<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[block rules not logging]]></title><description><![CDATA[<p dir="auto">I'm seeing a strange issue where traffic set to be logged isn't... logging. Here's an example:<br />
<img src="/assets/uploads/files/1766450709054-4c514635-7d7c-42aa-880c-9b2eb8ec51aa-image.png" alt="4c514635-7d7c-42aa-880c-9b2eb8ec51aa-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">There's nothing in the firewall logs (I'm trying to find the device(s) responsible) - I tried resetting the log files, and that just left it all blank. There's no external syslog in use (there was one configured a while back but it's been disabled). The config looks good, things should just be... logged. Any ideas?</p>
]]></description><link>https://forum.netgate.com/topic/199657/block-rules-not-logging</link><generator>RSS for Node</generator><lastBuildDate>Fri, 06 Mar 2026 04:42:59 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/199657.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 23 Dec 2025 00:48:42 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to block rules not logging on Mon, 29 Dec 2025 19:07:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> the only common package in use is System Patches, and there aren't any non-package-provided patches installed. I'll keep digging.</p>
]]></description><link>https://forum.netgate.com/post/1234243</link><guid isPermaLink="true">https://forum.netgate.com/post/1234243</guid><dc:creator><![CDATA[beatvjiking]]></dc:creator><pubDate>Mon, 29 Dec 2025 19:07:17 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Mon, 29 Dec 2025 18:44:09 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beatvjiking">@<bdi>beatvjiking</bdi></a> well it could still be a bug, but only triggered by some not so common thing. Do you use a specific package across the systems?</p>
<p dir="auto">But yeah its not a bug in the sense that everyone, or big common base of users are hit with it.</p>
]]></description><link>https://forum.netgate.com/post/1234240</link><guid isPermaLink="true">https://forum.netgate.com/post/1234240</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 29 Dec 2025 18:44:09 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Mon, 29 Dec 2025 18:25:41 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> I agree, and I'm going to move forward with the rebuild, and will update after. I just am baffled by this - based on my experiences and the breadth of configurations and systems the issue crosses, it seems like a bug; but as you say, if it were a bug one would expect more people would be seeing it.</p>
]]></description><link>https://forum.netgate.com/post/1234238</link><guid isPermaLink="true">https://forum.netgate.com/post/1234238</guid><dc:creator><![CDATA[beatvjiking]]></dc:creator><pubDate>Mon, 29 Dec 2025 18:25:41 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Mon, 29 Dec 2025 17:52:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beatvjiking">@<bdi>beatvjiking</bdi></a> well something is common between all the units causing the problem.  Finding out what that is the question.</p>
<p dir="auto">If it was some huge bug in 25.11 - why isn't mine showing the problem.. Why are not the 1000's or prob more like 10s of thousands of units out there now running 25.11 not having the issue?</p>
<p dir="auto">I would think if was some common thing causing the issue - the boards would be a flame with people reporting the issue, etc.,</p>
<p dir="auto">So I think the best way forward is since your home system rebuild would cause the least disruption is to attempt to find what is the root of the problem with it.  And then that hopefully points to the common thing that is causing it in your other systems</p>
]]></description><link>https://forum.netgate.com/post/1234232</link><guid isPermaLink="true">https://forum.netgate.com/post/1234232</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 29 Dec 2025 17:52:16 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Mon, 29 Dec 2025 17:33:59 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> <a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> I'll set aside some time in the next few days to rebuild the home unit from scratch and compare the backups. The thing that gives me pause is that the configuration on this unit doesn't really match up in any meaningful way to any of the other machines exhibiting the issue.</p>
