Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to hide ipv6 entries in firewall logs?

    Scheduled Pinned Locked Moved General pfSense Questions
    33 Posts 7 Posters 7.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • MikeV7896M
      MikeV7896
      last edited by MikeV7896

      There is a line above the log data that says Advanced Log Filter that when expanded allows you to filter the logs in a variety of ways. You can enter a specific interface, look for certain ports or IP addresses, and enter strings (I think some fields might even accept regex).

      The S in IOT stands for Security

      1 Reply Last reply Reply Quote 0
      • emammadovE
        emammadov
        last edited by

        This post is deleted!
        1 Reply Last reply Reply Quote 0
        • emammadovE
          emammadov
          last edited by

          Thank you very much.

          1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad
            last edited by

            @virgiliomi said in How to hide ipv6 entries in firewall logs?:

            e is a line above the log data that says Advanced Log Filter that when expanded allows you to filter the logs in a variety of ways. You can enter a specific interface, look for certain ports or IP addresses, and enter strings (I think some fields might even accept regex).

            If you don't run IPv6 you could always create two drop rules at the bottom of your interface rules and don't log IPv6.

            0_1539346837017_Screenshot 2018-10-12 at 13.18.51.png

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 0
            • emammadovE
              emammadov
              last edited by

              We don't use IPv6 in our network. We have this same rule in our pfsense. But I see these kind of logs in firewall logs.

              0_1539351009552_1.jpg

              johnpozJ GertjanG 2 Replies Last reply Reply Quote 0
              • NogBadTheBadN
                NogBadTheBad
                last edited by NogBadTheBad

                Try changing the IPv6 src to any rather than LAN2 net.

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                MikeV7896M 1 Reply Last reply Reply Quote 0
                • MikeV7896M
                  MikeV7896 @NogBadTheBad
                  last edited by

                  @nogbadthebad said in How to hide ipv6 entries in firewall logs?:

                  Try changing the IPv6 src to any rather than LAN2 net.

                  This will likely fix it as it’s likely that you’re seeing the logs with multicast addresses, which aren’t LAN2 addresses.

                  The S in IOT stands for Security

                  1 Reply Last reply Reply Quote 0
                  • emammadovE
                    emammadov
                    last edited by

                    Which one should I choose?

                    0_1539351576397_1.jpg

                    1 Reply Last reply Reply Quote 0
                    • NogBadTheBadN
                      NogBadTheBad
                      last edited by

                      Any

                      Andy

                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                      1 Reply Last reply Reply Quote 0
                      • emammadovE
                        emammadov
                        last edited by

                        I did as you said. But it didn't help. There are ipv6 logs running in firewall logs.
                        Do I always have to choose "any" as source address by default?
                        0_1539442611590_Screenshot from 2018-10-13 18-54-52.png

                        1 Reply Last reply Reply Quote 0
                        • MikeV7896M
                          MikeV7896
                          last edited by

                          Yes, you’ll need to choose “any” as the source. Link-local (fe80:) and multicast IPv6 addresses don’t meet the “LAN2 net” address range. That’s why those addresses still show up in the firewall logs for the LAN2 interface.

                          The S in IOT stands for Security

                          1 Reply Last reply Reply Quote 0
                          • emammadovE
                            emammadov
                            last edited by

                            I have chosen "any" as the source. I am attaching photos. Please have a look and let me know where I am wrong. By the way, I have unchecked "Allow IPv6" and checked "Prefer IPv4 over IPv6" in System / Advanced / Networking.

                            0_1539586327369_1.jpg
                            0_1539586333424_2.jpg
                            0_1539586339149_3.jpg
                            0_1539586344646_4.jpg

                            1 Reply Last reply Reply Quote 0
                            • NogBadTheBadN
                              NogBadTheBad
                              last edited by

                              Try doing the same from your other LAN interfaces.

                              Andy

                              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                              1 Reply Last reply Reply Quote 0
                              • emammadovE
                                emammadov
                                last edited by

                                Other interfaces has the same settings as others.
                                I have WAN, LAN, LAN2, LAN3, OPENVPN, IPSEC.

