Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Strange traffic in states table

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      bob76535
      last edited by

      What exactly does this mean?

      tcp  127.0.0.1:19004 <- "our external ip":80 <- 192.168.1.115:63933

      (I replaced our actual IP with the words)

      We have been having problems with this user playing WOW and a few other things on the clock. He got caught recently and now my states table is full of hundreds of these. What is he up to? Does this mean they set up a tunnel through port 80 (that was a suggestion from someone else who saw this)?

      Thanks

      Bob

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        That is how a normal NAT entry looks.

        That means that someone on 192.168.1.115 connected to your external port 80 and was redirected to 127.0.0.1:19004.

        That looks like you have NAT reflection enabled, and you have a port forward on port 80 to some other internal host.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • B Offline
          bob76535
          last edited by

          Ok thanks.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.