pfSense Firewall and IPsec
Remote syslog stream of one pfSense CE 2.9.0 firewall with eight site-to-site IPsec tunnels: filterlog records for LAN passes, WAN default-deny blocks and enc0 traffic through the tunnels, and charon records for Phase 1 lookups, failed and successful negotiations, CHILD_SA closures and IKE_SA deletions, as ECS JSON with the RFC 5424 line in event.original. Recurring episodes show a peer offering wrong identities until its tunnel comes up, followed by administrative access through it.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/network-pfsense/generator.yml \
--id network-pfsense \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| filterlog pass LAN | LAN pass, rule 115 | 52.34% measured share | network |
| filterlog block WAN | WAN default deny, rule 5 | 25.44% measured share | network |
| filterlog pass enc0 | IPsec (enc0) pass, rule 146 | 20.27% measured share | network |
| ipsec-peer-lookup | charon looking for pre-shared key peer configs matching ... | 0.53% measured share | network |
| ipsec-ike-established | charon IKE_SA ... established between ... | 0.30% measured share | network |
| ipsec-child-established | charon CHILD_SA ... established with SPIs ... | 0.30% measured share | network |
| ipsec-child-closed | charon closing CHILD_SA ... with SPIs ... | 0.29% measured share | network |
| ipsec-ike-deleting | charon deleting IKE_SA ... between ... | 0.29% measured share | network |
| ipsec-peer-not-found | charon no peer config found | 0.23% measured share | network |
Realism Features
- About 12,900 records per day. LAN and enc0 traffic follow a daily curve of about 133 records an hour at night to 750 at the 10:00-12:00 peak; WAN default-deny probes arrive at 143 an hour around the clock, with scanners sending one to four probes. Rates are synthetic workload choices.
- Each of eight site-to-site tunnels has its own lifecycle: negotiation, IKE_SA and CHILD_SA establishment, a lognormal lifetime (median 2.5 h), closure and deletion, and a lognormal pause (median 1 h). Some attempts offer a wrong Phase 1 identity and are retried until corrected or given up, so repeated failures and failures followed by a successful negotiation are ordinary. No tunnel is assumed up at the start of a run.
- Every enc0 pass requires an active CHILD_SA of its site, and closing and deleting records carry the native IDs, SPIs and selectors of the established SA. Administrative ports carry about a quarter of enc0 traffic, often followed by further management sessions from the same host to the same server. A pass record means a packet matched a pass rule, not that a connection or authentication succeeded.
- Records of the same moment (a lookup and its failure, IKE_SA and CHILD_SA, closure and deletion) are median 4-5 s apart and at most about 70 s at night, where real charon writes them within milliseconds.
- Selected profile: IPv4 TCP SYN and UDP DNS records, IKEv1 PSK site-to-site tunnels and default enc0 filtering; IPv6, ICMP, DHCP, NAT translation, OpenVPN, administrator logins and the full IKE exchange are not modeled. Real tunnels usually rekey without going down; the down periods stand for idle, DPD and reauthentication teardowns. CHILD_SA byte counters are synthetic.
- No complete CE 2.9.0 capture was found: filterlog grammar comes from Netgate documentation, charon bodies from Netgate troubleshooting examples and older real pfSense records, and close/delete bodies from upstream strongSwan 5.9.14. ECS source and destination on charon lines are derived from the message text, and live SIEM/parser compatibility is not verified.
Sample Output
{
"@timestamp": "2026-09-01T10:19:59.653536+00:00",
"data_stream": {
"dataset": "pfsense.log",
"namespace": "default",
"type": "logs"
},
"destination": {
"ip": "203.0.113.1"
},
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "ipsec-ike-established",
"category": [
"network"
],
"dataset": "pfsense.log",
"kind": "event",
"original": "\u003c30\u003e1 2026-09-01T10:19:59.653536+00:00 fw01.corp.example charon 18610 - - 10[IKE] \u003ccon2|803\u003e IKE_SA con2[803] established between 203.0.113.1[203.0.113.1]...198.51.100.2[198.51.100.2]",
"type": [
"info"
]
},
"host": {
"name": "fw01.corp.example"
},
"log": {
"syslog": {
"priority": 30
}
},
"message": "10[IKE] \u003ccon2|803\u003e IKE_SA con2[803] established between 203.0.113.1[203.0.113.1]...198.51.100.2[198.51.100.2]",
"observer": {
"name": "fw01.corp.example",
"product": "pfSense",
"type": "firewall",
"vendor": "Netgate",
"version": "2.9.0"
},
"process": {
"name": "charon",
"pid": 18610
},
"related": {
"ip": [
"198.51.100.2",
"203.0.113.1"
]
},
"source": {
"ip": "198.51.100.2"
},
"syslog": {
"facility": {
"code": 3
},
"priority": 30,
"severity": {
"code": 6
}
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Include recurring identity-mismatch tunnel episodes; false produces background only |
| anomaly_interval_hours | 24 | Episode interval in hours, minimum 4 |
| hostname | fw01.corp.example | Firewall host name in the syslog header, host.name and observer.name |
| wan_ip | 203.0.113.1 | WAN address: local IKE endpoint and target of blocked probes |
| ipsec_pass_rule_tracker | 1534283903 | Tracker of the logged IPsec-tab pass rule |
Related Generators
Cisco ASA Firewall
Cisco ASA adaptive security appliance syslog — TCP/UDP/ICMP connection lifecycle, ACL permit/deny decisions, NAT translations, VPN tunnel events, and failover status messages.
Check Point Security Gateway
Check Point Security Gateway SmartLog — 8 software blades including Firewall, IPS, Application Control, URL Filtering, Anti-Bot, Anti-Virus, Threat Emulation, and Identity Awareness.
Network Traffic (Continent-Level Geo)
Network traffic events enriched with continent-level geographic information. Models cross-continent and same-continent flows for both inbound and outbound directions, with realistic allow/deny outcomes based on geographic policy.