Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    weird reports for LAN and Guest blocks

    Scheduled Pinned Locked Moved pfBlockerNG
    15 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      michmoor LAYER 8 Rebel Alliance @motivio
      last edited by

      @motivio I would first correlate the IP and MAC to make sure it’s the charger.

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      motivioM 1 Reply Last reply Reply Quote 0
      • motivioM
        motivio @michmoor
        last edited by

        @michmoor said in weird reports for LAN and Guest blocks:

        @motivio I would first correlate the IP and MAC to make sure it’s the charger.

        I did.

        M 1 Reply Last reply Reply Quote 0
        • M
          michmoor LAYER 8 Rebel Alliance @motivio
          last edited by

          @motivio Then your device made a DNS query to snapchat.
          If you really want to disprove me or even hunt down what your charger is doing, run a pcap off the pfsense interface specifically looking for dns queries.

          Firewall: NetGate,Palo Alto-VM,Juniper SRX
          Routing: Juniper, Arista, Cisco
          Switching: Juniper, Arista, Cisco
          Wireless: Unifi, Aruba IAP
          JNCIP,CCNP Enterprise

          NogBadTheBadN M 2 Replies Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad @michmoor
            last edited by NogBadTheBad

            @michmoor Don't even need to do a packet capture if you're running unbound / DNS Resolver, add the following to the custom options and lookups will show in the logs:-

            log-queries: yes
            log-replies: yes
            log-tag-queryreply: yes

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            motivioM 1 Reply Last reply Reply Quote 0
            • M
              michmoor LAYER 8 Rebel Alliance @michmoor
              last edited by michmoor

              @NogBadTheBad yep you're absolutely right.

              Firewall: NetGate,Palo Alto-VM,Juniper SRX
              Routing: Juniper, Arista, Cisco
              Switching: Juniper, Arista, Cisco
              Wireless: Unifi, Aruba IAP
              JNCIP,CCNP Enterprise

              1 Reply Last reply Reply Quote 0
              • motivioM
                motivio @NogBadTheBad
                last edited by

                @nogbadthebad @michmoor

                Here the results from the Log of the DNS Resolver and the report for the same time from pfBlockerNG.
                The IP 192.168.100.99 did not send any DNS for snapchat. But in the report it's showing.

                IMG_0315.jpeg IMG_0316.jpeg

                NogBadTheBadN M 2 Replies Last reply Reply Quote 0
                • NogBadTheBadN
                  NogBadTheBad @motivio
                  last edited by

                  @motivio The second line shows 192.168.1.202 doing a lookup to a snapchat FQDN.

                  What is 192.168.1.202?

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  motivioM 1 Reply Last reply Reply Quote 0
                  • motivioM
                    motivio @NogBadTheBad
                    last edited by

                    @nogbadthebad said in weird reports for LAN and Guest blocks:

                    @motivio The second line shows 192.168.1.202 doing a lookup to a snapchat FQDN.

                    What is 192.168.1.202?

                    That’s an iPhone of my kids. They are using Snapchat.

                    NogBadTheBadN 1 Reply Last reply Reply Quote 0
                    • NogBadTheBadN
                      NogBadTheBad @motivio
                      last edited by NogBadTheBad

                      @motivio I'd just leave it logging for a while and check later.

                      Might even be a issue with the pfBlocker report.

                      Andy

                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                      1 Reply Last reply Reply Quote 0
                      • M
                        michmoor LAYER 8 Rebel Alliance @motivio
                        last edited by

                        @motivio lets get that pcap started on pfsense.
                        Not sure how often it's querying for snapchat but let it run until the alert in pfblocker comes up.
                        Make sure count is set to 0
                        Stop the capture
                        Download the capture
                        Open the capture
                        search for the string in the capture. Edit > Find Packet > Set to string

                        0a9cbe25-36eb-4bb1-9944-8306efaa8b03-image.png

                        Firewall: NetGate,Palo Alto-VM,Juniper SRX
                        Routing: Juniper, Arista, Cisco
                        Switching: Juniper, Arista, Cisco
                        Wireless: Unifi, Aruba IAP
                        JNCIP,CCNP Enterprise

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.