Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Weird Bogon activity on Realtek NIC

    Scheduled Pinned Locked Moved Firewalling
    17 Posts 3 Posters 1.2k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N Offline
      netblues
      last edited by

      Well. as I said, 0.0.0.0 is defined as bogus if you see packets from it.
      However, during dhcp requests, 0.0.0.0 is used. See dhcp negotiation for more details.

      T 1 Reply Last reply Reply Quote 0
      • T Offline
        techtester-m @netblues
        last edited by

        @netblues Where do I see such negotiations?

        1 Reply Last reply Reply Quote 0
        • N Offline
          netblues
          last edited by

          On the log posted, you have requests from 0.0.0.0 addressed to udp port 67. This looks like a dhcp request.
          https://en.wikipedia.org/wiki/Dynamic_Host_Configuration_Protocol

          T 1 Reply Last reply Reply Quote 0
          • T Offline
            techtester-m @netblues
            last edited by

            @netblues Ok...So that's how a machine asks to lease an IP. So should I remove that bogon rule or would setting a static IP to that machine fix it?

            1 Reply Last reply Reply Quote 0
            • N Offline
              netblues
              last edited by

              Probably both will do, virtualisation (if any ) could also be playing games with you.

              T 1 Reply Last reply Reply Quote 0
              • T Offline
                techtester-m @netblues
                last edited by

                @netblues How does it work eventually with the PC receiving IP regardless if this rule? Maybe something else causing that

                1 Reply Last reply Reply Quote 0
                • N Offline
                  netblues
                  last edited by

                  Where is the dhcp server? On pf? somewhere else?

                  T 1 Reply Last reply Reply Quote 0
                  • T Offline
                    techtester-m @netblues
                    last edited by

                    @netblues Everything is on pfSense

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ Offline
                      johnpoz LAYER 8 Global Moderator
                      last edited by johnpoz

                      Bogon should never be set on a lan interface!! rfc1918 is official part of bogon.. Even though pfsense pulls it out.

                      "Bogons are defined as Martians (private and reserved addresses defined by RFC 1918, RFC 5735, and RFC 6598) and netblocks that have not been allocated to a regional internet registry (RIR) by the Internet Assigned Numbers Authority."

                      You using on a lan side interface is going to cause you grief!!

                      There is zero point using bogon on a lan side interface..

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 25.07 | Lab VMs 2.8, 25.07

                      T 1 Reply Last reply Reply Quote 1
                      • T Offline
                        techtester-m @johnpoz
                        last edited by techtester-m

                        @johnpoz Screen Shot 2019-12-10 at 21.40.12.png

                        Then the above description by pfSense is misleading...

                        @johnpoz said in Weird Bogon activity on Realtek NIC:

                        There is zero point using bogon on a lan side interface

                        But any how...I get your point

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ Offline
                          johnpoz LAYER 8 Global Moderator
                          last edited by johnpoz

                          See my edit.. Pfsense pulls it out of bogon, because they use their own other rfc1918 block table..

                          Here is the thing if your setting bogon on your lan your doing it WRONG!!! There is zero reason to set that, and clearly you have no clue to what it actually is or you wouldn't be setting it..

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 25.07 | Lab VMs 2.8, 25.07

                          T 1 Reply Last reply Reply Quote 1
                          • T Offline
                            techtester-m @johnpoz
                            last edited by

                            @johnpoz Well...the only scenario I could think of is a virus or malicious software sitting on the lan and using bogon addresses LOL....Ok, I removed that rule. It should only be set on the WAN

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.