<p dir="auto">I found another machine exhibiting it, which only began having the issue on the upgrade to 25.11. That one hasn't had its logs cleared, but it hasn't logged a single blocked packet (despite definitely blocking many) since the upgrade/reboot. It's a completely different piece of hardware (an old C2358 machine with a CF card I use as an IPSec endpoint). Bafflingly, rolling back to the 25.07.1 boot environment does not fix the issue - it's still not logging blocked packets it's configured to log even after booting the old version and config. Comparing the config versions from enabling the firmware upgrade until today reveals absolutely nothing amiss changing in the config (below). I found yet another machine that hasn't logged blocked packets since a 123 seconds after booting into 25.07.1 (which was a clean install on a 7100). It booted, logged blocked packets for about two minutes, then stopped.</p>
<pre><code>--- /tmp/be_mount.6rG2/cf/conf/backup/config-1765562644.xml	2025-12-12 13:04:44.807537000 -0500
+++ /tmp/be_mount.6rG2/cf/conf/config.xml	2025-12-19 09:58:05.558321000 -0500
@@ -1,6 +1,6 @@
&lt;?xml version="1.0"?&gt;
&lt;pfsense&gt;
-	&lt;version&gt;24.0&lt;/version&gt;
+	&lt;version&gt;24.1&lt;/version&gt;
	&lt;lastchange&gt;&lt;/lastchange&gt;
	&lt;system&gt;
		&lt;optimization&gt;normal&lt;/optimization&gt;
@@ -870,9 +870,9 @@
	&lt;qinqs&gt;&lt;/qinqs&gt;
	&lt;laggs&gt;&lt;/laggs&gt;
	&lt;revision&gt;
-		&lt;time&gt;1765562644&lt;/time&gt;
-		&lt;description&gt;&lt;![CDATA[admin@a.b.c.d (Local Database): Saved firmware branch setting.&rsqb;&rsqb;&gt;&lt;/description&gt;
-		&lt;username&gt;&lt;![CDATA[admin@a.b.c.d (Local Database)&rsqb;&rsqb;&gt;&lt;/username&gt;
+		&lt;time&gt;1766156285&lt;/time&gt;
+		&lt;description&gt;&lt;![CDATA[(system): Overwrote previous installation of System Patches.&rsqb;&rsqb;&gt;&lt;/description&gt;
+		&lt;username&gt;&lt;![CDATA[(system)&rsqb;&rsqb;&gt;&lt;/username&gt;
	&lt;/revision&gt;
	&lt;captiveportal&gt;&lt;/captiveportal&gt;
	&lt;gateways&gt;
@@ -901,7 +901,7 @@
		&lt;refid&gt;67574832baa75&lt;/refid&gt;
		&lt;descr&gt;&lt;![CDATA[GUI default (67574832baa75)&rsqb;&rsqb;&gt;&lt;/descr&gt;
		&lt;type&gt;server&lt;/type&gt;
-		&lt;crt&gt;different cert info here==&lt;/crt&gt;
		&lt;prv&gt;different cert info here&lt;/prv&gt;
	&lt;/cert&gt;
	&lt;dhcrelay&gt;&lt;/dhcrelay&gt;
@@ -947,7 +947,7 @@
				most secure, easiest to use, and simplest VPN solution in&amp;lt;br /&amp;gt;
				the industry.&rsqb;&rsqb;&gt;&lt;/descr&gt;
			&lt;pkginfolink&gt;https://github.com/pfsense/FreeBSD-ports/commits/devel/net/pfSense-pkg-WireGuard&lt;/pkginfolink&gt;
-			&lt;version&gt;0.2.9_5&lt;/version&gt;
+			&lt;version&gt;0.2.11&lt;/version&gt;
			&lt;configurationfile&gt;wireguard.xml&lt;/configurationfile&gt;
			&lt;include_file&gt;/usr/local/pkg/wireguard/includes/wg.inc&lt;/include_file&gt;
		&lt;/package&gt;
@@ -955,7 +955,7 @@
			&lt;name&gt;System Patches&lt;/name&gt;
			&lt;internal_name&gt;System_Patches&lt;/internal_name&gt;
			&lt;descr&gt;&lt;![CDATA[A package to apply and maintain custom system patches.&rsqb;&rsqb;&gt;&lt;/descr&gt;
-			&lt;version&gt;2.2.23&lt;/version&gt;
+			&lt;version&gt;2.2.26&lt;/version&gt;
			&lt;configurationfile&gt;systempatches.xml&lt;/configurationfile&gt;
			&lt;include_file&gt;/usr/local/pkg/patches.inc&lt;/include_file&gt;
		&lt;/package&gt;
@@ -971,7 +971,7 @@
	agility. Whether you&amp;#039;re scaling deployments or streamlining network
	management, Netgate Nexus delivers the control and customization you
	need to stay ahead.&rsqb;&rsqb;&gt;&lt;/descr&gt;
-			&lt;version&gt;25.07.1_1&lt;/version&gt;
+			&lt;version&gt;25.11&lt;/version&gt;
			&lt;configurationfile&gt;nexus.xml&lt;/configurationfile&gt;
		&lt;/package&gt;
		&lt;menu&gt;
</code></pre>
]]></description><link>https://forum.netgate.com/post/1234230</link><guid isPermaLink="true">https://forum.netgate.com/post/1234230</guid><dc:creator><![CDATA[beatvjiking]]></dc:creator><pubDate>Mon, 29 Dec 2025 17:33:59 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Sat, 27 Dec 2025 16:21:04 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beatvjiking">@<bdi>beatvjiking</bdi></a> said in <a href="/post/1234067">block rules not logging</a>:</p>
<blockquote>
<p dir="auto">I'd say maybe there was some kind of issue with how it's configured (like trying to parse out the wrong interface's messages or something), rather than a bug causing it to fail.</p>
