Skip to content

pfSense

You can integrate pfSense with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

pfSense product overview

pfSense is a free, open-source firewall and router software distribution based on FreeBSD and developed by Netgate, managed entirely through a web interface, providing firewalling, routing, VPN, and related network security services.

What we ingest

Sophos XDR collects pfSense syslog data by listening for firewall filter-log messages your pfSense deployment forwards to a Sophos XDR data collector. The following log categories are collected:

  • Firewall traffic 1: Firewall pass and block events for TCP, UDP, and ICMP traffic.

Event and data types

We ingest the following event and data types from pfSense:

  • Firewall traffic 1: Firewall filter log pass and block events for TCP, UDP, and ICMP traffic, including source and destination addresses, ports, and the action. Normalized to netflow telemetry.

Data provided by this integration

Data provided by pfSense gets normalized to the following schemas:

  • netflow 1

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation


  1. Netflow telemetry is only available to NG-SIEM subscribers.