Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    New COD MWII Blocked By pfSense

    Scheduled Pinned Locked Moved Gaming
    newcall of dutymwii blockedby pfsense
    64 Posts 5 Posters 15.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      EmJeezy @johnpoz
      last edited by

      @johnpoz i think the pcap i need to do is WAN and not local. Problem is with the WAN pcap i cannot filter (at least not from pfsense) on the local IP.

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @EmJeezy
        last edited by

        @emjeezy no lan is fine.. That sniff has zero traffic going to any internet address in it.. To get to the internet you have to send it to pfsense right? But pfsense isn't seeing any traffic going to the internet in that sniff.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        E 1 Reply Last reply Reply Quote 0
        • E
          EmJeezy @johnpoz
          last edited by

          @johnpoz

          You have some remote desktop connection in that sniff - I see the RDP 3389
          yes i am remoted onto my gaming pc right now

          Trying the pcap again on lan..

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @EmJeezy
            last edited by johnpoz

            @emjeezy nor did see even any dns queries in that sniff. Only thing see in there is part of remote desktop connection.

            You most likely filled up your sniff before you even started anything because you didn't change the limit from 100 to 0

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            E 1 Reply Last reply Reply Quote 0
            • E
              EmJeezy @johnpoz
              last edited by

              @johnpoz said in New COD MWII Blocked By pfSense:

              You most likely filled up your sniff before you even started anything because you didn't change the limit from 100 to 0

              right, i forgot to change the 'count' to 0. changed it now and running another pcap while trying to connect to COD..

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @EmJeezy
                last edited by

                @emjeezy make sure you flushed the clients local dns cache as well - so we can see if any dns queries it asks for are not being answered.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                E 1 Reply Last reply Reply Quote 0
                • E
                  EmJeezy @johnpoz
                  last edited by

                  @johnpoz

                  copy. will do.

                  1 Reply Last reply Reply Quote 0
                  • E
                    EmJeezy
                    last edited by

                    @johnpoz So fighting the pcap size, too large to upload here. Set count to a thousand packets and ran. Hopefully it captured some useful traffic. updated pcap attached.

                    packetcapture(2).pcap

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @EmJeezy
                      last edited by

                      @emjeezy well can see no dns responses for stuff being asked for

                      nodnsansswer.jpg

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      E 1 Reply Last reply Reply Quote 0
                      • E
                        EmJeezy @johnpoz
                        last edited by

                        @johnpoz humm..yah thats my machine asking my firewall for dns..thats normal. Wonder why my firwewall would fail to answer. I have 8.8.8.8 set as primary and 9.9.9.9 as 2ndary dns server.

                        R 1 Reply Last reply Reply Quote 0
                        • R
                          rcoleman-netgate Netgate @EmJeezy
                          last edited by

                          @emjeezy What is DNS Resolver set up for?
                          And System->General for the DNS calls? 8f31ca46-d38a-4a1b-a9b7-653145dee84e-image.png

                          Ryan
                          Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                          Requesting firmware for your Netgate device? https://go.netgate.com
                          Switching: Mikrotik, Netgear, Extreme
                          Wireless: Aruba, Ubiquiti

                          E johnpozJ 2 Replies Last reply Reply Quote 0
                          • E
                            EmJeezy @rcoleman-netgate
                            last edited by

                            @rcoleman-netgate

                            mine is set to:

                            8699c0cb-9d84-44b3-8e2a-9e69e7ba728e-image.png

                            I will say i do have my dns resolver enabled too ->

                            de5d2673-f868-4c53-a62d-32284f5fc45c-image.png

                            R 1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator @rcoleman-netgate
                              last edited by

                              @rcoleman-netgate

                              I didn't find any that didn't have a record.. From the ones that he showed no response for. I queried for them and they all responded.

                              But like that one with loginservice.prod in the name - if that doesn't get an answer, it highly unlikely to be able to login ;)

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              1 Reply Last reply Reply Quote 0
                              • R
                                rcoleman-netgate Netgate @EmJeezy
                                last edited by

                                @emjeezy Is DNS resolver running? Check Status->Services

                                Ryan
                                Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                Requesting firmware for your Netgate device? https://go.netgate.com
                                Switching: Mikrotik, Netgear, Extreme
                                Wireless: Aruba, Ubiquiti

                                E johnpozJ 2 Replies Last reply Reply Quote 0
                                • E
                                  EmJeezy @rcoleman-netgate
                                  last edited by

                                  @rcoleman-netgate

                                  it is running ->

                                  98c59c84-cb2d-467f-afe1-b6491d92e65c-image.png

                                  1 Reply Last reply Reply Quote 0
                                  • johnpozJ
                                    johnpoz LAYER 8 Global Moderator @rcoleman-netgate
                                    last edited by

                                    @rcoleman-netgate he got a response for the ngx nvidia one - even though did seem delayed..

                                    But don't see any other responses - maybe they were delayed as well, and the sniff stopped before they came in? But yeah checking to make sure they do respond would be step 1 in trying to figure out what is going on.

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                                    R E 2 Replies Last reply Reply Quote 0
                                    • R
                                      rcoleman-netgate Netgate @johnpoz
                                      last edited by

                                      How about going to Diagnostics->DNS Lookup and running a few of those?
                                      I couldn't get the ergeron one to resolve but I did get steampowered to

                                      ebf537e9-8a08-4a4f-bb90-7baedc4289d4-image.png

                                      Ryan
                                      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                      Requesting firmware for your Netgate device? https://go.netgate.com
                                      Switching: Mikrotik, Netgear, Extreme
                                      Wireless: Aruba, Ubiquiti

                                      E 1 Reply Last reply Reply Quote 0
                                      • E
                                        EmJeezy @johnpoz
                                        last edited by

                                        @johnpoz just tried to resolve this from my pc with a simple nslookup + a ping 'iw9.steam-loginservice.prod.demonware.net'..nothing.. are you able to resolve that on your end..?

                                        johnpozJ 1 Reply Last reply Reply Quote 0
                                        • E
                                          EmJeezy @rcoleman-netgate
                                          last edited by

                                          @rcoleman-netgate

                                          cdcb62c1-8eec-4eef-b1fe-f06bb2325134-image.png

                                          f58d3c06-88bf-4853-908a-de39b5e7dd72-image.png

                                          1 Reply Last reply Reply Quote 0
                                          • E
                                            EmJeezy
                                            last edited by

                                            Also set a static google dns on my pc, flushed dns cache and tried sigining into COD, same issue...

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.