Random inbound connections causing internet timeout
-
I'm experiencing a timeout issue I'm hoping to get some help with. Basically my internet connection has time outs when random connections are made to my WAN IP. This is causing a poor internet experience as there are times when the time outs completely kill the connection.
From inside the LAN I disconnected all devices except my laptop and setup a continuous ping to an external server (4.2.2.2). Then I monitor the firewall logs in Dynamic View.
Network setup for this test is as follows:
Cable Modem -> pfSense -> Laptop
pfSense device is a Lanner FW7535, 1.6 Dual Core CPU, 2GB RAM, SSD, Gigabit Nics. CPU usage is less than 5%, RAM usage less than 20%.When a ping time out occurs, I see an entry similar to this in my log:
X Oct 18 11:19:48 WAN 194.55.142.41:55372 [My_WAN_IP]:23396 TCP:S
This happens continuously from different IP addresses all around the globe (looked up some of them using GeoIP). The ports they are trying to connect to are not open and appear to be random.
Although the connections are blocked, why does this cause a time out in my continuous ping? I've tried creating a floating rule with Quick enabled to block these IP's (I have an alias that I add the IP's to). However the originating IP's always change and I still see IP's that I have added to the alias appear in the log with the same symptom.
Why would blocked inbound connections cause packet loss?
What can I do to further troubleshoot/reslove this? -
I've tried creating a floating rule with Quick enabled to block these IP's...
Blocking the IPs is useless since they're already at your WAN. A firewall block will stop them from going further in the case where you have a NAT'd server or something.
Why would blocked inbound connections cause packet loss?
They don't. This is something unique to you. Everybody's WANs get slammed with random noise all day every day.
What can I do to further troubleshoot/reslove this?
Anything in the System log when this happens?
-
@rcampbell said in Random inbound connections causing internet timeout:
Why would blocked inbound connections cause packet loss?
If it really is the inbound connections then there are probably enough to saturate your WAN connection. This would then be a DOS attack. Blocking them on your end does absolutely nothing, as they have already traveled through your ISP connection. In that case you have to talk to your ISP, so that they can block them upstream.
-
This would then be a DOS attack.
Possible. I didn't gather that from his description, where he seems to indicate that it's hit or miss at random and not sustained.
It would be helpful to know exactly how many of these connections he is talking about. A few dozen IPs per minute isn't going to do anything. Thousands per second likely will depending on his bandwidth and hardware.
-
@kom said in Random inbound connections causing internet timeout:
d.
It would be helpful to know exactly how many of these connections he is talkingI don't think its a dos attack, the frequency is a connection attempt every 5 to 10 seconds or so. I will look at the system logs.
-
The next time it happens, check your System and Gateway logs. What hardware are you using?
-
Hardware: Lanner FW7535, 1.6 Dual Core CPU, 2GB RAM, SSD, Gigabit Nics.
Attached are the System-General logs from today (last 500 lines). I didn't check if the Arp messages correspond with the ping time outs, but I will check after I have plugged the switch and other devices back in. Even still with just my laptop connected to the firewall, the time outs occur as originally described and I don't see any other corresponding log entry other than the blocked connection attempts.
You can see from the below log where I removed the rest of the network and connected my laptop directly.
