pfSense

You can configure a pfSense® firewall to forward syslog logs to the ThreatDefence (TD) Syslog Forwarder for security monitoring.


Requirements

  • A deployed and activated ThreatDefence Syslog Forwarder VM

  • Administrator access to the pfSense firewall


Steps

Step 1. Access pfSense Syslog Settings

  1. Sign in to your pfSense WebGUI with administrator permissions.

  2. Navigate to: Status → System Logs → Settings


Step 2. Configure Remote Syslog Server

  1. In the Remote Syslog Servers section, add your TD Syslog Forwarder:

    • IP Address — Enter the IP address of your TD Syslog Forwarder

    • Port — Use the appropriate port (as per the Syslog Onboarding Guide)

    • Transport — Select UDP

  2. Under System Events to Send to Syslog, enable:

    • Firewall Events

    • System Events

    • VPN Events (if applicable)

    • DHCP/DNS Events (if applicable)

  3. Click Save



Step 4. Provide Details to ThreatDefence

Once configuration is complete, provide the following details to ThreatDefence Support at 📧 [email protected]:

  • Firewall make/model and pfSense version

  • Source IP address and used port number.

Last updated