</blockquote>
<p dir="auto">Possible for sure, something related to weirdness with your interface setups. Recent thread where they were seeing the anti-lock out rule on one of their vlan interfaces vs lan, and they too were having issues with rules.</p>
<p dir="auto">You clearly have something wrong - but what is crazy is you would have the same sort of something wrong on multiple setups.</p>
<p dir="auto">Kind of leaning towards <a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> suggest, just start clean.. When you have logging working.. Then restore rules on the interfaces. Maybe only backup the firewall rules vs complete restore.  But since you would have a clean system, make sure you take a backup of its config.. Before you restore - if the restore breaks the logging you will have files you can compare to what could be causing it.</p>
]]></description><link>https://forum.netgate.com/post/1234073</link><guid isPermaLink="true">https://forum.netgate.com/post/1234073</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sat, 27 Dec 2025 16:21:04 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Sat, 27 Dec 2025 16:06:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beatvjiking">@<bdi>beatvjiking</bdi></a> Fresh install and config restore is your best option. Something is corrupted. Not worth identifying what.</p>
]]></description><link>https://forum.netgate.com/post/1234070</link><guid isPermaLink="true">https://forum.netgate.com/post/1234070</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Sat, 27 Dec 2025 16:06:52 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Sat, 27 Dec 2025 15:58:24 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> raw logging+reboot = no go, unfortunately. I'm wondering if there's a good way for me to look at the raw output of pflog - it seems pfSense does something to capture and manage that information using the filterlog process.</p>
<p dir="auto">As an experiment I set up a syslog server on my home network and directed pfSense to send its output there, and it was able to capture everything pfSense is capturing log-wise, but still nothing from the firewall.</p>
<pre><code>root    27982   0.0  0.1  15000  3776  -  Ss   Fri01      0:05.84 /usr/local/sbin/filterlog -i pflog0 -p /var/run/filterlog.pid
</code></pre>
<p dir="auto">The filterlog process seems to be the next place to focus troubleshooting, but some googling makes it seem like it's sort of a black box - a simple one, but not one that people seem to have issues with in terms of troubleshooting. Any ideas on where to start looking? If I had to guess, I'd say maybe there was some kind of issue with how it's configured (like trying to parse out the wrong interface's messages or something), rather than a bug causing it to fail.</p>
]]></description><link>https://forum.netgate.com/post/1234067</link><guid isPermaLink="true">https://forum.netgate.com/post/1234067</guid><dc:creator><![CDATA[beatvjiking]]></dc:creator><pubDate>Sat, 27 Dec 2025 15:58:24 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Thu, 25 Dec 2025 14:39:53 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> the raw logging plus reboot makes logical sense since it'd restart pflog/filterlog in addition to changing the configuration. I'll do so when there are fewer people in my house :)</p>
]]></description><link>https://forum.netgate.com/post/1233951</link><guid isPermaLink="true">https://forum.netgate.com/post/1233951</guid><dc:creator><![CDATA[beatvjiking]]></dc:creator><pubDate>Thu, 25 Dec 2025 14:39:53 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Thu, 25 Dec 2025 02:08:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> nice catch</p>
<pre><code>[25.11-RELEASE][admin@sg4860.home.arpa]/: ps -A | grep syslogd
94189  -  SCs      0:02.15 /usr/sbin/syslogd -O rfc3164 -s -c -c -l /var/dhcpd/var/run/log -l /tmp/haproxy_chroot/var/run/log -P /var/run/syslog.pid -f /etc/syslog.conf
95527  -  I        0:00.01 syslogd: syslogd.casper (syslogd)
96345  -  Is       0:00.00 syslogd: system.net (syslogd)
57942  0  S+       0:00.00 grep syslogd
[25.11-RELEASE][admin@sg4860.home.arpa]/: 
</code></pre>
<p dir="auto">Really odd - I have no issues..</p>