Oct 18 13:26:06 xinetd 61234 Reconfigured: new=0 old=7 dropped=0 (services) Oct 18 13:26:06 xinetd 61234 readjusting service 19004-udp Oct 18 13:26:06 xinetd 61234 readjusting service 19004-tcp Oct 18 13:26:06 xinetd 61234 readjusting service 19003-udp Oct 18 13:26:06 xinetd 61234 readjusting service 19003-tcp Oct 18 13:26:06 xinetd 61234 readjusting service 19002-tcp Oct 18 13:26:06 xinetd 61234 readjusting service 19001-udp Oct 18 13:26:06 xinetd 61234 readjusting service 19000-tcp Oct 18 13:26:06 xinetd 61234 Swapping defaults Oct 18 13:26:06 xinetd 61234 Starting reconfiguration Oct 18 13:26:05 xinetd 61234 Reconfigured: new=0 old=7 dropped=0 (services) Oct 18 13:26:05 xinetd 61234 readjusting service 19004-udp Oct 18 13:26:05 xinetd 61234 readjusting service 19004-tcp Oct 18 13:26:05 xinetd 61234 readjusting service 19003-udp Oct 18 13:26:05 xinetd 61234 readjusting service 19003-tcp Oct 18 13:26:05 xinetd 61234 readjusting service 19002-tcp Oct 18 13:26:05 xinetd 61234 readjusting service 19001-udp Oct 18 13:26:05 xinetd 61234 readjusting service 19000-tcp Oct 18 13:26:05 xinetd 61234 Swapping defaults Oct 18 13:26:05 xinetd 61234 Starting reconfiguration Oct 18 13:26:05 check_reload_status Reloading filter Oct 18 13:26:04 dhcpleases /etc/hosts changed size from original! Oct 18 13:26:04 php-fpm /rc.newwanip: rc.newwanip: on (IP address: 172.16.0.1) (interface: LAN[lan]) (real interface: em1). Oct 18 13:26:04 php-fpm /rc.newwanip: rc.newwanip: Info: starting on em1. Oct 18 13:26:03 check_reload_status Reloading filter Oct 18 13:26:03 check_reload_status rc.newwanip starting em1 Oct 18 13:26:03 php-fpm /rc.linkup: Hotplug event detected for LAN(lan) static IP (172.16.0.1 ) Oct 18 13:26:02 kernel em1: link state changed to UP Oct 18 13:26:02 check_reload_status Linkup starting em1 Oct 18 13:25:43 xinetd 61234 Reconfigured: new=0 old=7 dropped=0 (services) Oct 18 13:25:43 xinetd 61234 readjusting service 19004-udp Oct 18 13:25:43 xinetd 61234 readjusting service 19004-tcp Oct 18 13:25:43 xinetd 61234 readjusting service 19003-udp Oct 18 13:25:43 xinetd 61234 readjusting service 19003-tcp Oct 18 13:25:43 xinetd 61234 readjusting service 19002-tcp Oct 18 13:25:43 xinetd 61234 readjusting service 19001-udp Oct 18 13:25:43 xinetd 61234 readjusting service 19000-tcp Oct 18 13:25:43 xinetd 61234 Swapping defaults Oct 18 13:25:43 xinetd 61234 Starting reconfiguration Oct 18 13:25:42 check_reload_status Reloading filter Oct 18 13:25:42 php-fpm 96089 /rc.linkup: Hotplug event detected for LAN(lan) static IP (172.16.0.1 ) Oct 18 13:25:40 kernel em1: link state changed to DOWN Oct 18 13:25:40 check_reload_status Linkup starting em1 Oct 18 13:25:39 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:25:29 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:25:19 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:25:09 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:24:59 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:24:49 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:24:39 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:24:29 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:24:19 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:24:09 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:23:59 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:23:49 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:23:39 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:23:29 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:23:19 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:23:09 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:22:59 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:22:49 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:22:39 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:22:29 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:22:19 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:22:09 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:21:59 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:21:49 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:21:39 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:21:29 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:21:19 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:21:09 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:20:59 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:20:49 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:20:39 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:20:29 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:20:19 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:20:09 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:19:59 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:19:49 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:19:39 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:19:29 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:19:19 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:19:08 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:18:58 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:18:48 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:18:38 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:18:28 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:18:18 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:18:08 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:17:58 