Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSec connection attempt isn't blocked.

    Scheduled Pinned Locked Moved IPsec
    3 Posts 2 Posters 658 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z Offline
      zMaliz
      last edited by

      Hi.

      Each evening I see an entry for 216.218.206.118 in my IPSEC  logs.
      It never gets connected but it shows up each night.

      So I decided to add some rules to try and block it.

      On WAN I added
      BLOCK TCP v4 * from 216.218.206.118

      On IPSEC I added
      BLOCK TCP v4 * from 216.218.206.118

      Yet I still see it trying to connect. Is there anyway I can block it ?

      Thanks.

      1 Reply Last reply Reply Quote 0
      • Z Offline
        zMaliz
        last edited by

        Quick update. My original post was wrong.

        The rules are :

        On WAN I added
        BLOCK IPv4 any from 216.218.206.118

        On IPSEC I added
        BLOCK IPv4 any from 216.218.206.118

        Why doesn't this stop the connections ?

        1 Reply Last reply Reply Quote 0
        • P Offline
          P3R
          last edited by

          @zMaliz:

          Why doesn't this stop the connections ?

          Because when configuring a VPN, hidden firewall rules are automatically added to allow the corresponding traffic in. I would assume that you allow mobile clients in as then the source address of the above mentioned hidden rules is set to any.

          You could disable these VPN rules from being automatically created (System, Advanced, Firewall and NAT, Disable Auto-added VPN rules) but then you'd have to manually add your own rules on the WAN interface to allow the legitimate IPsec traffic.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.