Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    New log type entry?

    Scheduled Pinned Locked Moved General pfSense Questions
    45 Posts 5 Posters 1.0k Views 6 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG Offline
      Gertjan @stephenw10
      last edited by Gertjan

      @stephenw10 said in New log type entry?:

      when you see that it's almost always because it's pulled in something newer.

      Noop. I should be on 'Release', not RC or beta.

      I'm, imho, on a rock solid 25.07.1. I saw the same thing happening on (several ?) versions before.
      I've installed '25.07.1' clean and it was on of the first things I've tested.
      I've written about it in the past, in the captive portal forum (I'll look it up : edit : here it is).

      I use(d) this : Troubleshooting Captive Portal.

      Even when I de activate the captive portal, I'll keep seeing this :

      [25.07.1-RELEASE][root@pfSense.bhf.tld]/root: pfSsh.php playback pfanchordrill
      
      cpzoneid_2_allowedhosts rules/nat contents:
      pfctl: DIOCGETETHRULES: No such file or directory
      
      hostname_0 rules/nat contents:
      pfctl: DIOCGETRULES: Invalid argument
      pfctl: DIOCGETRULES: Invalid argument
      

      If I recall well, restarting pfSense without the portal will solve the issue.
      Re activating the portal will bring the issue back.

      dit : Bob.dig, sorry for polluting your post.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      stephenw10S 1 Reply Last reply Reply Quote 0
      • Bob.DigB Offline
        Bob.Dig LAYER 8 @tinfoilmatt
        last edited by Bob.Dig

        @tinfoilmatt said in New log type entry?:

        But it does give some insight into this system's configuration. Definitely makes it all less of a wonder.

        I changed mine, to look like yours. Let's see, if it has any positive impact.

        Btw, your questions have been already answered here, it is a WAN-type interface and with that, it can have no rules and be perfectly fine.

        tinfoilmattT 2 Replies Last reply Reply Quote 0
        • tinfoilmattT Offline
          tinfoilmatt @Bob.Dig
          last edited by

          @Bob.Dig

          [in New log type entry?:]

          Notice in OP how the oldest packet is apparently a TCP packet without any flag set, no source/destination ports logged? But then the next packet is an ACK in the same direction, ostensibly from a webserver, and this time with logged ports?

          Any thoughts provoked there? I don't see that as having been addressed anywhere.

          All due politeness—but a jacked-up system has the potential to 'trigger' jacked-up logging...

          1 Reply Last reply Reply Quote 0
          • tinfoilmattT Offline
            tinfoilmatt @Bob.Dig
            last edited by

            @Bob.Dig said in New log type entry?:

            I changed mine to look like yours.

            And this wouldn't seem feasible, so I'm not sure what you would've changed.

            1 Reply Last reply Reply Quote 0
            • stephenw10S Online
              stephenw10 Netgate Administrator @tinfoilmatt
              last edited by

              @tinfoilmatt said in New log type entry?:

              ...feels like a mess.

              There are a lot of interfaces but that all looks like expected output.

              tinfoilmattT 1 Reply Last reply Reply Quote 1
              • stephenw10S Online
                stephenw10 Netgate Administrator @Gertjan
                last edited by

                @Gertjan said in New log type entry?:

                hostname_0

                What is hostname_0 in that context? I'll try to replicate with some clients on it....

                GertjanG 1 Reply Last reply Reply Quote 0
                • tinfoilmattT Offline
                  tinfoilmatt @stephenw10
                  last edited by

                  @stephenw10 If by "interfaces" you mean 'four virtualized interfaces, some outrageous number of virtual sub-virtualized interfaces, and a buncha WireGuard sprinkled in'—sure.

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S Online
                    stephenw10 Netgate Administrator
                    last edited by

                    Ha, well levels of outrage may vary! 😉

                    1 Reply Last reply Reply Quote 0
                    • tinfoilmattT Offline
                      tinfoilmatt @Bob.Dig
                      last edited by

                      Hey, I wouldn't have even chimed in if not for the incessant...

                      Looks like having a block rule on that interface is "fixing" it for my eyes. 😉

                      ...insinuation...

                      I hope you guys will find the secret rule. 😉

                      ...that...

                      those entries still come up. 😉

                      ...there's some kind of development issue here. Outrageous indeed.

                      1 Reply Last reply Reply Quote 0
                      • GertjanG Offline
                        Gertjan @stephenw10
                        last edited by

                        @stephenw10 said in New log type entry?:

                        What is hostname_0 in that context? I'll try to replicate with some clients on it....

                        See here : pfSsh.php playback pfanchordrill (when portal is active) - let's continue over there.

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.