• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

23.01.b.20230106.0600 IGMP proxy stops TV stream

Scheduled Pinned Locked Moved General pfSense Questions
139 Posts 18 Posters 59.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    thebear @michiel
    last edited by Apr 25, 2023, 8:44 PM

    @michiel said in 23.01.b.20230106.0600 IGMP proxy stops TV stream:

    @thebear @haraldinho
    I read about solving the GUI issue as well (0.0.0.0/0 is possible now).

    Way more cleaner to read.

    @haraldinho Perhaps clearing the stating table via the "x" in the firewall rules op IPTV_WAN and IPTV_VLAN solves your issue? Or rebooting the Netgate...

    Good point!

    @thebear thanks for the extra security; that's partly going back to what I had. What extra settings do you have in the firewall rules flagged with the 3 thicks in the box; the second WAN rule and rules 2 and 4 at your LAN rules?

    Only enabled logging to see if I can narrow down the rules further more. But don’t want to spend more time at it. The chance of being attacked over vlan4 is almost none by allowing only UDP multicast. With the LAN rule blocking to the other LAN segments, if they where able to take controle over the STB, makes the attacker only look on that vlan. My STB is the only device in that VLAN.

    M 1 Reply Last reply Apr 25, 2023, 8:50 PM Reply Quote 0
    • M
      michiel @thebear
      last edited by Apr 25, 2023, 8:50 PM

      @thebear I understand. And what is defined in LAN_v4_v6? My idea was to allow DNS (53) and then block LAN-net…

      T 1 Reply Last reply Apr 25, 2023, 9:05 PM Reply Quote 0
      • T
        thebear @michiel
        last edited by Apr 25, 2023, 9:05 PM

        @michiel said in 23.01.b.20230106.0600 IGMP proxy stops TV stream:

        @thebear I understand. And what is defined in LAN_v4_v6? My idea was to allow DNS (53) and then block LAN-net…

        In that alias are all my other lan subnets v4 and v6.

        The STB communicates with the KPN NTP and DNS servers and that’s handled via the last rule. My STB is not using any pfsense service like NTP or DNS. The DHCP sever for this VLAN is handing out the KPN dns servers :)

        M 1 Reply Last reply Apr 28, 2023, 4:08 PM Reply Quote 1
        • H
          haraldinho
          last edited by Apr 27, 2023, 8:55 PM

          @thebear @michiel I think I figured it out. For some reason asymetric routing seems to happen. So some packets sent by the box through route A return to the box through route B. No clue why. But after reading about this issue in this article on the Netgate website I enabled "Bypass firewall rules for traffic on the same interface". For now, it seems that the logs are now clean.

          T 1 Reply Last reply Apr 28, 2023, 8:55 AM Reply Quote 0
          • T
            thebear @haraldinho
            last edited by Apr 28, 2023, 8:55 AM

            @haraldinho do you have multiple routers in your network?

            H 1 Reply Last reply Apr 28, 2023, 8:59 AM Reply Quote 0
            • H
              haraldinho @thebear
              last edited by haraldinho Apr 28, 2023, 9:14 AM Apr 28, 2023, 8:59 AM

              @thebear Nope, only multiple VLANs. The comment with this option is "This option only applies if one or more static routes have been defined. If it is enabled, traffic that enters and leaves through the same interface will not be checked by the firewall. This may be desirable in some situations where multiple subnets are connected to the same interface."

              T 1 Reply Last reply Apr 28, 2023, 9:16 AM Reply Quote 0
              • T
                thebear @haraldinho
                last edited by thebear Apr 28, 2023, 9:40 AM Apr 28, 2023, 9:16 AM

                @haraldinho do you be sure you did not disable the whole security layer?

                Is it a router with one or two ports?

                This option only applies if one or more static routes have been defined. Is that your case?

                H 2 Replies Last reply Apr 28, 2023, 11:17 AM Reply Quote 0
                • H
                  haraldinho @thebear
                  last edited by Apr 28, 2023, 11:17 AM

                  This post is deleted!
                  1 Reply Last reply Reply Quote 0
                  • H
                    haraldinho @thebear
                    last edited by haraldinho Apr 28, 2023, 3:28 PM Apr 28, 2023, 3:26 PM

                    @thebear It's a Netgate 6100 with 8 ports. I myself did not define any static routes. I was thinking that might come from KPN DHCP. In all honesty I do not oversee the exact consequences of disabling this option, however from the Netgate pfSense docs I understood that sometimes this option needs to be checked when asymmetric routing is happening... The way they describe it, it came across as quite benign.

                    1 Reply Last reply Reply Quote 0
                    • M
                      michiel @thebear
                      last edited by Apr 28, 2023, 4:08 PM

                      @thebear As soon as I block "Lan net" in the firewall rules of IPTV VLAN, pausing recorded programs stops working. I defined DNS servers in the IPTV VLAN. Any idea what goes wrong?
                      You block your other LAN subnets; does that include your default LAN range (in my case: 192.168.1.0/24)?

                      Schermafbeelding 2023-04-28 om 18.06.08.png

                      1 Reply Last reply Reply Quote 0
                      • T
                        thebear @thebear
                        last edited by thebear Apr 28, 2023, 5:57 PM Apr 28, 2023, 5:56 PM

                        @thebear said in 23.01.b.20230106.0600 IGMP proxy stops TV stream:

                        065479f1-6f96-45ef-aedd-a0114cece915-image.png

                        I have added some more security to the ruleset, there is no traffic allowed to the other LAN components when "the hacker" has access to the STB.

                        WAN
                        1a83cf9e-7a15-47f9-a4a4-87a1b2266265-image.png

                        LAN
                        703d9f8a-594d-497f-b246-ec6771566905-image.png

                        @michiel said in 23.01.b.20230106.0600 IGMP proxy stops TV stream:

                        @thebear As soon as I block "Lan net" in the firewall rules of IPTV VLAN, pausing recorded programs stops working. I defined DNS servers in the IPTV VLAN. Any idea what goes wrong?
                        You block your other LAN subnets; does that include your default LAN range (in my case: 192.168.1.0/24)?

                        Schermafbeelding 2023-04-28 om 18.06.08.png

                        Yes it include all RFC1918 address. Did you pay attention to the order, the top down order is relevant. Attached my earlier post as reference.

                        M 1 Reply Last reply Apr 28, 2023, 6:15 PM Reply Quote 0
                        • M
                          michiel @thebear
                          last edited by Apr 28, 2023, 6:15 PM

                          @thebear Ah, the order was incorrect! Could have known that :(. Changed the order and will do some further testing; let you know!

                          M 1 Reply Last reply May 4, 2023, 9:04 PM Reply Quote 0
                          • M
                            michiel @michiel
                            last edited by michiel May 4, 2023, 9:05 PM May 4, 2023, 9:04 PM

                            This post is deleted!
                            1 Reply Last reply Reply Quote 0
                            139 out of 139
                            • First post
                              139/139
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                              This community forum collects and processes your personal information.
                              consent.not_received