• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Amazon Echo suddenly blocked

Scheduled Pinned Locked Moved General pfSense Questions
6 Posts 4 Posters 3.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    jpoet
    last edited by Sep 19, 2016, 6:14 PM

    My Amazon Echo Tap has worked fine for several months.  Suddenly this weekend it started saying that it could not connect to the internet.  All of my other wired and WiFi devices continued to work perfectly.  I tried:

    • Restarting the Echo

    • Restarting my WiFi access point (An Apple Airport Express in bridge mode)

    • Resetting the Echo to factory defaults

    • Resetting the WiFi access point to factory defaults

    None of that helped.  I finally tried restarting my pfSense router (10.3-RELEASE-p5), and that fixed it.

    Now my question is: why was pfSense blocking my Echo?  Looking through the logs I did not see anything helpful, but I may not have recognized the issue.

    I adding a firewall rule for traffic from the Echo's IP address, which does not block traffic, but logs it, which results in messages like:

    X Sep 19 12:01:43 LAN 10.0.5.18:33202 72.21.215.34:443 TCP:A

    Since rebooting pfSense fixed the problem, though, I don't expect it to be a firewall rule.  It is more likely to be a state table issue, right?

    Dashboard shows:

    
    State table size    0% (443/5000000)
    MBUF Usage          4% (36700/1000000)
    
    

    Is there something specific I should be looking for in the state table to identify a problem like this?  Is there any configuration steps I should take to help identify the issue?

    TIA!

    1 Reply Last reply Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator
      last edited by Sep 19, 2016, 6:16 PM

      Well that is an out of state packet.. If your device wants to create a connection it has to send a Syn not an Ack..

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • K
        KOM
        last edited by Sep 19, 2016, 6:45 PM

        Any time things are working great and then suddenly stop, I look for an IDS like Snort or pfBlocker. Something may have tripped a trigger and it added a rule to block the "offender".

        1 Reply Last reply Reply Quote 0
        • J
          jpoet
          last edited by Sep 20, 2016, 5:43 PM

          Since rebooting it, fixed it for now, I will wait until it happens again, and try to get useful information out of the logs.

          Thank you for the comments.

          1 Reply Last reply Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator
            last edited by Sep 20, 2016, 6:06 PM

            Rebooting what psense or the echo?

            Your state tables were not even close to being an issue.  So your not using any ids/ips package?

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • A
              avocado
              last edited by Dec 8, 2016, 5:49 PM

              I've been having the same issues.  Did you ever resolve it?

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received