• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Rule to Block Logging of Traffic to x.x.x.255?

Scheduled Pinned Locked Moved Firewalling
3 Posts 2 Posters 1.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    beremonavabi
    last edited by Apr 12, 2017, 9:12 PM Apr 12, 2017, 3:46 AM

    According to my firewall log, about every minute I get two instances of a local computer sending traffic across the subnet from port 21327 to x.x.x.255 – one to port 21327 and the other to port 21328.  It looks like my rule to allow only certain ports is picking that up.  I can't find anything specifying what might be using those ports.  On the assumption the traffic really should remain blocked, what would the rule look like to specifically do so?  I could make the rule non-blocking and place it above my "allow only certain ports" rule to stop cluttering up the log.

    EDIT:  After more research, I finally found a reference to those ports.  UDP 21327 and 21328 are used by SpiderOakONE for LAN Sync.  So, it looks like I need to add them to my safe port alias.

    SG-4860, pfSense 2.4.5-RELEASE-p1 (amd64)

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Apr 14, 2017, 2:51 PM

      That would be broadcast traffic inside the same segment. It doesn't matter if the firewall passes or blocks that, it has no bearing on what happens to the traffic as the switch has already delivered it to everyone on that network.

      Pass or block without logging, your choice, it's only log spam at that point.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • B
        beremonavabi
        last edited by Apr 14, 2017, 3:08 PM

        Yep.  When I thought it was supposed to be blocked, I just wanted a rule so I could turn off the logging of that.  I want logging on my "allow only certain ports" rule, so I didn't want to turn that logging off.  But, since the traffic was legitimate and I let those ports through, I'm ok, now.

        SG-4860, pfSense 2.4.5-RELEASE-p1 (amd64)

        1 Reply Last reply Reply Quote 0
        1 out of 3
        • First post
          1/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received