Zeek (formerly Bro) Network Security Monitor package for pfSense router/firewall


Zeek Network Security Monitor package for pfSense router/firewall



This package has been tested on pfSense 2.5.1-RELEASE (amd64). Maybe it might not work with older versions of pfSense.


Download the generated package through pfSense-pkg-zeek

Copy the package from your local machine to your firewall

You’ll need to enable ssh access to your pfSense firewall as it’s not enabled by default. To do this, login to pfsense and browse to System > Advanced, then scroll down to the SSH section and check ‘Enable Secure Shell’.

By default, pfSense disables upstream pkg repositories (for good reason). So we need to re-enable them albeit, temporarily. There are two files you’ll need to edit.


Make it look like:

FreeBSD: { enabled: yes }

As this package depends on zeek, we need to update the pkg cache and get on with installing zeek.

pkg update && pkg install -y zeek

Finally, copy the package to your firewall temporary folder.

scp ~/Downloads/pfSense-pkg-zeek-3.0.6.txz root@firewall-ip-address:/tmp/

Install the package on the firewall via pkg add command

pkg add pfSense-pkg-zeek-0.1.1.txz

Now, you can access the interface by login to pfSense and browse to Services > Zeek NSM

Note : After installing the package, the service does not start automatically, all you need is to enable the zeek instance on an interface from pfsense GUI to get the service started.


