crowdsecurity / pfSense-pkg-crowdsec

54 stars 2 forks source link

Hidden firewall rules + logs #93

Open andrebrait opened 2 months ago

andrebrait commented 2 months ago

Why are the firewall rules hidden? I understand it may be concerning that users might touch them, but pfBlockerNG lets you see its rules (and lets you set then as floating rules) just fine.

In turn, perhaps as a consequence of the rules being hidden, it seems that blocked connections on the firewall logs are being logged with the Rule value set to @0 for what seems to be CrowdSec.

LaurenceJJones commented 2 months ago

Why are the firewall rules hidden?

Cause the rules are floating by default and floating rules are hidden by the GUI also by default I believe (not an active pfsense user here but "dabbled")

andrebrait commented 2 months ago

Why are the firewall rules hidden?

Cause the rules are floating by default and floating rules are hidden by the GUI also by default I believe (not an active pfsense user here but "dabbled")

You mean those not defined by users, right? I wonder if pfBlockerNG is setting them in some special way. I never touched that part of its code (I only worked on the DNSBL side and on the Python integration with Unbound).

I'll check that later.

Either way, visible (which is my preference and can perhaps be achieved with a simple toggle rather than having to write the entire rule by hand) or not, there's the @0 problem, still.