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:17:48 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:17:38 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:17:28 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:17:18 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:17:08 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:16:58 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:16:48 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:16:38 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:16:28 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:16:18 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:16:08 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:15:58 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:15:48 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:15:38 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:15:28 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:15:18 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:15:08 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:14:58 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:14:48 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:14:38 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:14:28 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:14:18 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:14:08 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:13:58 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:13:48 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:13:38 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:13:28 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:13:18 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:13:08 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:12:58 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:12:48 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:12:38 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:12:28 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:12:18 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:12:08 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:11:58 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:11:48 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:11:38 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:11:28 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:11:18 bandwidthd Drawing initial graphs Oct 18 13:11:18 bandwidthd Packet Encoding: Ethernet Oct 18 13:11:18 bandwidthd Opening em1 Oct 18 13:11:18 bandwidthd Finished recovering 6734 records Oct 18 13:11:18 bandwidthd Drawing initial graphs Oct 18 13:11:18 bandwidthd Packet Encoding: Ethernet Oct 18 13:11:18 bandwidthd Drawing initial graphs Oct 18 13:11:18 bandwidthd Packet Encoding: Ethernet Oct 18 13:11:18 bandwidthd Opening em1 Oct 18 13:11:18 bandwidthd Finished recovering 15392 records Oct 18 13:11:18 bandwidthd Drawing initial graphs Oct 18 13:11:18 bandwidthd Packet Encoding: Ethernet Oct 18 13:11:18 bandwidthd Opening em1 Oct 18 13:11:18 bandwidthd Finished recovering 6734 records Oct 18 13:11:18 bandwidthd Opening em1 Oct 18 13:11:18 bandwidthd Finished recovering 15392 records Oct 18 13:11:18 bandwidthd Recovering from log.1.0.cdf Oct 18 13:11:18 bandwidthd Finished recovering 10361 records Oct 18 13:11:18 bandwidthd Recovering from log.1.0.cdf Oct 18 13:11:18 bandwidthd Finished recovering 10361 records Oct 18 13:11:18 bandwidthd Recovering from log.1.1.cdf Oct 18 13:11:18 bandwidthd Finished recovering 12516 records Oct 18 13:11:18 bandwidthd Recovering from log.1.1.cdf Oct 18 13:11:18 bandwidthd Finished recovering 12516 records Oct 18 13:11:18 bandwidthd Drawing initial graphs Oct 18 13:11:18 bandwidthd Packet Encoding: Ethernet Oct 18 13:11:18 bandwidthd Opening em1 Oct 18 13:11:18 bandwidthd Finished recovering 2548 records Oct 18 13:11:18 bandwidthd Recovering from log.3.0.cdf Oct 18 13:11:18 bandwidthd Recovering from log.2.0.cdf Oct 18 13:11:18 bandwidthd Drawing initial graphs Oct 18 13:11:18 bandwidthd Packet Encoding: Ethernet Oct 18 13:11:18 bandwidthd Opening em1 Oct 18 13:11:18 bandwidthd Finished recovering 185 records Oct 18 13:11:18 bandwidthd Recovering from log.1.2.cdf Oct 18 13:11:18 bandwidthd Recovering from log.4.0.cdf Oct 18 13:11:18 bandwidthd Drawing initial graphs Oct 18 13:11:18 bandwidthd Packet Encoding: Ethernet Oct 18 13:11:18 bandwidthd Opening em1 Oct 18 13:11:18 xinetd 61234 Reconfigured: new=0 old=7 dropped=0 (services) Oct 18 13:11:18 xinetd 61234 readjusting service 19004-udp Oct 18 13:11:18 xinetd 61234 readjusting service 19004-tcp Oct 18 13:11:18 xinetd 61234 readjusting service 19003-udp Oct 18 13:11:18 xinetd 61234 readjusting service 19003-tcp Oct 18 13:11:18 xinetd 61234 readjusting service 19002-tcp Oct 18 13:11:18 xinetd 61234 readjusting service 19001-udp Oct 18 13:11:18 xinetd 61234 readjusting service 19000-tcp Oct 18 13:11:18 xinetd 61234 Swapping defaults Oct 18 13:11:18 xinetd 61234 Starting reconfiguration Oct 18 13:11:18 bandwidthd Finished recovering 2548 records Oct 18 13:11:18 bandwidthd Drawing initial graphs Oct 18 13:11:18 bandwidthd Packet Encoding: Ethernet Oct 18 13:11:18 bandwidthd Opening em1 Oct 18 13:11:18 bandwidthd Finished recovering 185 records Oct 18 13:11:18 bandwidthd Recovering from log.4.0.cdf Oct 18 13:11:18 bandwidthd Recovering from log.1.2.cdf Oct 18 13:11:18 bandwidthd Recovering from log.3.0.cdf