]]></description><link>https://forum.netgate.com/post/1233930</link><guid isPermaLink="true">https://forum.netgate.com/post/1233930</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Thu, 25 Dec 2025 02:08:16 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Wed, 24 Dec 2025 21:59:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beatvjiking">@<bdi>beatvjiking</bdi></a> I might suggest 'raw logging' <em>plus</em> a reboot for good measure. But I'm running out of weak suggestions.</p>
]]></description><link>https://forum.netgate.com/post/1233923</link><guid isPermaLink="true">https://forum.netgate.com/post/1233923</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Wed, 24 Dec 2025 21:59:40 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Wed, 24 Dec 2025 21:32:12 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> I had seen that box so many times over the last 24 hours it stopped mentally registering, lol. I checked it, saved, reset the log files. Still nothing, but I am indeed learning!</p>
]]></description><link>https://forum.netgate.com/post/1233922</link><guid isPermaLink="true">https://forum.netgate.com/post/1233922</guid><dc:creator><![CDATA[beatvjiking]]></dc:creator><pubDate>Wed, 24 Dec 2025 21:32:12 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Wed, 24 Dec 2025 21:18:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> Oh. It's because you included a colon in your <code>grep</code> string.</p>
]]></description><link>https://forum.netgate.com/post/1233921</link><guid isPermaLink="true">https://forum.netgate.com/post/1233921</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Wed, 24 Dec 2025 21:18:52 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Wed, 24 Dec 2025 21:18:07 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> Weird because mine matches (in addition to an HAproxy logging hook). I assumed that was <em>the</em> operative <code>syslogd</code> process. But maybe not.</p>
<p dir="auto">Obligatory mention that I'm on CE <code>2.8.1-RELEASE</code> over here.</p>
<pre><code>ps -A | grep syslogd
89854  -  SCs      0:02.20 /usr/sbin/syslogd -O rfc5424 -s -c -c -l /var/dhcpd/var/run/log -l /tmp/haproxy_chroot/var/run/log -P /var/run/syslog.pid -f /etc/syslog.conf
91058  -  I        0:00.00 syslogd: syslogd.casper (syslogd)
91991  -  Is       0:00.00 syslogd: system.net (syslogd)
56861  1  S+       0:00.00 grep syslogd
</code></pre>
]]></description><link>https://forum.netgate.com/post/1233920</link><guid isPermaLink="true">https://forum.netgate.com/post/1233920</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Wed, 24 Dec 2025 21:18:07 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Wed, 24 Dec 2025 21:14:33 GMT]]></title><description><![CDATA[<p dir="auto">Not sure what that first line is on your grep output, I do not show that</p>
<pre><code>[25.11-RELEASE][admin@sg4860.home.arpa]/: ps -A | grep syslogd:
95527  -  I        0:00.00 syslogd: syslogd.casper (syslogd)
96345  -  Is       0:00.00 syslogd: system.net (syslogd)
57157  0  S+       0:00.00 grep syslogd:
[25.11-RELEASE][admin@sg4860.home.arpa]/: 
</code></pre>
]]></description><link>https://forum.netgate.com/post/1233919</link><guid isPermaLink="true">https://forum.netgate.com/post/1233919</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Wed, 24 Dec 2025 21:14:33 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Wed, 24 Dec 2025 21:10:04 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beatvjiking">@<bdi>beatvjiking</bdi></a> There's a checkbox, "<code>Show raw filter logs</code>", on the logs settings page. I was suggesting you try <em>that</em>, and only because you got me thinking about <a href="https://docs.netgate.com/pfsense/en/latest/monitoring/logs/raw-filter-format.html" target="_blank" rel="noopener noreferrer nofollow ugc">the relationship between system logging and <code>syslogd</code></a> (something I hadn't previously considered).</p>
<p dir="auto">We're both learning here! lol</p>
]]></description><link>https://forum.netgate.com/post/1233918</link><guid isPermaLink="true">https://forum.netgate.com/post/1233918</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Wed, 24 Dec 2025 21:10:04 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Wed, 24 Dec 2025 20:35:55 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> Switched to syslog (the RFC5424 option, I assume), saved, reset the logs, saved, and unfortunately no go.</p>
<p dir="auto">/var/etc/syslog.d/pfSense.conf contents - it looks like it probably should from what I can tell:</p>
<pre><code># Automatically generated, do not edit!
