Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Issues with pfsense firewall log

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 3 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      koko_adams
      last edited by

      i have pfsense 2.4.3

      i watch the firewall logs and i have seen that :

      Mar 8 19:03:14 LAN Default deny rule IPv4 (1000000103) 10.90.90.90:62976 255.255.255.255:62976 UDP

      the 10.90.90.90 is the only switch in my firewall

      what this log ? and i can resolv that ?

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by

        @koko_adams said in Issues with pfsense firewall log:

        Mar 8 19:03:14 LAN Default deny rule IPv4 (1000000103) 10.90.90.90:62976 255.255.255.255:62976 UDP

        Mar 8 19:03:14 LAN Default deny rule IPv4 (1000000103) 10.90.90.90:62976 255.255.255.255:62976 UDP

        It's broadcast traffic.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • K
          koko_adams
          last edited by

          how i can resolv this , sir ?

          what is the default rule for disable logging ?

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            @koko_adams said in Issues with pfsense firewall log:

            62976

            I would be more concerned with why your seeing the traffic in the first place
            https://www.speedguide.net/port.php?port=62976

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            K 1 Reply Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad
              last edited by

              https://docs.netgate.com/pfsense/en/latest/monitoring/firewall-logs.html

              Or add a rule to block and not log, place it at the bottom.

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              1 Reply Last reply Reply Quote 1
              • K
                koko_adams @johnpoz
                last edited by

                @johnpoz

                this logs is repeated more and more

                It's a annoying

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by johnpoz

                  Yeah and you should look to why your seeing that traffic on your network vs just not logging it... That is not NORMAL traffic...

                  If it was on your wan (internet) I would say just ignore it but if that is local?? Shouldn't be see that.. Do you have any of those cameras?

                  Do a packet capture on pfsense and capture that traffic and upload the pcap.. Lets take a look to what is in it.

                  https://vuldb.com/?id.22182

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  K 1 Reply Last reply Reply Quote 0
                  • K
                    koko_adams @johnpoz
                    last edited by

                    @johnpoz

                    i have a camera in my lan network

                    this is a capture

                    06:53:51.650228 IP 10.90.90.90.62976 > 255.255.255.255.62976: UDP, length 317

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by johnpoz

                      That is not the capture.. Download the file and post up the pcap file.

                      0_1552122809239_downloadpcap.png

                      But 10.90.90.90 is your SWITCH IP, or is that the camera IP?

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.