Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Log / routing full of upnp related messages

    Scheduled Pinned Locked Moved General pfSense Questions
    10 Posts 4 Posters 461 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      Gblenn
      last edited by Gblenn

      I was looking through my logs today and noticed that the System / Routing log was full of messages related to miniupnpd.

      36ab27a9-6ab0-4ec7-bb7f-584d3947d15f-image.png

      And all of it for PC's that are not in the ACL list of allowed IP's. What is this and why is it being logged? I don't even have logging turned on for upnp...

      c4039d31-a485-4175-a643-8fe5c51f42c9-image.png

      M 1 Reply Last reply Reply Quote 0
      • M
        mikek @Gblenn
        last edited by

        @Gblenn

        That check box seems to indicate it is for logging packets "HANDLED" by UPnP.
        Since the packet was not handled and the connection failed, it logs the failure. (which would seem to be a good thing)

        Personally I would not have UPNP enable on my network. Not a fan of allowing applications to decide what is allowed in. That is a different discussion though.

        A couple ways to deal these log entries that I can think of are:

        1. go to the denied workstations and disable UPnP services. Since your not allowing it anyway
        2. disable UPnP service on PFSense and add specific NAT entries and rules for what you wish to allow on your network.
        3. ignore these log entries for the specific devices since you know and understand why they are there.

        I am running Version: 24.03-RELEASE and have the UPnP service disabled. I do specific NAT rules for inbound traffic. I do not see these log entries at all.

        Hope this helps,
        Mike

        G 1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Yup that adds logging to the firewall rules created by UPnP so you see traffic actually passed by it. It doesn't affect logging from the daemon itself.

          1 Reply Last reply Reply Quote 0
          • G
            Gblenn @mikek
            last edited by

            @mikek @stephenw10 Yeah that makes sense and I guess there is no way to turn of logging for UPnP completely? And I understand it's just for information and not indicating any problem, it's just that it fills up that log...

            @mikek I do have UPnP enabled for two gaming PC's and just a few ports that I have narrowed it down to. And there is one game in particular that simply will not show Open NAT unless UPnP is enabled, which messes up some online gaming unfortunately.

            M 1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Mmm, not seeing a way to do that. You can increase logging by starting it with -v or -vv but I don't see anything else either as a switch or in the conf file.

              1 Reply Last reply Reply Quote 0
              • JonathanLeeJ
                JonathanLee
                last edited by

                Did you add matching rule for upnp on the access control lists?

                Check out this guide to make sure you didn't miss anything you never know...

                https://docs.netgate.com/pfsense/en/latest/services/upnp.html

                Make sure to upvote

                G 1 Reply Last reply Reply Quote 0
                • M
                  mikek @Gblenn
                  last edited by mikek

                  This post is deleted!
                  1 Reply Last reply Reply Quote 0
                  • G
                    Gblenn @JonathanLee
                    last edited by

                    @JonathanLee said in Log / routing full of upnp related messages:

                    add matching rule for upnp on the access control lists

                    By matching rule do you mean the ACL entries as in:
                    c19775b9-30da-491c-a9e6-50eba8b480d5-image.png

                    JonathanLeeJ 1 Reply Last reply Reply Quote 0
                    • JonathanLeeJ
                      JonathanLee @Gblenn
                      last edited by

                      @Gblenn Yes does your ip schema still the same?

                      Make sure to upvote

                      G 1 Reply Last reply Reply Quote 0
                      • G
                        Gblenn @JonathanLee
                        last edited by

                        @JonathanLee said in Log / routing full of upnp related messages:

                        Yes does your ip schema still the same

                        Hmm? Does my IP schema still ?look? the same??

                        The LAN, where UPnP is enabled has two of the Static IP's (gaming PCs) which in the ACL list (192.168.1.92) and they have the same port range allowed.

                        The IP's that show up in the log are all from the DHCP range .130 and above.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.