10 on:
August 03, 2020, 03:27:46 pm »
+1 to that, the options aren't immediately clear, once you realise how to use the parameters, it works.
IIRC the filter dialogue popped over the list, so hard to reference the columns (or maybe they were blank at the beginning), so made it a bit harder when choosing what to filter.
Needs a few of the options in the dialogue, and/or the help.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
20.7 Legacy Series
»
Firewall Live View filtering