Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    weird reports for LAN and Guest blocks

    Scheduled Pinned Locked Moved pfBlockerNG
    15 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      michmoor LAYER 8 Rebel Alliance @motivio
      last edited by

      @motivio Clients don't have to have the app loaded in order to do any DNS queries for snapchat, right? So there is some commonality between clients. There is some reason they are querying for an address that's on the OISD block list you have loaded.

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      motivioM 1 Reply Last reply Reply Quote 0
      • motivioM
        motivio @michmoor
        last edited by

        @michmoor said in weird reports for LAN and Guest blocks:

        @motivio Clients don't have to have the app loaded in order to do any DNS queries for snapchat, right? So there is some commonality between clients. There is some reason they are querying for an address that's on the OISD block list you have loaded.

        But the IP on the Guest net is currently a EV-Charger. I ready don't think this device will ever send DNS requests for Snapchat. There seams to be something else happening.

        M 1 Reply Last reply Reply Quote 0
        • M
          michmoor LAYER 8 Rebel Alliance @motivio
          last edited by

          @motivio I would first correlate the IP and MAC to make sure it’s the charger.

          Firewall: NetGate,Palo Alto-VM,Juniper SRX
          Routing: Juniper, Arista, Cisco
          Switching: Juniper, Arista, Cisco
          Wireless: Unifi, Aruba IAP
          JNCIP,CCNP Enterprise

          motivioM 1 Reply Last reply Reply Quote 0
          • motivioM
            motivio @michmoor
            last edited by

            @michmoor said in weird reports for LAN and Guest blocks:

            @motivio I would first correlate the IP and MAC to make sure it’s the charger.

            I did.

            M 1 Reply Last reply Reply Quote 0
            • M
              michmoor LAYER 8 Rebel Alliance @motivio
              last edited by

              @motivio Then your device made a DNS query to snapchat.
              If you really want to disprove me or even hunt down what your charger is doing, run a pcap off the pfsense interface specifically looking for dns queries.

              Firewall: NetGate,Palo Alto-VM,Juniper SRX
              Routing: Juniper, Arista, Cisco
              Switching: Juniper, Arista, Cisco
              Wireless: Unifi, Aruba IAP
              JNCIP,CCNP Enterprise

              NogBadTheBadN M 2 Replies Last reply Reply Quote 0
              • NogBadTheBadN
                NogBadTheBad @michmoor
                last edited by NogBadTheBad

                @michmoor Don't even need to do a packet capture if you're running unbound / DNS Resolver, add the following to the custom options and lookups will show in the logs:-

                log-queries: yes
                log-replies: yes
                log-tag-queryreply: yes

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                motivioM 1 Reply Last reply Reply Quote 0
                • M
                  michmoor LAYER 8 Rebel Alliance @michmoor
                  last edited by michmoor

                  @NogBadTheBad yep you're absolutely right.

                  Firewall: NetGate,Palo Alto-VM,Juniper SRX
                  Routing: Juniper, Arista, Cisco
                  Switching: Juniper, Arista, Cisco
                  Wireless: Unifi, Aruba IAP
                  JNCIP,CCNP Enterprise

                  1 Reply Last reply Reply Quote 0
                  • motivioM
                    motivio @NogBadTheBad
                    last edited by

                    @nogbadthebad @michmoor

                    Here the results from the Log of the DNS Resolver and the report for the same time from pfBlockerNG.
                    The IP 192.168.100.99 did not send any DNS for snapchat. But in the report it's showing.

                    IMG_0315.jpeg IMG_0316.jpeg

                    NogBadTheBadN M 2 Replies Last reply Reply Quote 0
                    • NogBadTheBadN
                      NogBadTheBad @motivio
                      last edited by

                      @motivio The second line shows 192.168.1.202 doing a lookup to a snapchat FQDN.

                      What is 192.168.1.202?

                      Andy

                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                      motivioM 1 Reply Last reply Reply Quote 0
                      • motivioM
                        motivio @NogBadTheBad
                        last edited by

                        @nogbadthebad said in weird reports for LAN and Guest blocks:

                        @motivio The second line shows 192.168.1.202 doing a lookup to a snapchat FQDN.

                        What is 192.168.1.202?

                        That’s an iPhone of my kids. They are using Snapchat.

                        NogBadTheBadN 1 Reply Last reply Reply Quote 0
                        • NogBadTheBadN
                          NogBadTheBad @motivio
                          last edited by NogBadTheBad

                          @motivio I'd just leave it logging for a while and check later.

                          Might even be a issue with the pfBlocker report.

                          Andy

                          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                          1 Reply Last reply Reply Quote 0
                          • M
                            michmoor LAYER 8 Rebel Alliance @motivio
                            last edited by

                            @motivio lets get that pcap started on pfsense.
                            Not sure how often it's querying for snapchat but let it run until the alert in pfblocker comes up.
                            Make sure count is set to 0
                            Stop the capture
                            Download the capture
                            Open the capture
                            search for the string in the capture. Edit > Find Packet > Set to string

                            0a9cbe25-36eb-4bb1-9944-8306efaa8b03-image.png

                            Firewall: NetGate,Palo Alto-VM,Juniper SRX
                            Routing: Juniper, Arista, Cisco
                            Switching: Juniper, Arista, Cisco
                            Wireless: Unifi, Aruba IAP
                            JNCIP,CCNP Enterprise

                            1 Reply Last reply Reply Quote 1
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.