• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Bridge mode causing SMB traffic to fill firewall log

Scheduled Pinned Locked Moved Firewalling
12 Posts 3 Posters 1.8k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    KOM
    last edited by Aug 18, 2015, 3:13 PM

    It may be out of state traffic if it doesn't seem to match any of your rules.

    https://doc.pfsense.org/index.php/Why_do_my_logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection

    1 Reply Last reply Reply Quote 0
    • F
      finchy
      last edited by Aug 18, 2015, 3:26 PM

      Thanks for the quick response.

      I looked through that article and while it could very well be something to do with what it is talking about, there doesn't seem to be any way of rectifying the issue.  Also, the data in my firewall log doesn't seem the same as what is shown in that article as some of the traffic I am seeing doesn't state that it's been blocked by a default deny any rule ipv4.

      Another thing I can't understand is why this traffic is ever hitting the firewall, the source and destination addresses on all the hits are physically on the LAN.  To clarify, this is a windows domain with two windows domain controllers used for DHCP & DNS, pfsense is nothing more than a firewall and OpenVPN server.

      It does seem to be misinformation from the firewall as no user has reported any problems accessing the samba drive.

      1 Reply Last reply Reply Quote 0
      • J
        johnpoz LAYER 8 Global Moderator
        last edited by Aug 18, 2015, 4:38 PM

        Can you post up screen shot of these firewall hits your seeing.  And details of how you bridged your lan to your openvpn - I can think of no reason why that would ever in a million years have to be done to allow access to file shares, etc.

        I access file shares over a normal tun setup where openvpn is on own network different than the lan network.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • F
          finchy
          last edited by Aug 19, 2015, 7:56 AM

          I followed this article to set up my OpenVPN:

          https://forum.pfsense.org/index.php?topic=46984.0

          I could not get VPN clients talking to LAN resources without setting it up this way.

          Attached is a screen grab of my firewall log.

          fw-log.png
          fw-log.png_thumb

          1 Reply Last reply Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator
            last edited by Aug 19, 2015, 10:48 AM Aug 19, 2015, 10:43 AM

            Did you change your firewalls on your local clients to allow access from a remote network?

            TAP is not a good option.. All broadcast traffic is now over your vpn.. Bridges in general are horrible performance..  Unless you had a specific need for say broadcast traffic to be used there is no reason for tap, and accessing file shares sure doesn't need to be on the same segment.

            So lets see your rules?  Post up rules you have on lan and bridge interfaces in your firewall.  All of that traffic is out of state for sure.  Also you can click the red x to see what rule it was that blocked.. Or better yet just enable the rule to be listed.  In your log settings change it so it displays the rules desc.

            That is dated back from 2012?  So version 2.0.2 at best.. You do understand the vpn wizard would walk you through setting it up in like 30 seconds.  Are you running version 2.0.2?  Or current 2.2.4?

            displayrule.png
            displayrule.png_thumb

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • F
              finchy
              last edited by Aug 20, 2015, 8:40 AM

              I haven't changed any client firewalls at all, the WAN on the pfsense box allows openVPN traffic but that's it.

              When I click the red X half of the entries are blocked by default deny rule IPV4 and the others are blank.  I have already selected the option add pass rule from the firewall but this had no effect and I subsequently deleted those rules.

              I'm starting to think maybe I need to set up a new box and try installing OpenVPN with the wizard on TAP and try and get that working again.  I used the wizard previously with TAP, I couldn't get anything on the VPN to speak with anything on the LAN with that set up either.

              I am currently running 2.2.4.

              Bridge-fw.png
              Bridge-fw.png_thumb
              LAN-fw.png
              LAN-fw.png_thumb

              1 Reply Last reply Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator
                last edited by Aug 20, 2015, 11:31 AM

                Why do you think you need tap???  You DONT!!! File sharing does not require to be on the same segment.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • F
                  finchy
                  last edited by Aug 20, 2015, 12:53 PM

                  My apologies, please replace TAP with TUN in my last message.

                  1 Reply Last reply Reply Quote 0
                  • J
                    johnpoz LAYER 8 Global Moderator
                    last edited by Aug 20, 2015, 1:11 PM

                    don't think you need to setup a new box..  Just redo the vpn connection on this one.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • F
                      finchy
                      last edited by Aug 20, 2015, 3:52 PM

                      I should probably open a new ticket for this but any chance you can point me in the right direction.  I have set up the TUN OpenVPN server and connected to it fine.  I can see some stuff on the LAN network from the VPN tunnel but I can't access the SMB share.  It keeps hitting the firewall despite those rules I have setup allowing traffic over the VPN, I have attached an image of the firewall log.

                      fw.png
                      fw.png_thumb

                      1 Reply Last reply Reply Quote 0
                      • J
                        johnpoz LAYER 8 Global Moderator
                        last edited by Aug 20, 2015, 5:26 PM

                        and what are the rules on your vpn tab?  By default I believe its an any any - what did you change it to or add above it?  Did you check to allow netbios over the vpn?

                        Enable NetBIOS over TCP/IP
                        If this option is not set, all NetBIOS-over-TCP/IP options (including WINS) will be disabled.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        12 out of 12
                        • First post
                          12/12
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                          This community forum collects and processes your personal information.
                          consent.not_received