Oct 18 13:11:18 bandwidthd Recovering from log.2.0.cdf Oct 18 13:11:18 bandwidthd Monitoring subnet 172.16.8.0 with netmask 255.255.252.0 Oct 18 13:11:18 bandwidthd Monitoring subnet [My_WAN_Subnet] with netmask 255.255.255.128 Oct 18 13:11:18 bandwidthd Monitoring subnet 10.4.216.0 with netmask 255.255.255.0 Oct 18 13:11:18 bandwidthd Monitoring subnet 172.16.0.0 with netmask 255.255.252.0 Oct 18 13:11:18 bandwidthd Monitoring subnet 172.16.8.0 with netmask 255.255.252.0 Oct 18 13:11:18 bandwidthd Monitoring subnet [My_WAN_Subnet] with netmask 255.255.255.128 Oct 18 13:11:18 bandwidthd Monitoring subnet 10.4.216.0 with netmask 255.255.255.0 Oct 18 13:11:18 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:11:18 bandwidthd Monitoring subnet 172.16.0.0 with netmask 255.255.252.0 Oct 18 13:11:17 php-fpm 337 /rc.start_packages: Restarting/Starting all packages. Oct 18 13:11:16 check_reload_status Starting packages Oct 18 13:11:16 check_reload_status Reloading filter Oct 18 13:11:14 pkg-static whois-5.2.17 deinstalled Oct 18 13:11:14 pkg-static lua52-5.2.4 deinstalled Oct 18 13:11:14 pkg-static icu-62.1_1,1 deinstalled Oct 18 13:11:14 pkg-static grepcidr-2.0 deinstalled Oct 18 13:11:14 pkg-static aggregate-1.6_1 deinstalled Oct 18 13:11:14 pkg-static lighttpd-1.4.49 deinstalled Oct 18 13:11:14 pkg-static php72-intl-7.2.10 deinstalled Oct 18 13:11:13 xinetd 61234 Reconfigured: new=0 old=7 dropped=0 (services) Oct 18 13:11:13 xinetd 61234 readjusting service 19004-udp Oct 18 13:11:13 xinetd 61234 readjusting service 19004-tcp Oct 18 13:11:13 xinetd 61234 readjusting service 19003-udp Oct 18 13:11:13 xinetd 61234 readjusting service 19003-tcp Oct 18 13:11:13 xinetd 61234 readjusting service 19002-tcp Oct 18 13:11:13 xinetd 61234 readjusting service 19001-udp Oct 18 13:11:13 xinetd 61234 readjusting service 19000-tcp Oct 18 13:11:13 xinetd 61234 Swapping defaults Oct 18 13:11:13 xinetd 61234 Starting reconfiguration Oct 18 13:11:13 pkg-static pfSense-pkg-pfBlockerNG-2.1.4_13 deinstalled Oct 18 13:11:12 check_reload_status Syncing firewall Oct 18 13:11:12 check_reload_status Reloading filter Oct 18 13:11:12 php [pfBlockerNG] Starting cron process. Oct 18 13:11:12 check_reload_status Syncing firewall Oct 18 13:11:10 check_reload_status Syncing firewall Oct 18 13:11:08 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:10:57 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:10:48 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:10:38 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:10:28 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:10:17 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:10:07 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:09:57 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:09:47 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:09:37 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:09:27 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:09:17 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:09:07 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:08:57 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:08:47 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:08:37 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:08:27 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:08:17 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:08:07 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:07:57 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:07:47 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:07:37 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:07:27 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:07:17 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:07:07 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:06:57 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:06:47 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:06:37 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:06:27 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:06:17 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:06:07 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:05:57 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:05:47 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:05:37 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:05:27 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:05:17 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:05:07 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:04:57 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:04:47 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:04:37 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:04:27 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:04:17 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:04:07 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:03:57 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:03:47 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:03:37 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:03:27 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:03:17 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:03:07 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:02:56 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:02:47 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:02:37 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:02:26 