                                1 Reply Last reply Reply Quote 0
                                • NogBadTheBadN
                                  NogBadTheBad
                                  last edited by NogBadTheBad

                                  Hmm should work, have you killed the firewall states ?

                                  There aren't any hits against that firewall rule.

                                  Andy

                                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                  1 Reply Last reply Reply Quote 0
                                  • johnpozJ
                                    johnpoz LAYER 8 Global Moderator
                                    last edited by johnpoz

                                    Doesn't matter what you put on your interfaces since its being blocked by the BLOCK ALL IPv6 rule you have enabled.

                                    0_1539597335020_blockALL.png

                                    0_1539597274368_blockallIPv6.png

                                    That is what is logging it - I do not believe you can enable that and not log off the top of my head.. if you don't want any logging blocked ipv6.. Just undo that setting.. Then don't allow it.. If your seeing stuff being blocked by the default log, then as stated create an IPv6 block rule for any IPv6 and don't log it.

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                                    1 Reply Last reply Reply Quote 0
                                    • NogBadTheBadN
                                      NogBadTheBad
                                      last edited by

                                      @johnpoz said in How to hide ipv6 entries in firewall logs?:

                                      That is what is logging it - I do not believe you can enable that and not log off the top of my head.. if you don't want any logging blocked ipv6.. Just undo that setting.. Then don't allow it.. If your seeing stuff being blocked by the default log, then as stated create an IPv6 block rule for any IPv6 and don't log it

                                      Drat didn't notice 1000000003, good spot John

                                      Andy

                                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                      1 Reply Last reply Reply Quote 0
                                      • johnpozJ
                                        johnpoz LAYER 8 Global Moderator @emammadov
                                        last edited by johnpoz

                                        @emammadov said in How to hide ipv6 entries in firewall logs?:

                                        We don't use IPv6 in our network.

                                        Do you control all the devices in your network? If so and your not wanting to use IPv6 I would actually try and turn it off at the devices. Windows is one chatty kathy that when it comes to noise - out of the box it just doubles all that noise via IPv6. And if your not using it - its pointless to leave all that noise out there..

                                        Simple reg entry or can be disabled in group policy.. Prob a good thing to see the noise so you can turn it off at the source ;)

                                        Linux is not anywhere as chatty... You prob won't hear a peep out of it if you don't have IPv6 at the router.

                                        547 is dhcpv6 - and 5355 is LLMNR, NOISE!!! if your not actually using it. You for sure can turn that off on ipv6.. And that screams windows clients ;)

                                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                                        If you get confused: Listen to the Music Play
                                        Please don't Chat/PM me for help, unless mod related
                                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                                        1 Reply Last reply Reply Quote 0
                                        • emammadovE
                                          emammadov
                                          last edited by emammadov

                                          I have checked "Allow IPv6", now I see this entries in firewall logs:

                                          Oct 15 14:08:40 WAN Block ULA networks from WAN block fc00::/7 (12000) 10.128.0.2 my public ip ICMP

                                          You said: if you don't want any logging blocked ipv6.. Just undo that setting.. Then don't allow it

                                          It means, I have to check "Allow IPv6" and then uncheck "Allow IPv6"? I have rules in interfaces that block ipv6.

                                          1 Reply Last reply Reply Quote 0
                                          • NogBadTheBadN
                                            NogBadTheBad
                                            last edited by

                                            @emammadov said in How to hide ipv6 entries in firewall logs?:

                                            I have checked "Allow IPv6", now I see this entries in firewall logs:
                                            Oct 15 14:08:40 WAN Block ULA networks from WAN block fc00::/7 (12000) 10.128.0.2 my public ip ICMP
                                            You said: if you don't want any logging blocked ipv6.. Just undo that setting.. Then don't allow it
                                            It means, I have to check "Allow IPv6" and then uncheck "Allow IPv6"? I have rules in interfaces that block ipv6.

                                            Status -> System Logs -> Settings

                                            0_1539598961397_Screenshot 2018-10-15 at 11.22.22.png

                                            Guessing you had these ticked.

                                            Andy

                                            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.