Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    weird reports for LAN and Guest blocks

    Scheduled Pinned Locked Moved pfBlockerNG
    15 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • motivioM
      motivio @michmoor
      last edited by

      @michmoor said in weird reports for LAN and Guest blocks:

      @motivio Clients don't have to have the app loaded in order to do any DNS queries for snapchat, right? So there is some commonality between clients. There is some reason they are querying for an address that's on the OISD block list you have loaded.

      But the IP on the Guest net is currently a EV-Charger. I ready don't think this device will ever send DNS requests for Snapchat. There seams to be something else happening.

      M 1 Reply Last reply Reply Quote 0
      • M
        michmoor LAYER 8 Rebel Alliance @motivio
        last edited by

        @motivio I would first correlate the IP and MAC to make sure it’s the charger.

        Firewall: NetGate,Palo Alto-VM,Juniper SRX
        Routing: Juniper, Arista, Cisco
        Switching: Juniper, Arista, Cisco
        Wireless: Unifi, Aruba IAP
        JNCIP,CCNP Enterprise

        motivioM 1 Reply Last reply Reply Quote 0
        • motivioM
          motivio @michmoor
          last edited by

          @michmoor said in weird reports for LAN and Guest blocks:

          @motivio I would first correlate the IP and MAC to make sure it’s the charger.

          I did.

          M 1 Reply Last reply Reply Quote 0
          • M
            michmoor LAYER 8 Rebel Alliance @motivio
            last edited by

            @motivio Then your device made a DNS query to snapchat.
            If you really want to disprove me or even hunt down what your charger is doing, run a pcap off the pfsense interface specifically looking for dns queries.

            Firewall: NetGate,Palo Alto-VM,Juniper SRX
            Routing: Juniper, Arista, Cisco
            Switching: Juniper, Arista, Cisco
            Wireless: Unifi, Aruba IAP
            JNCIP,CCNP Enterprise

            NogBadTheBadN M 2 Replies Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad @michmoor
              last edited by NogBadTheBad

              @michmoor Don't even need to do a packet capture if you're running unbound / DNS Resolver, add the following to the custom options and lookups will show in the logs:-

              log-queries: yes
              log-replies: yes
              log-tag-queryreply: yes

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              motivioM 1 Reply Last reply Reply Quote 0
              • M
                michmoor LAYER 8 Rebel Alliance @michmoor
                last edited by michmoor

                @NogBadTheBad yep you're absolutely right.

                Firewall: NetGate,Palo Alto-VM,Juniper SRX
                Routing: Juniper, Arista, Cisco
                Switching: Juniper, Arista, Cisco
                Wireless: Unifi, Aruba IAP
                JNCIP,CCNP Enterprise

                1 Reply Last reply Reply Quote 0
                • motivioM
                  motivio @NogBadTheBad
                  last edited by

                  @nogbadthebad @michmoor

                  Here the results from the Log of the DNS Resolver and the report for the same time from pfBlockerNG.
                  The IP 192.168.100.99 did not send any DNS for snapchat. But in the report it's showing.

                  IMG_0315.jpeg IMG_0316.jpeg

                  NogBadTheBadN M 2 Replies Last reply Reply Quote 0
                  • NogBadTheBadN
                    NogBadTheBad @motivio
                    last edited by

                    @motivio The second line shows 192.168.1.202 doing a lookup to a snapchat FQDN.

                    What is 192.168.1.202?

                    Andy

                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                    motivioM 1 Reply Last reply Reply Quote 0
                    • motivioM
                      motivio @NogBadTheBad
                      last edited by

                      @nogbadthebad said in weird reports for LAN and Guest blocks:

                      @motivio The second line shows 192.168.1.202 doing a lookup to a snapchat FQDN.

                      What is 192.168.1.202?

                      That’s an iPhone of my kids. They are using Snapchat.

                      NogBadTheBadN 1 Reply Last reply Reply Quote 0
                      • NogBadTheBadN
                        NogBadTheBad @motivio
                        last edited by NogBadTheBad

                        @motivio I'd just leave it logging for a while and check later.

                        Might even be a issue with the pfBlocker report.

                        Andy

                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                        1 Reply Last reply Reply Quote 0
                        • M
                          michmoor LAYER 8 Rebel Alliance @motivio
                          last edited by

                          @motivio lets get that pcap started on pfsense.
                          Not sure how often it's querying for snapchat but let it run until the alert in pfblocker comes up.
                          Make sure count is set to 0
                          Stop the capture
                          Download the capture
                          Open the capture
                          search for the string in the capture. Edit > Find Packet > Set to string

                          0a9cbe25-36eb-4bb1-9944-8306efaa8b03-image.png

                          Firewall: NetGate,Palo Alto-VM,Juniper SRX
                          Routing: Juniper, Arista, Cisco
                          Switching: Juniper, Arista, Cisco
                          Wireless: Unifi, Aruba IAP
                          JNCIP,CCNP Enterprise

                          1 Reply Last reply Reply Quote 1
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.