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:02:16 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:02:06 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:01:57 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:01:46 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:01:36 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:01:26 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:01:16 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:01:06 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:00:56 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:00:46 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:00:36 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:00:26 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:00:16 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 13:00:06 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:59:56 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:59:46 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:59:36 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:59:26 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:59:16 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:59:06 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:58:56 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:58:46 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:58:36 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:58:26 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:58:16 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:58:06 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:57:56 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:57:46 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:57:36 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:57:26 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:57:16 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:57:06 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:56:56 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:56:46 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:56:36 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:56:26 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:56:16 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:56:06 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:55:56 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:55:52 php-fpm 337 /rc.dyndns.update: phpDynDNS ([My_DDNS_Address]): No change in my IP address and/or 25 days has not passed. Not updating dynamic DNS entry. Oct 18 12:55:52 xinetd 61234 Reconfigured: new=0 old=7 dropped=0 (services) Oct 18 12:55:52 xinetd 61234 readjusting service 19004-udp Oct 18 12:55:52 xinetd 61234 readjusting service 19004-tcp Oct 18 12:55:52 xinetd 61234 readjusting service 19003-udp Oct 18 12:55:52 xinetd 61234 readjusting service 19003-tcp Oct 18 12:55:52 xinetd 61234 readjusting service 19002-tcp Oct 18 12:55:52 xinetd 61234 readjusting service 19001-udp Oct 18 12:55:52 xinetd 61234 readjusting service 19000-tcp Oct 18 12:55:52 xinetd 61234 Swapping defaults Oct 18 12:55:52 xinetd 61234 Starting reconfiguration Oct 18 12:55:51 php-fpm /rc.openvpn: OpenVPN: One or more OpenVPN tunnel endpoints may have changed its IP. Reloading endpoints that may use WAN_DHCP. Oct 18 12:55:51 php-fpm /rc.openvpn: Gateway, none 'available' for inet6, use the first one configured. '' Oct 18 12:55:50 check_reload_status Reloading filter Oct 18 12:55:50 check_reload_status Restarting OpenVPN tunnels/interfaces Oct 18 12:55:50 check_reload_status Restarting ipsec tunnels Oct 18 12:55:50 check_reload_status updating dyndns WAN_DHCP Oct 18 12:55:50 rc.gateway_alarm 61425 >>> Gateway alarm: WAN_DHCP (Addr:[My_WAN_IP] Alarm:0 RTT:31.575ms RTTsd:56.185ms Loss:15%) Oct 18 12:55:46 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:55:36 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:55:32 php-fpm /rc.dyndns.update: phpDynDNS ([My_DDNS_Address]): No change in my IP address and/or 25 days has not passed. Not updating dynamic DNS entry. Oct 18 12:55:31 xinetd 61234 Reconfigured: new=0 old=7 dropped=0 (services) Oct 18 12:55:31 xinetd 61234 readjusting service 19004-udp Oct 18 12:55:31 xinetd 61234 readjusting service 19004-tcp Oct 18 12:55:31 xinetd 61234 readjusting service 19003-udp Oct 18 12:55:31 xinetd 61234 readjusting service 19003-tcp Oct 18 12:55:31 xinetd 61234 readjusting service 19002-tcp Oct 18 12:55:31 xinetd 61234 readjusting service 19001-udp Oct 18 12:55:31 xinetd 61234 readjusting service 19000-tcp Oct 18 12:55:31 xinetd 61234 Swapping defaults Oct 18 12:55:31 xinetd 61234 Starting reconfiguration Oct 18 12:55:31 php-fpm 337 /rc.openvpn: OpenVPN: One or more OpenVPN tunnel endpoints may have changed its IP. Reloading endpoints that may use WAN_DHCP. Oct 18 12:55:31 php-fpm 337 /rc.openvpn: Gateway, none 'available' for inet6, use the first one configured. '' Oct 18 12:55:30 check_reload_status Reloading filter Oct 18 12:55:30 check_reload_status Restarting OpenVPN tunnels/interfaces Oct 18 12:55:30 check_reload_status Restarting ipsec tunnels Oct 18 12:55:30 check_reload_status updating dyndns WAN_DHCP Oct 18 12:55:30 rc.gateway_alarm 66697 >>> Gateway alarm: WAN_DHCP (Addr:[My_WAN_IP] Alarm:1 RTT:42.993ms RTTsd:66.374ms Loss:21%) Oct 18 12:55:26 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:55:16 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:55:06 