Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Log flooded with port 137 & 138 UDP

    Scheduled Pinned Locked Moved Firewalling
    12 Posts 3 Posters 9.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jim82
      last edited by

      Thanks for your reply, John.

      Can you explain how I stop the log from being spammed?

      It's quite a heavy amount of entries, see new attachment below.

      BR Jim

      4.png
      4.png_thumb

      Best regards
      Jim

      Still learning, correct me if I'm wrong please.

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        Can you explain how I stop the log from being spammed?

        This traffic is being caught by the Default Deny rule, which is set to log all blocks.  If you want to ignore this traffic, create a firewall rule to specifically block this traffic and set it to not log.  From then on, that traffic will be blocked but not logged.

        1 Reply Last reply Reply Quote 0
        • J
          jim82
          last edited by

          Thanks KOM,

          Would attached be the correct way of doing this?

          BR Jim

          6.png_thumb
          6.png

          Best regards
          Jim

          Still learning, correct me if I'm wrong please.

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            Looks OK to me.  Test it and see if your log entries disappear.

            1 Reply Last reply Reply Quote 0
            • J
              jim82
              last edited by

              Thanks for your assistance :) Looks like that finally god rid of em.

              BR Jim

              Best regards
              Jim

              Still learning, correct me if I'm wrong please.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                where do you see that is the default deny rule?  He is not listing the rules.. So how do you know its default deny without seeing the rest of his rules.  Like I said pfsense is not going to forward that traffic anyway.  You must have the vlan really locked down if default deny is listing that.  Why don't you turn on so that you can see what rule is blocking - I thought that was the new default in 2.2.2?

                I see those in my dmz because its locked down very tight..  But I just turn that shit off on the client, seeing it in the logs is a reminder that box is sending out noise and to turn it off at the source vs just hiding the noise from your logs doesn't mean the noise is not still there.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • J
                  jim82
                  last edited by

                  To me it seems like it's NetBIOS traffic being sent from my 2 domain controllers to the VLAN10 broadcast. I guess they're polling for clients to index in the network browser.

                  My rules for VLAN10 are attached, any further input is greatly appreciated.

                  BR Jim

                  rules.png
                  rules.png_thumb

                  Best regards
                  Jim

                  Still learning, correct me if I'm wrong please.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    How is your network browsing going to work when there are no clients on your server segment to list?  Like I said what is the point of just not logging the traffic.  Why don't you turn off the noise at the source dc1 and 2??  For the network browser to work there needs to be a master browser on each segment and 1 for the domain, etc.

                    Why don't you just turn off the ability for those machines to be master browser, etc.  Disable the computer browsing service, etc.

                    Did you sniff the traffic and look to what it was?  If you see what you think is lot of traffic and you don't really understand what it is - why would you not understand what it is before you just don't log it?  Could point to a misconfiguration on the machine that should be fixed and not really just ignored.

                    So when your check engine light comes on in your car, do you just put a piece of tap over the light?  Or do you look to see what is turning on the light?  Floods of traffic should be investigated and corrected not just ignored if you ask me.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    • J
                      jim82
                      last edited by

                      Hi John,

                      Thanks a lot for the insightful information. I have started to investigate the traffic now. Generally it is NetBIOS broadcasts which could be ignored or disabled, since NetBIOS can now be served over DNS in stead.

                      In regards to the "engine light" analogy, I completely agree! Sometimes one just requires a real world simple comparison of an otherwise more complex problem.

                      Have a nice day
                      BR Jim

                      Best regards
                      Jim

                      Still learning, correct me if I'm wrong please.

                      1 Reply Last reply Reply Quote 0
                      • KOMK
                        KOM
                        last edited by

                        where do you see that is the default deny rule?  He is not listing the rules.. So how do you know its default deny without seeing the rest of his rules.

                        Educated guess.  Only his main LAN gets an auto-rule.  All others are empty.  He is blocking NETBIOS traffic without knowing what, where or why, which leads me to believe it's the default deny rule.  It doesn't take the Scooby Gang to figure that mystery out.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.