Log shows repeated denials from several addresses
-
On my log, I'm seeing a continual run of repeated denials from several IP addresses. Is this some kind of hacking or DOS attack? Any idea what's causing this?
-
@tangooversway that is your typical Ipv6 link-local noise. 1900 is SSDP/UPnP and 5353 is mdns.. Yeah clients love to put that noise on the network.
Prob best just not to log such noise, create rules that allow it, or just if you want to block it for some reason - pfsense wouldn't do anything with it anyway, unless maybe you were trying to use UPnP, but that would be pretty useless via link-local anyway. Pfsense not going to answer any mdns query, etc.
-
@johnpoz said in Log shows repeated denials from several addresses:
that is your typical Ipv6 link-local noise. 1900 is SSDP/UPnP and 5353 is mdns.. Yeah clients love to put that noise on the network.
For the SERIOUSLY outdated who may be misremembering, is it fair to say this is like using the broadcast address in my LAN to try to find a device or something like that?
-
@tangooversway exactly its broadcasting to find stuff.. it pretty useless to be honest.. The only time say mdns as any use for say something trying to find your printer to use Airprint - and that doesn't work across vlans without some setup.
If your printer is on this same network - pfsense logging it is just spam.
-
@johnpoz said in Log shows repeated denials from several addresses:
exactly its broadcasting to find stuff.. it pretty useless to be honest..
Okay, thanks for clarifying. As I keep saying, I know I am SERIOUSLY out of date on dealing with any firewall issues and there's a lot of new stuff I don't know. But, to sound like an old timer, when I learned how to set things up, I learned not to use a broadcast signal unless I absolutely had to - that doing so was basically obnoxious and rude because it created extra traffic and got in peoples' (and computers') way.
-
@tangooversway the new stuff puts a shit ton of useless broadcast/multicast traffic on the wire.. Windows is horrible at, phones are even worse - and they are wireless so yeah broadcast and multicast even bigger pain over wireless, etc.
I with I could get my phones to stop their constant mdns noise, have not been able to find a way to turn off the nonsense..
-
Years ago, some one (jimp, I guess) proposed this for the LAN firewall rules :
Forgot about what it was doing, until you brought up the subject.
edit : I am using the avahi packages, and users on other LANs can find my printers on my main LAN, and use them.
-
@gertjan yeah because it doesn't come from some ipv6 link-local address ;)