!*
auth.*;authpriv.*                                       /var/log/auth.log
!radvd
*.err                                                           /var/log/routing.log
!routed,zebra,ospfd,ospf6d,bgpd,watchfrr,miniupnpd,igmpproxy
*.*                                                                     /var/log/routing.log
!ntp,ntpd,ntpdate
*.*                                                                     /var/log/ntpd.log
!ppp
*.*                                                                     /var/log/ppp.log
!poes
*.*                                                                     /var/log/poes.log
!l2tps
*.*                                                                     /var/log/l2tps.log
!charon,ipsec_starter
*.*                                                                     /var/log/ipsec.log
!openvpn
*.*                                                                     /var/log/openvpn.log
!dpinger
*.*                                                                     /var/log/gateways.log
!dnsmasq,named,filterdns,unbound
*.*                                                                     /var/log/resolver.log
!dhcpd,dhcrelay,dhclient,dhcp6c,dhcpleases,dhcpleases6,kea2fib6,kea2unbound,kea-dhcp4,kea-dhcp6
*.*                                                                     /var/log/dhcpd.log
!hostapd
*.*                                                             /var/log/wireless.log
!filterlog
*.*                                                             /var/log/filter.log
!logportalauth
*.*                                                             /var/log/portalauth.log
!watchdogd
*.*                                                             /var/log/watchdogd.log
!-bgpd,charon,dhclient,dhcp6c,dhcpd,dhcrelay,dnsmasq,dpinger,filterdns,filterlog,hostapd,igmpproxy,ipsec_starter,kea-dhcp4,kea-dhcp6,unbound,kea2fib6,kea2unbound,l2tps,miniupnpd,named,ntp,ntpd,ntpdate,openvpn,ospf6d,ospfd,poes,radvd,routed,watchfrr,zebra
local3.*                                                        /var/log/vpn.log
local5.*                                                        /var/log/nginx.log
*.notice;kern.debug;lpr.info;mail.crit;daemon.none;news.err;local0.none;local3.none;local4.none;local7.none;security.*;auth.info;authpriv.info;daemon.info      /var/log/system.log
*.emerg                                                         *
!*
:msg, startswith, "if_pppoe: "
*.*                                                             /var/log/ppp.log
:*
</code></pre>
]]></description><link>https://forum.netgate.com/post/1233915</link><guid isPermaLink="true">https://forum.netgate.com/post/1233915</guid><dc:creator><![CDATA[beatvjiking]]></dc:creator><pubDate>Wed, 24 Dec 2025 20:35:55 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Wed, 24 Dec 2025 20:17:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beatvjiking">@<bdi>beatvjiking</bdi></a> Try flipping on raw logs. Reset log files again after doing so (i.e., two separate saves).</p>
<p dir="auto"><code>/var/etc/syslog.d/pfSense.conf</code> looks intact?</p>
]]></description><link>https://forum.netgate.com/post/1233913</link><guid isPermaLink="true">https://forum.netgate.com/post/1233913</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Wed, 24 Dec 2025 20:17:40 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Wed, 24 Dec 2025 19:52:07 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> Services shows syslogd running - it's generating logs for itself and other services on the machine. If I had to guess I'd say there has to be something going on with the interaction between filterlog and syslogd, but that's a part of the OS I don't have a lot of familiarity with in FreeBSD. I also don't know how any configuration options in pfSense would mess with that.</p>
<p dir="auto">ps -A | grep syslogd:</p>
