Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Netgate pfSense

The JSA DSM for Netgate pfSense collects syslog events from a pfSense device.

To integrate Netgate pfSense with JSA, complete the following steps:

  1. If automatic updates are not enabled, download and install the most recent version of the following RPMs from Juniper Customer Support on your JSA console:

    • DSMCommon RPM

    • Netgate pfSense DSM RPM

    • Linux DHCP DSM RPM (only if DHCP event logging is enabled)

    • Sourcefire Snort DSM RPM (only if the Snort package for Netgate pfSense is installed and event logging is enabled)

    Suricata events are not officially supported by the Sourcefire Snort DSM. However, they might be parsed by the Snort DSM.

  2. Configure your Netgate pfSense device to send events to JSA. For more information, see Configuring Netgate pfSense to Communicate with JSA.

    If you send Snort or Suricata events to JSA, and the log source is not automatically detected, add a Snort log source on the JSA Console For more information, see Syslog Log Source Parameters for Open Source SNORT.

  3. If JSA does not automatically detect the log source, add a Netgate pfSense log source on the JSA Console. For more information, see Syslog Log Source Parameters for Netgate pfSense.

    If you send Snort or Suricata events to JSA and JSA does not automatically detect the log source, add a Snort log source on the JSA Console For more information, see Syslog Log Source Parameters for Open Source SNORT.