Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Weird Bogon activity on Realtek NIC

    Scheduled Pinned Locked Moved Firewalling
    17 Posts 3 Posters 1.2k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      techtester-m @netblues
      last edited by

      @netblues Where do I see such negotiations?

      1 Reply Last reply Reply Quote 0
      • N Offline
        netblues
        last edited by

        On the log posted, you have requests from 0.0.0.0 addressed to udp port 67. This looks like a dhcp request.
        https://en.wikipedia.org/wiki/Dynamic_Host_Configuration_Protocol

        T 1 Reply Last reply Reply Quote 0
        • T Offline
          techtester-m @netblues
          last edited by

          @netblues Ok...So that's how a machine asks to lease an IP. So should I remove that bogon rule or would setting a static IP to that machine fix it?

          1 Reply Last reply Reply Quote 0
          • N Offline
            netblues
            last edited by

            Probably both will do, virtualisation (if any ) could also be playing games with you.

            T 1 Reply Last reply Reply Quote 0
            • T Offline
              techtester-m @netblues
              last edited by

              @netblues How does it work eventually with the PC receiving IP regardless if this rule? Maybe something else causing that

              1 Reply Last reply Reply Quote 0
              • N Offline
                netblues
                last edited by

                Where is the dhcp server? On pf? somewhere else?

                T 1 Reply Last reply Reply Quote 0
                • T Offline
                  techtester-m @netblues
                  last edited by

                  @netblues Everything is on pfSense

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Offline
                    johnpoz LAYER 8 Global Moderator
                    last edited by johnpoz

                    Bogon should never be set on a lan interface!! rfc1918 is official part of bogon.. Even though pfsense pulls it out.

                    "Bogons are defined as Martians (private and reserved addresses defined by RFC 1918, RFC 5735, and RFC 6598) and netblocks that have not been allocated to a regional internet registry (RIR) by the Internet Assigned Numbers Authority."

                    You using on a lan side interface is going to cause you grief!!

                    There is zero point using bogon on a lan side interface..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07 | Lab VMs 2.8, 25.07

                    T 1 Reply Last reply Reply Quote 1
                    • T Offline
                      techtester-m @johnpoz
                      last edited by techtester-m

                      @johnpoz Screen Shot 2019-12-10 at 21.40.12.png

                      Then the above description by pfSense is misleading...

                      @johnpoz said in Weird Bogon activity on Realtek NIC:

                      There is zero point using bogon on a lan side interface

                      But any how...I get your point

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Offline
                        johnpoz LAYER 8 Global Moderator
                        last edited by johnpoz

                        See my edit.. Pfsense pulls it out of bogon, because they use their own other rfc1918 block table..

                        Here is the thing if your setting bogon on your lan your doing it WRONG!!! There is zero reason to set that, and clearly you have no clue to what it actually is or you wouldn't be setting it..

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07 | Lab VMs 2.8, 25.07

                        T 1 Reply Last reply Reply Quote 1
                        • T Offline
                          techtester-m @johnpoz
                          last edited by

                          @johnpoz Well...the only scenario I could think of is a virus or malicious software sitting on the lan and using bogon addresses LOL....Ok, I removed that rule. It should only be set on the WAN

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.