Hub
Network

pfSense Firewall and IPsec

Remote syslog stream of one pfSense CE 2.9.0 firewall with eight site-to-site IPsec tunnels: filterlog records for LAN passes, WAN default-deny blocks and enc0 traffic through the tunnels, and charon records for Phase 1 lookups, failed and successful negotiations, CHILD_SA closures and IKE_SA deletions, as ECS JSON with the RFC 5424 line in event.original. Recurring episodes show a peer offering wrong identities until its tunnel comes up, followed by administrative access through it.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/network-pfsense/generator.yml \
  --id network-pfsense \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
filterlog pass LANLAN pass, rule 11552.34% measured sharenetwork
filterlog block WANWAN default deny, rule 525.44% measured sharenetwork
filterlog pass enc0IPsec (enc0) pass, rule 14620.27% measured sharenetwork
ipsec-peer-lookupcharon looking for pre-shared key peer configs matching ...0.53% measured sharenetwork
ipsec-ike-establishedcharon IKE_SA ... established between ...0.30% measured sharenetwork
ipsec-child-establishedcharon CHILD_SA ... established with SPIs ...0.30% measured sharenetwork
ipsec-child-closedcharon closing CHILD_SA ... with SPIs ...0.29% measured sharenetwork
ipsec-ike-deletingcharon deleting IKE_SA ... between ...0.29% measured sharenetwork
ipsec-peer-not-foundcharon no peer config found0.23% measured sharenetwork

Realism Features

  • About 12,900 records per day. LAN and enc0 traffic follow a daily curve of about 133 records an hour at night to 750 at the 10:00-12:00 peak; WAN default-deny probes arrive at 143 an hour around the clock, with scanners sending one to four probes. Rates are synthetic workload choices.
  • Each of eight site-to-site tunnels has its own lifecycle: negotiation, IKE_SA and CHILD_SA establishment, a lognormal lifetime (median 2.5 h), closure and deletion, and a lognormal pause (median 1 h). Some attempts offer a wrong Phase 1 identity and are retried until corrected or given up, so repeated failures and failures followed by a successful negotiation are ordinary. No tunnel is assumed up at the start of a run.
  • Every enc0 pass requires an active CHILD_SA of its site, and closing and deleting records carry the native IDs, SPIs and selectors of the established SA. Administrative ports carry about a quarter of enc0 traffic, often followed by further management sessions from the same host to the same server. A pass record means a packet matched a pass rule, not that a connection or authentication succeeded.
  • Records of the same moment (a lookup and its failure, IKE_SA and CHILD_SA, closure and deletion) are median 4-5 s apart and at most about 70 s at night, where real charon writes them within milliseconds.
  • Selected profile: IPv4 TCP SYN and UDP DNS records, IKEv1 PSK site-to-site tunnels and default enc0 filtering; IPv6, ICMP, DHCP, NAT translation, OpenVPN, administrator logins and the full IKE exchange are not modeled. Real tunnels usually rekey without going down; the down periods stand for idle, DPD and reauthentication teardowns. CHILD_SA byte counters are synthetic.
  • No complete CE 2.9.0 capture was found: filterlog grammar comes from Netgate documentation, charon bodies from Netgate troubleshooting examples and older real pfSense records, and close/delete bodies from upstream strongSwan 5.9.14. ECS source and destination on charon lines are derived from the message text, and live SIEM/parser compatibility is not verified.

Sample Output

{
  "@timestamp": "2026-09-01T10:19:59.653536+00:00",
  "data_stream": {
    "dataset": "pfsense.log",
    "namespace": "default",
    "type": "logs"
  },
  "destination": {
    "ip": "203.0.113.1"
  },
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "ipsec-ike-established",
    "category": [
      "network"
    ],
    "dataset": "pfsense.log",
    "kind": "event",
    "original": "\u003c30\u003e1 2026-09-01T10:19:59.653536+00:00 fw01.corp.example charon 18610 - - 10[IKE] \u003ccon2|803\u003e IKE_SA con2[803] established between 203.0.113.1[203.0.113.1]...198.51.100.2[198.51.100.2]",
    "type": [
      "info"
    ]
  },
  "host": {
    "name": "fw01.corp.example"
  },
  "log": {
    "syslog": {
      "priority": 30
    }
  },
  "message": "10[IKE] \u003ccon2|803\u003e IKE_SA con2[803] established between 203.0.113.1[203.0.113.1]...198.51.100.2[198.51.100.2]",
  "observer": {
    "name": "fw01.corp.example",
    "product": "pfSense",
    "type": "firewall",
    "vendor": "Netgate",
    "version": "2.9.0"
  },
  "process": {
    "name": "charon",
    "pid": 18610
  },
  "related": {
    "ip": [
      "198.51.100.2",
      "203.0.113.1"
    ]
  },
  "source": {
    "ip": "198.51.100.2"
  },
  "syslog": {
    "facility": {
      "code": 3
    },
    "priority": 30,
    "severity": {
      "code": 6
    }
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueInclude recurring identity-mismatch tunnel episodes; false produces background only
anomaly_interval_hours24Episode interval in hours, minimum 4
hostnamefw01.corp.exampleFirewall host name in the syslog header, host.name and observer.name
wan_ip203.0.113.1WAN address: local IKE endpoint and target of blocked probes
ipsec_pass_rule_tracker1534283903Tracker of the logged IPsec-tab pass rule

Related Generators