Open Status → Firewall Live View in LuCI.
Live View shows whatever OpenWrt is already logging. Stock configurations log almost nothing — that is normal, not a broken install. Use Enable logging once for WAN drops/rejects (same as Network → Firewall). The app does not add allow/deny rules on its own.
On-page Help (collapsed at the bottom) covers the basics without leaving the router.
- Title — Logging is off on this router (cause first, not “broken table”).
- Before you enable logging — one-time panel: what changes, what does not, how to undo.
- Enable WAN drop/reject logging — intentional step; or pick Not now, or configure zones under Network → Firewall yourself.
- Watch strip shows WAN logging: off and a short Enable logging button.
Nothing changes until you click Enable.
- Watch strip shows a single WAN logging on · rate control (click to disable).
- A green notice shows that WAN drop/reject logging is on — not normal LAN browsing.
- If the table is still empty, you are waiting for firewall events (quiet WAN). Blocked inbound traffic appears as it happens.
Optional synthetic check: Enabling firewall logs → ping test.
- Title row — Firewall Live View on the left; Watching status (dot + counts) on the right.
- Watch strip — Pause/Resume, logging control, and segmented Simple / Detail and Wrap / One line groups.
- Display options bar — Limit, Row tint, Palette, and Show hostnames on one line (no drawer).
- Filter row — quick search, Action, and Protocol (grouped menu + optional custom type-in); open More filters for the rest.
- Table — click a cell to filter; click a row body (not a filter link) to expand Message.
| Column | Meaning |
|---|---|
| Action | pass, drop, reject, etc. — color-coded |
| Time | Compact HH:MM:SS (today) |
| Interface | Ingress interface (badge) |
| Flow | source:port → destination:port — click parts to filter |
| Proto | TCP, UDP, ICMP, … |
| Rule | Resolved fw4/UCI name when possible |
Expand raw message: click any data row (not a filter link) to show or hide the full netfilter log line below that row.
- Click the row body (for example the Action cell) to expand.
- The full log line appears under that row — click again to collapse.
Quick search, Action, and Protocol are always visible. Protocol offers common values in a menu; type in the adjacent field for anything else (prefix ! to exclude). Open More filters for interface, source/destination, and ports.
- Active filters appear as chips under the search bar.
- Click ≠ on a chip to flip include ↔ exclude; × removes one; Clear all resets.
- More filters reveals interface, addresses, and ports.
Click Detail on the watch strip (the active segment is highlighted). Click Simple to return.
- Detail switches to the forensic table and uses the full browser width (Simple keeps LuCI's normal column) — widen the window to see more per row.
- Every normalized field is visible in one row (including Message).
- Wrap / One line (next to Simple / Detail) applies in Detailed view only.
Shows every normalized field in one wide table:
Time, Action, Rule, IN, OUT, Dir, Proto, Source, SPort, Destination, DPort, Flags, Len, Message
Use Detailed when you need the raw KEY=value message inline without expanding rows, or when debugging flags, length, and direction fields.
| Control | Behavior |
|---|---|
| Pause / Resume | Live updates run until you Pause. Resume continues the table. Polling never stops. |
| Enable logging | Filled button on the watch strip when WAN logging is off. Sets WAN zone drop/reject logging (same as Network → Firewall). No allow/deny rules are added. Concurrent toggles from multiple admins are last-writer-wins. Rate is the firewall log_limit (default 10/minute), not a fwlive cap. |
| WAN logging on · rate | When logging is on, one merged control shows status and rate. Click it to disable. |
| Simple / Detail | Segmented pair on the watch strip. The active segment is highlighted. Preferences saved in localStorage. |
| Wrap / One line | Segmented pair next to Simple / Detail. Visible in Detailed view only. |
| Display options | Inline bar below the watch strip: Limit, Row tint (checkbox + palette), and Show hostnames. |
| Limit | Rows to keep (25 … 2000, default 100). Stored in the browser. On a router reported as a weak device, the browser renders at most 250 rows and explains the cap in the status line; the larger limit remains available for buffering and stronger devices. |
| Fetch budget | Auto requests min(max(Limit × 4, 100), 2000) raw log lines for live polls. Manual selects a bounded maximum from 25, 50, 100, 250, 500, 1000, or 2000. Both modes retain server protection and adaptive polling cadence. |
| Maximum raw lines | Enabled in Manual mode. It is a raw-line fetch budget, not a number of firewall rows displayed. Paused Manual fetches use this maximum; paused Auto keeps the compatibility 2000-line request. |
| Show hostnames | Off by default. When checked, resolved names replace IPs in Flow and address columns. Hover shows the IP. Click still filters by IP. |
| Quick search | Matches across all normalized fields. |
For a responsive display on a weak router or an older client, keep Limit at 250 rows or below. A router-reported weak-device cap limits how many rows the browser renders; the selected limit can still allow the in-memory buffer to retain more rows for filtering and stronger devices.
Switching to another browser tab pauses polling. Returning to fwlive performs one catch-up poll, then resumes the normal cadence. Show hostnames is off by default because reverse-DNS lookups add work; leave it off when the router or browser is busy.
The router's log ring is finite and may evict older events before fwlive reads them. fwlive cannot recover evicted entries and does not change forwarding behavior. If events arrive faster than the UI can display them, use a lower Limit, keep hostname lookup disabled, and rely on the high-rate banner as a signal to reduce the workload.
- Click any cell (action, IP, protocol, interface, flow endpoint) to filter.
- Active filters appear as chips — click ≠ on a chip to flip include ↔ exclude; × removes one; Clear all resets.
- You can also prefix text filters with
!for negation (same as ≠ on a chip). - URL hash stores filters, limit, and
view=detailedfor shareable links.
| Goal | Approach |
|---|---|
| See only drops | Action → drop |
| Hide passes | Click pass in the table, then ≠ on the action: pass chip |
| One client | Click source in Flow or use More filters → Source |
| ICMP test | Protocol → ICMP after enabling ping logging |
When fw4 logs a prefix (for example, fwlive-ping followed by a space), the UI shows a label. Ctrl+click (Cmd+click on macOS) a rule name to open the firewall configuration; plain click filters on that hint.
If no events appear after install, that is expected until logging is on — see First visit. Enable logging sets WAN zone log=1 (same as Network → Firewall). The empty state explains what will and will not appear (WAN drops/rejects, not normal LAN browsing).
If logging is already on but the table is still empty, wait for inbound WAN traffic or see Quick start — optional ping test. Advanced setup: Enabling firewall logs.
If more than ~250 new events arrive per second, a banner may appear and rendering throttles briefly.
The status banner can distinguish the requested raw-line budget, a successful server-applied limit, and the number of classified firewall messages returned. Fewer returned messages do not by themselves prove shedding: filtering, sparse logs, deduplication, and finite router log retention can all reduce the result. While paused in Manual mode, the status line says buffer filling when successive full or growing snapshots are still adding rows; it clears on a short read, an unchanged snapshot, an error, or Resume.





