Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Outbound traffic from LAN sourced from unknown external public IP address

    Scheduled Pinned Locked Moved Firewalling
    10 Posts 3 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P Offline
      pvols1979
      last edited by

      I am seeing traffic originating from my LAN coming from an unknown public IP address and destined for known IP addresses on my LAN.  This doesn't seem right to me.  The example below if off of my LAN interface, em1.  Can someone help me understand this?  Could this be something on my LAN spoofing connections to internal servers?

      Feb  6 10:34:00 filterlog: 87,16777216,,1000004765,em1,match,pass,out,4,0x0,,113,19058,0,DF,6,tcp,52,199.202.216.106,192.168.1.5,56152,56555,0,S,352846900,,8192,,mss;nop;wscale;nop;nop;sackOK

      Let Your Geek Hangout
      Geekzweb.com

      1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann
        last edited by

        @pvols1979:

        I am seeing traffic originating from my LAN coming from an unknown public IP address

        Why do you think so?

        The log says, the packet goes out em1.
        This traffic would be permitted by a floating rule.

        1 Reply Last reply Reply Quote 0
        • P Offline
          pvols1979
          last edited by

          em1 is my LAN interface.  Why is any address other than a LAN address leaving my LAN?  Also, why is a non-LAN address leaving my LAN and going to an address that actually exists on my LAN.  My LAN net is 192.168.1.x.  I would not expect to see any other address leaving my LAN, especially not a public IP that does not exist behind my firewall.

          Let Your Geek Hangout
          Geekzweb.com

          1 Reply Last reply Reply Quote 0
          • P Offline
            pvols1979
            last edited by

            I just noticed that these events appear to be torrent connections based on the port.  I still don't understand the logic though.

            Let Your Geek Hangout
            Geekzweb.com

            1 Reply Last reply Reply Quote 0
            • V Offline
              viragomann
              last edited by

              @pvols1979:

              Why is any address other than a LAN address leaving my LAN?  Also, why is a non-LAN address leaving my LAN and going to an address that actually exists on my LAN.

              I guess the reason is, that it is allowed by rules.

              Now, what's about your floating rules? Have you any floating rules?
              Have you activated UPnP?

              Check Status > System Logs > Firewall for this entry. pfSense will show the appropriate firewall rule there.

              1 Reply Last reply Reply Quote 0
              • DerelictD Offline
                Derelict LAYER 8 Netgate
                last edited by

                1000004765 <– That's the rule that passed it:

                Diagnostics > Command Prompt, Execute grep 1000004765 /tmp/rules.debug

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • P Offline
                  pvols1979
                  last edited by

                  Ok. I'm an idiot. I never thought about actually looking at the rule instead of trying to make sense out of the log. Thanks. Man, I hate when I overlook something that simple. Now to figure out what this rule is doing.

                  Let Your Geek Hangout
                  Geekzweb.com

                  1 Reply Last reply Reply Quote 0
                  • P Offline
                    pvols1979
                    last edited by

                    Ok. So, that actually doesn't help answer my question.  I was not so much concerned about whether or not it was blocked.  I can see that from the logs.  It was blocked as it should have been.  My question was why would I see, on my LAN interface, source addresses that are external?  It appears as though these source addresses are behind my LAN, which they are not.  Should I ever see an external NET address as a source from my LAN interface outbound? That is what I see from the sample event I posted.  Please tell me if I am misinterpreting.

                    In other words, I would expect every log from my LAN interface OUTBOUND, whether it is blocked or passed, to be sourced with a LAN address and not an external address.

                    Let Your Geek Hangout
                    Geekzweb.com

                    1 Reply Last reply Reply Quote 0
                    • DerelictD Offline
                      Derelict LAYER 8 Netgate
                      last edited by

                      Because that is logged in the OUTBOUND direction, from the perspective of LAN (em1). So things that are OUTBOUND on LAN would have a source from somewhere other than LAN.

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • P Offline
                        pvols1979
                        last edited by

                        I had just figured that out and was coming back to close this out and I saw your post.  Yes, out is out of the pfSense box and into the LAN and in is into the pfSense box and out to the world.  It makes sense now.

                        Let Your Geek Hangout
                        Geekzweb.com

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                        Privacy Policy · Cookie Policy