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:54:56 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:54:46 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:54:36 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:54:26 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:54:15 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:54:05 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:53:55 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:53:45 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:53:36 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:53:25 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:53:15 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:53:05 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:52:55 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:52:45 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:52:35 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:52:25 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:52:15 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:52:05 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:51:55 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:51:45 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:51:35 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:51:25 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:51:15 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:51:05 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:50:55 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:50:45 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:50:35 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:50:25 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:50:15 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:50:05 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:49:55 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:49:45 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:49:35 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:49:25 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:49:15 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:49:05 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:48:55 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:48:45 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:48:35 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:48:25 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:48:15 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:48:05 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:47:55 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:47:45 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:47:35 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:47:25 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:47:15 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:47:05 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:46:55 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:46:45 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:46:35 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:46:25 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:46:15 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:46:05 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:45:54 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:45:45 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:45:34 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:45:25 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:45:14 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:45:04 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:44:54 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:44:44 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:44:34 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:44:24 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:44:14 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:44:04 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:43:54 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:43:44 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:43:34 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:43:24 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:43:14 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:43:04 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:42:54 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:42:44 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:42:34 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:42:24 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:42:14 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:42:04 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:41:54 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:41:44 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:41:34 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:41:24 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:41:14 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:41:04 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:40:54 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:40:44 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:40:34 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:40:24 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:40:14 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:40:04 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:39:54 