Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    RRD shows high number of blocked packets, but logs do not.

    Scheduled Pinned Locked Moved General pfSense Questions
    12 Posts 4 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jsvg
      last edited by

      Hey guys,

      Try to get to the bottom of a problem. The packet graphs show we're blocking quite a few packets, but our logs do not show what they are. How do I figure out what is going on?

      If you look at the attachment, it says we're blocking 1000/sec. If I look at my firewall block logs, I have 85 entries. What gives?
      ![Screen Shot 2015-06-06 at 11.34.44 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2015-06-06 at 11.34.44 AM.png_thumb)
      ![Screen Shot 2015-06-06 at 11.34.44 AM.png](/public/imported_attachments/1/Screen Shot 2015-06-06 at 11.34.44 AM.png)

      1 Reply Last reply Reply Quote 0
      • H Offline
        Harvy66
        last edited by

        Have you tried looking at your logs to see what's being blocked?

        1 Reply Last reply Reply Quote 0
        • J Offline
          jsvg
          last edited by

          That's exactly the problem… RRD shows I'm blocking 1000 packets / second but my logs are showing very little activity. I'm trying to figure out what is being blocked, but it's not in my logs.

          1 Reply Last reply Reply Quote 0
          • H Offline
            Harvy66
            last edited by

            Then you must have a rule that is blocking but not logging.

            1 Reply Last reply Reply Quote 0
            • J Offline
              jsvg
              last edited by

              So I only had three rules that would have qualified, and I disabled them all.

              Still seeing the traffic and not seeing the logs…

              1 Reply Last reply Reply Quote 0
              • S Offline
                Supermule Banned
                last edited by

                How do you know its blocked packets?

                I cant seem to find the setting that shows blocked packets.

                @j@svg:

                That's exactly the problem… RRD shows I'm blocking 1000 packets / second but my logs are showing very little activity. I'm trying to figure out what is being blocked, but it's not in my logs.

                1 Reply Last reply Reply Quote 0
                • H Offline
                  Harvy66
                  last edited by

                  The RRD PPS graph he posted shows blocked PPS of near 1k/s, the light red color.

                  1 Reply Last reply Reply Quote 0
                  • C Offline
                    cmb
                    last edited by

                    Did you disable logging on the default rules? Status>System logs, Settings tab.

                    1 Reply Last reply Reply Quote 0
                    • J Offline
                      jsvg
                      last edited by

                      Log packets matched from the default block rules put in the ruleset
                      Hint: packets that are blocked by the implicit default block rule will not be logged if you uncheck this option. Per-rule logging options are still respected.

                      That option -is- checked.

                      On my syslog settings, I have firewall rules -not- sent to syslog, so I disabled syslog completely. No dice :/

                      1 Reply Last reply Reply Quote 0
                      • J Offline
                        jsvg
                        last edited by

                        I'm an idiot, I just re-read that carefully. Let me try it…

                        1 Reply Last reply Reply Quote 0
                        • J Offline
                          jsvg
                          last edited by

                          Nope, doesn't make a difference. argh

                          1 Reply Last reply Reply Quote 0
                          • C Offline
                            cmb
                            last edited by

                            So you have no firewall logs at all then? Sounds like you've disabled all logging, or at least logging of default block and other rules. Turn on local logging again, and make sure default blocks are all logging.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.