pfSense
You can integrate pfSense with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
pfSense product overview
pfSense is a free, open-source firewall and router software distribution based on FreeBSD and developed by Netgate, managed entirely through a web interface, providing firewalling, routing, VPN, and related network security services.
What we ingest
Sophos XDR collects pfSense syslog data by listening for firewall filter-log messages your pfSense deployment forwards to a Sophos XDR data collector. The following log categories are collected:
- Firewall traffic 1: Firewall pass and block events for TCP, UDP, and ICMP traffic.
Event and data types
We ingest the following event and data types from pfSense:
- Firewall traffic 1: Firewall filter log pass and block events for TCP, UDP, and ICMP traffic, including source and destination addresses, ports, and the action. Normalized to netflow telemetry.
Data provided by this integration
Data provided by pfSense gets normalized to the following schemas:
netflow1
For more information about using schemas in Data Lake Search, see Schemas and logical types.