Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Understanding firewall logs - source and destination addresses

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 4 Posters 819 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      Cylindric
      last edited by

      Hi, folks.

      I'm trying to track down a malware infestation that is getting some of our IPs blacklisted, so have created a firewall rule to block & log traffic to particular IPs.

      That seems to be working fine, as I'm now seeing blocked traffic in the logs. The problem is, the IP shown as the source is on the WAN, one of the gateway IPs, not the internal machine. The destination IP is the external botnet target, so is "correct".

      How do I work out what the actual source of this is?

      Thanks.
      screenshot.png
      screenshot.png_thumb

      1 Reply Last reply Reply Quote 0
      • P
        phil.davis
        last edited by

        I guess you put a block on the way out of WAN? Which seems to be after NAT is applied.
        Put block rules on LAN and you should see the internal private LAN source IP, before NAT gets to it.

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • C
          Cylindric
          last edited by

          It's a floating rule. I also have similar rules on WAN, LAN and OPT1, but they don't seem to catch these. Not sure how.

          1 Reply Last reply Reply Quote 0
          • D
            doktornotor Banned
            last edited by

            So remove the floating rule.

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              what are the exact rules you have in place so we can see why other rules might not catch.  Keep in mind other than floating rules are evaluated top down, first rule that hits would stop evaluation of the rest of the rules.  So you see stuff like

              any any default rule, and then below that rule you want to put in place and no wonder it does fire, since its never evaluated.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.