Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    One computer filling logs with UDP Broadcast Default deny block

    Scheduled Pinned Locked Moved Firewalling
    20 Posts 4 Posters 5.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ Offline
      johnpoz LAYER 8 Global Moderator
      last edited by

      click the download button in packet capture and post up the file.. That does not allow to see any data.. But those seem to be large packets!!  Like some sort of stream.. length is 1420..

      Your PC is a Asrock system and your pfsense is intel system.. Seems odd that its sending the directed broadcast .255 to 00:15:17:7d:e7:cb and all FF's mac..  You sure you don't have a mask wrong or something and .255 is host?  Are you using say a /22 or something?

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

      1 Reply Last reply Reply Quote 0
      • P Offline
        pfBasic Banned
        last edited by

        Oh, sorry here you go! And thank you for taking your time to help me out.

        packetcapture.pcap

        1 Reply Last reply Reply Quote 0
        • P Offline
          pfBasic Banned
          last edited by

          @johnpoz:

          click the download button in packet capture and post up the file.. That does not allow to see any data.. But those seem to be large packets!!  Like some sort of stream.. length is 1420..

          Your PC is a Asrock system and your pfsense is intel system.. Seems odd that its sending the directed broadcast .255 to 00:15:17:7d:e7:cb and all FF's mac..  You sure you don't have a mask wrong or something and .255 is host?  Are you using say a /22 or something?

          It's certainly possible I've messed something up. Although the network is working perfectly well.

          It's a /24 network.

          1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by

            So I see the same question here - but no answer

            https://ask.wireshark.org/questions/59565/udp-broadcast-port-889

            At a loss to what that traffic would be.. They are large packets - but nothing really in them.. I have tried decoding them as different things.. But not sure what that traffic is..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

            1 Reply Last reply Reply Quote 0
            • P Offline
              pfBasic Banned
              last edited by

              Interesting, well thank you for your help, I really do  appreciate it.

              I just clicked Easy pass in the logs then edited the rule to block it without logging so at least it won't be flooding the logs.

              1 Reply Last reply Reply Quote 0
              • johnpozJ Offline
                johnpoz LAYER 8 Global Moderator
                last edited by

                I would be very interested in what the traffic is.. Can you figure out what process on your pc is sending it?  That can be hard with UDP.. But I really would look to what is sending that traffic.. Maybe someone else can tell from that sniff.  But I have been unable to figure out what it is.. its not bt-dht or something..

                But someone with better wireshark fu than me might figure it out from your sniff.. Lets hope because I am now very curious ;)

                There are few tools you can use on windows to try and figure out what is the process sending them - which can give us a clue to what it is..  But I can tell you I have never seen such traffic before…

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                1 Reply Last reply Reply Quote 0
                • P Offline
                  pfBasic Banned
                  last edited by

                  I'd be glad to look into it more and report back, I just don't have a clue as to what I'm doing with Wireshark. I literally installed it this morning because I was curious about those logs.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Offline
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    wireshark is not going to be able to tell you what process is sending the traffic on windows.  But seems you have more machine than 1 sending.  Your sniff you attached shows its coming from 192.168.1.26, not .99

                    you could use something like https://technet.microsoft.com/en-us/sysinternals/tcpview.aspx

                    To try and catch what is sending the UDP.  While is more geared to your tcp traffic, it can do udp as well.

                    https://technet.microsoft.com/en-us/sysinternals/processmonitor.aspx

                    is another tool that could be used to track down what is creating udp traffic.

                    Since its sending from udp 889.. you could also see if its listening on that port.  Say simple netstat -anb could show you the process if what is sending is also listening, etc.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                    1 Reply Last reply Reply Quote 0
                    • P Offline
                      pfBasic Banned
                      last edited by

                      Ok thanks I'll check that out and report back. It was both the same machine, different DHCP lease

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Offline
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        yup same machine see the same mac in both.. that 28:f1:15 as the sender.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                        1 Reply Last reply Reply Quote 0
                        • P Offline
                          pfBasic Banned
                          last edited by

                          Thank you for links to those programs! I used process monitor and had it figured out right away! Great tools, very easy to use.

                          It was some bloatware software from the motherboard manufacturer.

                          ASRock XFast LAN by cFosSpeed Service

                          Uninstalled.

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ Offline
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            Have to look to what it was suppose to be doing sending data to a broadcast address..

                            Glad you got it sorted.. I recall cfosSpeed - its been around for many years as some form of optimization/shaping tool.. Been years and years since looked at it.. Now going to have to figure out for my own curiosity what it was doing sending very large packets with no real data in them out to a brodcast address..

                            There are lots of sysinternal tools that are very useful..  Too bad many of those features/functions are not just built right into the OS.. many of those tools should just come with the OS…

                            edit:  So it was this
                            http://www.asrock.com/feature/XFast/XFastLAN/index.asp

                            Why and the F would it send out large packets to broacast???  Wonder if there is any whitepaper on it.

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                            1 Reply Last reply Reply Quote 0
                            • D Offline
                              doktornotor Banned
                              last edited by

                              Asus is well known for producing completely idiotic "addons" to their MBs. I recall some crap called XFastUSB or something, just broke USB completely. Ugh.

                              1 Reply Last reply Reply Quote 0
                              • P Offline
                                pfBasic Banned
                                last edited by

                                Haha yeah, when I uninstalled it took me to their website and had a questionnaire with a long list of reasons why I uninstalled. They were all along the lines of because your program makes things worse not better.

                                1 Reply Last reply Reply Quote 0
                                • H Offline
                                  Harvy66
                                  last edited by

                                  I never install 3rd-party if I don't have to. If drivers have both an install and just the drivers, I got with just the drivers. Except my Razer, which I would like to find another mouse, but all mice require 3rd-party apps for their custom features.

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.