Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    weird reports for LAN and Guest blocks

    Scheduled Pinned Locked Moved pfBlockerNG
    15 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • motivioM
      motivio
      last edited by motivio

      Hi,
      I see some weird reports in my pfBlockerNG-devl v3.1.0_16 on pfBlockerNG on 23.01 beta.
      Bildschirm­foto 2023-01-26 um 18.29.27.png

      An IP from the normal LAN is blocked, which is correct.
      But at the exact same time the report states, that an IP from the Guest also got blocked with the same destination. But on Guest there is no device accessing this destination.

      How is this possible???

      M 1 Reply Last reply Reply Quote 0
      • M
        michmoor LAYER 8 Rebel Alliance @motivio
        last edited by

        @motivio said in weird reports for LAN and Guest blocks:

        But on Guest there is no device accessing this destination

        How do you know this for sure?

        Firewall: NetGate,Palo Alto-VM,Juniper SRX
        Routing: Juniper, Arista, Cisco
        Switching: Juniper, Arista, Cisco
        Wireless: Unifi, Aruba IAP
        JNCIP,CCNP Enterprise

        motivioM 1 Reply Last reply Reply Quote 0
        • motivioM
          motivio @michmoor
          last edited by

          @michmoor said in weird reports for LAN and Guest blocks:

          @motivio said in weird reports for LAN and Guest blocks:

          But on Guest there is no device accessing this destination

          How do you know this for sure?

          Because I know the other IP and device on the Guest network. And it can't rund snapchat. ;-)

          M 1 Reply Last reply Reply Quote 0
          • M
            michmoor LAYER 8 Rebel Alliance @motivio
            last edited by

            @motivio Clients don't have to have the app loaded in order to do any DNS queries for snapchat, right? So there is some commonality between clients. There is some reason they are querying for an address that's on the OISD block list you have loaded.

            Firewall: NetGate,Palo Alto-VM,Juniper SRX
            Routing: Juniper, Arista, Cisco
            Switching: Juniper, Arista, Cisco
            Wireless: Unifi, Aruba IAP
            JNCIP,CCNP Enterprise

            motivioM 1 Reply Last reply Reply Quote 0
            • motivioM
              motivio @michmoor
              last edited by

              @michmoor said in weird reports for LAN and Guest blocks:

              @motivio Clients don't have to have the app loaded in order to do any DNS queries for snapchat, right? So there is some commonality between clients. There is some reason they are querying for an address that's on the OISD block list you have loaded.

              But the IP on the Guest net is currently a EV-Charger. I ready don't think this device will ever send DNS requests for Snapchat. There seams to be something else happening.

              M 1 Reply Last reply Reply Quote 0
              • M
                michmoor LAYER 8 Rebel Alliance @motivio
                last edited by

                @motivio I would first correlate the IP and MAC to make sure it’s the charger.

                Firewall: NetGate,Palo Alto-VM,Juniper SRX
                Routing: Juniper, Arista, Cisco
                Switching: Juniper, Arista, Cisco
                Wireless: Unifi, Aruba IAP
                JNCIP,CCNP Enterprise

                motivioM 1 Reply Last reply Reply Quote 0
                • motivioM
                  motivio @michmoor
                  last edited by

                  @michmoor said in weird reports for LAN and Guest blocks:

                  @motivio I would first correlate the IP and MAC to make sure it’s the charger.

                  I did.

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    michmoor LAYER 8 Rebel Alliance @motivio
                    last edited by

                    @motivio Then your device made a DNS query to snapchat.
                    If you really want to disprove me or even hunt down what your charger is doing, run a pcap off the pfsense interface specifically looking for dns queries.

                    Firewall: NetGate,Palo Alto-VM,Juniper SRX
                    Routing: Juniper, Arista, Cisco
                    Switching: Juniper, Arista, Cisco
                    Wireless: Unifi, Aruba IAP
                    JNCIP,CCNP Enterprise

                    NogBadTheBadN M 2 Replies Last reply Reply Quote 0
                    • NogBadTheBadN
                      NogBadTheBad @michmoor
                      last edited by NogBadTheBad

                      @michmoor Don't even need to do a packet capture if you're running unbound / DNS Resolver, add the following to the custom options and lookups will show in the logs:-

                      log-queries: yes
                      log-replies: yes
                      log-tag-queryreply: yes

                      Andy

                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                      motivioM 1 Reply Last reply Reply Quote 0
                      • M
                        michmoor LAYER 8 Rebel Alliance @michmoor
                        last edited by michmoor

                        @NogBadTheBad yep you're absolutely right.

                        Firewall: NetGate,Palo Alto-VM,Juniper SRX
                        Routing: Juniper, Arista, Cisco
                        Switching: Juniper, Arista, Cisco
                        Wireless: Unifi, Aruba IAP
                        JNCIP,CCNP Enterprise

                        1 Reply Last reply Reply Quote 0
                        • motivioM
                          motivio @NogBadTheBad
                          last edited by

                          @nogbadthebad @michmoor

                          Here the results from the Log of the DNS Resolver and the report for the same time from pfBlockerNG.
                          The IP 192.168.100.99 did not send any DNS for snapchat. But in the report it's showing.

                          IMG_0315.jpeg IMG_0316.jpeg

                          NogBadTheBadN M 2 Replies Last reply Reply Quote 0
                          • NogBadTheBadN
                            NogBadTheBad @motivio
                            last edited by

                            @motivio The second line shows 192.168.1.202 doing a lookup to a snapchat FQDN.

                            What is 192.168.1.202?

                            Andy

                            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                            motivioM 1 Reply Last reply Reply Quote 0
                            • motivioM
                              motivio @NogBadTheBad
                              last edited by

                              @nogbadthebad said in weird reports for LAN and Guest blocks:

                              @motivio The second line shows 192.168.1.202 doing a lookup to a snapchat FQDN.

                              What is 192.168.1.202?

                              That’s an iPhone of my kids. They are using Snapchat.

                              NogBadTheBadN 1 Reply Last reply Reply Quote 0
                              • NogBadTheBadN
                                NogBadTheBad @motivio
                                last edited by NogBadTheBad

                                @motivio I'd just leave it logging for a while and check later.

                                Might even be a issue with the pfBlocker report.

                                Andy

                                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                1 Reply Last reply Reply Quote 0
                                • M
                                  michmoor LAYER 8 Rebel Alliance @motivio
                                  last edited by

                                  @motivio lets get that pcap started on pfsense.
                                  Not sure how often it's querying for snapchat but let it run until the alert in pfblocker comes up.
                                  Make sure count is set to 0
                                  Stop the capture
                                  Download the capture
                                  Open the capture
                                  search for the string in the capture. Edit > Find Packet > Set to string

                                  0a9cbe25-36eb-4bb1-9944-8306efaa8b03-image.png

                                  Firewall: NetGate,Palo Alto-VM,Juniper SRX
                                  Routing: Juniper, Arista, Cisco
                                  Switching: Juniper, Arista, Cisco
                                  Wireless: Unifi, Aruba IAP
                                  JNCIP,CCNP Enterprise

                                  1 Reply Last reply Reply Quote 1
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.