<pre><code>69461  -  SCs      0:00.90 /usr/sbin/syslogd -O rfc3164 -s -c -c -l /var/dhcpd/var/run/log -P /var/run/syslog.pid -f /etc/syslog.conf
72847  -  I        0:00.01 syslogd: syslogd.casper (syslogd)
73151  -  Is       0:00.00 syslogd: system.net (syslogd)
68064  1  S+       0:00.00 grep syslogd
</code></pre>
]]></description><link>https://forum.netgate.com/post/1233911</link><guid isPermaLink="true">https://forum.netgate.com/post/1233911</guid><dc:creator><![CDATA[beatvjiking]]></dc:creator><pubDate>Wed, 24 Dec 2025 19:52:07 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Wed, 24 Dec 2025 19:36:08 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beatvjiking">@<bdi>beatvjiking</bdi></a> Does <code>Status / Services</code> show <code>syslogd</code> running? Output of <code>ps -A | grep syslogd</code>?</p>
]]></description><link>https://forum.netgate.com/post/1233910</link><guid isPermaLink="true">https://forum.netgate.com/post/1233910</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Wed, 24 Dec 2025 19:36:08 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Wed, 24 Dec 2025 17:10:56 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> no syslog-ng, no sending logs anywhere else. No exotic partitioning, just the default installer ZFS setup. Nothing weird with NAT. Some of the other affected machines are in failover pairs and NAT through their virtual CARP-managed IP, but there's nothing of that sort going on here.</p>
]]></description><link>https://forum.netgate.com/post/1233892</link><guid isPermaLink="true">https://forum.netgate.com/post/1233892</guid><dc:creator><![CDATA[beatvjiking]]></dc:creator><pubDate>Wed, 24 Dec 2025 17:10:56 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Wed, 24 Dec 2025 17:07:18 GMT]]></title><description><![CDATA[<p dir="auto">it’s extreme but maybe set one to defaults temporarily and check. If it works compare config files. If not then it seems something on the router(s)…reinstall?</p>
]]></description><link>https://forum.netgate.com/post/1233891</link><guid isPermaLink="true">https://forum.netgate.com/post/1233891</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Wed, 24 Dec 2025 17:07:18 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Wed, 24 Dec 2025 17:04:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beatvjiking">@<bdi>beatvjiking</bdi></a> I'm perplexed—further confounded only by you seeing this on multiple systems.</p>
<p dir="auto">No <code>syslog-ng</code> install or otherwsie any log shipping or anything?</p>
<p dir="auto">Big system disk. No exotic partitioning? Exotic ZFS config?</p>
<p dir="auto">You already confirmed no RAM disk.</p>
<p dir="auto">Ruleset looks fine (if not exceedingly straightfoward).</p>
<p dir="auto">Are you doing anything particular with NAT?</p>
]]></description><link>https://forum.netgate.com/post/1233890</link><guid isPermaLink="true">https://forum.netgate.com/post/1233890</guid><dc:creator><![CDATA[tinfoilmatt]]></dc:creator><pubDate>Wed, 24 Dec 2025 17:04:23 GMT</pubDate></item><item><title><![CDATA[Reply to block rules not logging on Wed, 24 Dec 2025 16:36:48 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tinfoilmatt">@<bdi>tinfoilmatt</bdi></a> the other machines are running pfSense+ 25.11 but running on a variety of hardware. There are some roll-your-own machines, some 8200s, 7100s, 1537s, etc. The other Netgate hardware isn't altered from factory.</p>
<p dir="auto">By "removing the state limiter" I meant removing the advanced rule option to limit states per device on the default allow. I normally add it to prevent resource exhaustion at the firewall, but wondered if adding it interfered with logging, so I removed it. It didn't change anything.</p>
]]></description><link>https://forum.netgate.com/post/1233885</link><guid isPermaLink="true">https://forum.netgate.com/post/1233885</guid><dc:creator><![CDATA[beatvjiking]]></dc:creator><pubDate>Wed, 24 Dec 2025 16:36:48 GMT</pubDate></item></channel></rss>