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:39:44 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:39:34 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:39:24 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:39:14 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:39:04 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:38:54 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:38:44 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:38:34 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:38:24 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:38:14 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:38:04 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:37:54 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:37:44 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:37:33 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:37:23 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:37:13 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:37:03 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:36:53 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:36:43 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:36:33 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:36:23 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:36:13 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:36:03 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:35:53 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:35:43 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:35:33 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:35:23 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:35:13 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:35:03 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:34:53 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:34:43 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:34:33 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:34:23 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:34:13 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:34:03 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:33:53 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:33:43 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:33:33 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:33:23 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:33:13 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:33:03 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:32:53 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:32:43 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:32:33 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:32:23 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:32:13 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:32:03 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:31:53 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:31:43 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:31:33 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:31:23 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:31:13 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:31:03 kernel arp: 43:05:43:05:00:00 is multicast Oct 18 12:30:53 kernel arp: 43:05:43:05:00:00 is multicast
The Gateway logs only show this for today:
Oct 18 12:55:50 dpinger WAN_DHCP [My_WAN_IP]: Clear latency 31575us stddev 56185us loss 15% Oct 18 12:55:30 dpinger WAN_DHCP [My_WAN_IP]: Alarm latency 42993us stddev 66374us loss 21%
-
Here is a sample of the firewall logs over the last 40 minutes with just my laptop connected. This should give an idea of the frequency, all these connections were blocked.
Oct 18 14:39:44 WAN 176.119.7.30:46507 [My_WAN_IP]:55288 TCP:S Oct 18 14:39:40 WAN 5.188.206.247:50641 [My_WAN_IP]:5903 TCP:S Oct 18 14:38:41 WAN 185.35.62.99:60389 [My_WAN_IP]:123 UDP Oct 18 14:38:06 WAN 77.72.85.27:48856 [My_WAN_IP]:3395 TCP:S Oct 18 14:38:04 WAN 103.198.81.168:16054 [My_WAN_IP]:23 TCP:S Oct 18 14:38:03 WAN 176.119.7.2:44833 [My_WAN_IP]:11021 TCP:S Oct 18 14:37:33 WAN [fe80::217:10ff:fe91:f1e] [ff02::1] ICMPv6 Oct 18 14:37:31 WAN 71.6.199.23:25399 [My_WAN_IP]:1777 TCP:S Oct 18 14:37:14 WAN 176.119.7.66:45059 [My_WAN_IP]:3353 TCP:S Oct 18 14:37:06 WAN 185.255.31.77:40386 [My_WAN_IP]:33895 TCP:S Oct 18 14:36:57 WAN 99.239.246.93 224.0.0.1 IGMP Oct 18 14:36:40 WAN 198.62.109.180:20417 [My_WAN_IP]:5900 TCP:S Oct 18 14:36:29 WAN 185.255.31.77:40386 [My_WAN_IP]:14000 TCP:S Oct 18 14:36:18 WAN 151.177.128.210:29365 [My_WAN_IP]:23 TCP:S Oct 18 14:35:49 WAN 223.81.51.70:46856 [My_WAN_IP]:23 TCP:S Oct 18 14:35:36 WAN 81.198.253.223:36482 [My_WAN_IP]:5555 TCP:S Oct 18 14:35:34 WAN 185.153.196.21:45891 [My_WAN_IP]:3686 TCP:S Oct 18 14:34:56 WAN 5.188.206.14:45784 [My_WAN_IP]:3392 TCP:S Oct 18 14:32:51 WAN 78.128.112.62:50115 [My_WAN_IP]:60689 TCP:S Oct 18 14:32:45 WAN 216.243.31.2:45067 [My_WAN_IP]:443 TCP:S Oct 18 14:32:07 WAN 184.105.139.82:59078 [My_WAN_IP]:23 TCP:S Oct 18 14:31:01 WAN 153.3.73.125:41765 [My_WAN_IP]:23 TCP:S Oct 18 14:30:57 WAN 36.233.70.89:36112 [My_WAN_IP]:23 TCP:S Oct 18 14:30:49 WAN 185.53.91.25:5190 [My_WAN_IP]:5060 UDP Oct 18 14:30:46 WAN [fe80::217:10ff:fe91:f1e] [ff02::1] ICMPv6 Oct 18 14:30:45 WAN 36.233.70.89:36112 [My_WAN_IP]:23 TCP:S Oct 18 14:30:39 WAN 36.233.70.89:36112 [My_WAN_IP]:23 TCP:S Oct 18 14:30:36 WAN 95.38.69.173:55465 [My_WAN_IP]:8080 TCP:S Oct 18 14:30:36 WAN 36.233.70.89:36112 [My_WAN_IP]:23 TCP:S Oct 18 14:29:48 WAN 176.119.7.62:45984 [My_WAN_IP]:55001 TCP:S Oct 18 14:29:22 WAN 31.192.108.68:45417 [My_WAN_IP]:32942 TCP:S Oct 18 14:29:20 WAN 185.255.31.77:40386 [My_WAN_IP]:2000 TCP:S Oct 18 14:28:57 WAN 99.239.246.93 224.0.0.1 IGMP Oct 18 14:28:16 WAN 176.119.7.66:45059 [My_WAN_IP]:8008 TCP:S Oct 18 14:28:06 WAN 176.119.7.66:45059 [My_WAN_IP]:6565 TCP:S Oct 18 14:27:54 WAN 89.46.77.10:47022 [My_WAN_IP]:81 TCP:S Oct 18 14:27:47 WAN 176.119.7.50:59692 [My_WAN_IP]:6840 TCP:S Oct 18 14:27:25 WAN 5.188.86.61:52992 [My_WAN_IP]:3391 TCP:S Oct 18 14:27:25 WAN 188.19.214.185:20396 [My_WAN_IP]:23 TCP:S Oct 18 14:26:12 LAN [fe80::f851:dad0:5b2:d204]:61568 [ff02::1:3]:5355 UDP Oct 18 14:26:12 LAN [fe80::f851:dad0:5b2:d204]:5353 [ff02::fb]:5353 UDP Oct 18 14:26:12 LAN [fe80::f851:dad0:5b2:d204]:5353 [ff02::fb]:5353 UDP Oct 18 14:26:00 WAN 113.120.95.152:16677 [My_WAN_IP]:37215 TCP:S Oct 18 14:25:29 WAN 196.52.43.57:63722 [My_WAN_IP]:1433 TCP:S Oct 18 14:25:26 WAN 206.189.173.187:57850 [My_WAN_IP]:23 TCP:S Oct 18 14:24:47 WAN 185.255.31.77:40386 [My_WAN_IP]:9182 TCP:S Oct 18 14:24:25 WAN 37.79.151.78:24394 [My_WAN_IP]:23 TCP:S Oct 18 14:24:13 WAN 93.175.215.132:37940 [My_WAN_IP]:23 TCP:S Oct 18 14:24:02 WAN 5.188.206.247:50641 [My_WAN_IP]:5913 TCP:S Oct 18 14:23:58 WAN [fe80::217:10ff:fe91:f1e] [ff02::1] ICMPv6 Oct 18 14:23:49 WAN 185.255.31.2:54534 [My_WAN_IP]:432 TCP:S Oct 18 14:23:43 WAN 14.236.193.71:24757 [My_WAN_IP]:2323 TCP:S Oct 18 14:23:42 WAN 176.119.7.50:59692 [My_WAN_IP]:6802 TCP:S Oct 18 14:23:09 WAN 5.8.54.27:46755 [My_WAN_IP]:8088 TCP:S Oct 18 14:22:48 WAN 185.200.118.67:32957 [My_WAN_IP]:1080 TCP:S Oct 18 14:22:34 WAN 107.170.219.71:49809 [My_WAN_IP]:81 TCP:S Oct 18 14:22:19 WAN 178.132.217.245:48589 [My_WAN_IP]:1433 TCP:S Oct 18 14:22:00 WAN 209.141.40.63:42635 [My_WAN_IP]:5050 TCP:S Oct 18 14:21:20 WAN 186.194.199.33:23208 [My_WAN_IP]:23 TCP:S Oct 18 14:21:15 WAN 209.141.62.172:42737 [My_WAN_IP]:6666 TCP:S Oct 18 14:20:57 WAN 99.239.246.93 224.0.0.1 IGMP Oct 18 14:19:09 WAN 80.82.70.118:60000 [My_WAN_IP]:3790 TCP:S Oct 18 14:19:07 WAN 205.185.123.211:42612 [My_WAN_IP]:5000 TCP:S Oct 18 14:18:38 WAN 209.141.36.21:42685 [My_WAN_IP]:5555 TCP:S Oct 18 14:17:38 WAN 213.30.47.33:53895 [My_WAN_IP]:22 TCP:S Oct 18 14:17:09 WAN [fe80::217:10ff:fe91:f1e] [ff02::1] ICMPv6 Oct 18 14:16:15 WAN 37.49.231.76:5146 [My_WAN_IP]:5060 UDP Oct 18 14:15:41 WAN 188.16.40.130:11807 [My_WAN_IP]:23 TCP:S Oct 18 14:15:23 WAN 185.153.198.223:57657 [My_WAN_IP]:4298 TCP:S Oct 18 14:14:54 WAN 36.238.9.154:46325 [My_WAN_IP]:23 TCP:S Oct 18 14:14:47 WAN 36.238.9.154:46325 [My_WAN_IP]:23 TCP:S Oct 18 14:14:44 WAN 36.238.9.154:46325 [My_WAN_IP]:23 TCP:S Oct 18 14:13:43 WAN 74.82.47.27:36971 [My_WAN_IP]:2323 TCP:S Oct 18 14:13:23 WAN 141.237.97.201:43756 [My_WAN_IP]:80 TCP:S Oct 18 14:12:58 WAN 177.94.157.159:55019 [My_WAN_IP]:8080 TCP:S Oct 18 14:12:57 WAN 99.239.246.93 224.0.0.1 IGMP Oct 18 14:12:14 WAN 125.24.104.40:52975 [My_WAN_IP]:88 TCP:S Oct 18 14:11:43 WAN 185.255.31.77:40386 [My_WAN_IP]:30000 TCP:S Oct 18 14:10:59 WAN 91.210.25.207:80 [My_WAN_IP]:5131 TCP:SA Oct 18 14:10:34 WAN 118.175.13.138:50081 [My_WAN_IP]:1433 TCP:S Oct 18 14:10:22 WAN [fe80::217:10ff:fe91:f1e] [ff02::1] ICMPv6 Oct 18 14:09:01 WAN 196.52.43.60:61888 [My_WAN_IP]:5900 TCP:S Oct 18 14:07:58 WAN 185.255.31.77:40386 [My_WAN_IP]:40010 TCP:S Oct 18 14:05:59 WAN 65.39.79.144:55665 [My_WAN_IP]:8443 TCP:S Oct 18 14:05:01 WAN 115.59.12.17:18195 [My_WAN_IP]:2323 TCP:S Oct 18 14:04:57 WAN 99.239.246.93 224.0.0.1 IGMP Oct 18 14:03:56 WAN 78.128.112.62:50115 [My_WAN_IP]:37559 TCP:S Oct 18 14:03:35 WAN 223.80.19.12:38529 [My_WAN_IP]:23 TCP:S Oct 18 14:03:34 WAN [fe80::217:10ff:fe91:f1e] [ff02::1] ICMPv6 Oct 18 14:00:08 WAN 37.191.196.1:8875 [My_WAN_IP]:22 TCP:S Oct 18 14:00:03 WAN 46.174.191.28:20222 [My_WAN_IP]:8080 TCP:S
-
This is just normal background noise and should not cause any of your problems.
I think the problem is upstream from you (your ISP, maybe they got routing/peering issues). If possible replace your edge router just to confirm the problem is not your equipment and call the ISP.-Rico
-
I agree with Rico. 4-5 blocks per second is literally statistically insignificant. This looks interesting:
Oct 18 13:25:42 php-fpm 96089 /rc.linkup: Hotplug event detected for LAN(lan) static IP (172.16.0.1 ) Oct 18 13:25:40 kernel em1: link state changed to DOWN
You may have a bad cable or flaky port on wither your router or the cablemodem. This error means there is no link on your NIC. Was it working well for some period of time before it started doing this? Or was it doing this from the moment you installed pfSense?
-
The 'link state changed to down' you see there is me unplugging the internal network, then plugging my laptop directly to the Lan interface on pfSense.
I disconnected pfsense and tried an old router I had laying around (WRT54G), and the time outs continued.
I then bypassed any router and connected my laptop directly to the modem, the time outs still happened so I tried another PC directly connected to the modem and time outs still happen.
When my computer was connected directly to the modem, I was pinging the providers gateway and getting time outs so for sure anything beyond that will get time outs.
I think its safe to say its something with the ISP, possibly their gateway or a switch in between, I've submitted a ticket with them to investigate.
-
Thanks for the update.