<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cleaning TCP: FA FPA RA logs. How to remove them from the logs?]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">This is a recurring post but after trying several solutions (conservative + reboot, create a pass rule to not log), I am not able to get rid of these flood. I know it doesn't hurt the traffic and the FW but it's just annoying.</p>
<p dir="auto">I created an explicitly rule to filter out those logs but it doesn't match for certain reason. Are they advanced options to check so I can filter out these packets?</p>
<p dir="auto">Merci<br />
Xavier</p>
<p dir="auto">https://doc.pfsense.org/index.php/Why_do_my_logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/FWlogs.jpg" alt="FWlogs.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/FWlogs.jpg_thumb" alt="FWlogs.jpg_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/tcpdump.jpg" alt="tcpdump.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/tcpdump.jpg_thumb" alt="tcpdump.jpg_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/FWrule.jpg" alt="FWrule.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/FWrule.jpg_thumb" alt="FWrule.jpg_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/FWalias.jpg" alt="FWalias.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/FWalias.jpg_thumb" alt="FWalias.jpg_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/124289/cleaning-tcp-fa-fpa-ra-logs-how-to-remove-them-from-the-logs</link><generator>RSS for Node</generator><lastBuildDate>Wed, 09 Sep 2026 00:21:17 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/124289.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 11 Dec 2017 15:43:53 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Cleaning TCP: FA FPA RA logs. How to remove them from the logs? on Sat, 16 Dec 2017 20:04:18 GMT]]></title><description><![CDATA[<p dir="auto">Sorry yes I should have specified:</p>
<ul>
<li>
<p dir="auto">The first letter is the VLAN tag: Untagged or Tagged</p>
</li>
<li>
<p dir="auto">The second letter is the network: Cam, Lan or Wan</p>
</li>
</ul>
<p dir="auto">Thanks for asking <a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a></p>
<p dir="auto">Therefore can I assume that my 'default rule' is OK for logging the Syn packets only?</p>
]]></description><link>https://forum.netgate.com/post/741475</link><guid isPermaLink="true">https://forum.netgate.com/post/741475</guid><dc:creator><![CDATA[XabiX]]></dc:creator><pubDate>Sat, 16 Dec 2017 20:04:18 GMT</pubDate></item><item><title><![CDATA[Reply to Cleaning TCP: FA FPA RA logs. How to remove them from the logs? on Sat, 16 Dec 2017 17:12:35 GMT]]></title><description><![CDATA[<p dir="auto">What is UW?  TL TC UL stand for?</p>
]]></description><link>https://forum.netgate.com/post/741463</link><guid isPermaLink="true">https://forum.netgate.com/post/741463</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sat, 16 Dec 2017 17:12:35 GMT</pubDate></item><item><title><![CDATA[Reply to Cleaning TCP: FA FPA RA logs. How to remove them from the logs? on Fri, 15 Dec 2017 17:25:04 GMT]]></title><description><![CDATA[<p dir="auto">Thank you all. I have added the attached rule and since then it's very quiet which I like :)</p>
<p dir="auto">Can you confirm that this the correct way to set the rule? (I have applied it in every interface).</p>
<p dir="auto">FYI I don't think I have any asymmetric routing because of how my network is setup. I have added a picture for transparency.</p>
<p dir="auto">Merci and have a nice WE! Santa Claus is coming :)</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/black1.jpg" alt="black1.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/black1.jpg_thumb" alt="black1.jpg_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/black2.jpg" alt="black2.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/black2.jpg_thumb" alt="black2.jpg_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/black3.jpg" alt="black3.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/black3.jpg_thumb" alt="black3.jpg_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/network.jpg" alt="network.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/network.jpg_thumb" alt="network.jpg_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/741343</link><guid isPermaLink="true">https://forum.netgate.com/post/741343</guid><dc:creator><![CDATA[XabiX]]></dc:creator><pubDate>Fri, 15 Dec 2017 17:25:04 GMT</pubDate></item><item><title><![CDATA[Reply to Cleaning TCP: FA FPA RA logs. How to remove them from the logs? on Wed, 13 Dec 2017 13:01:28 GMT]]></title><description><![CDATA[<p dir="auto">If you are seeing a huge amount of out of state traffic - this would either point to an asymmetrical routing issue, or borked client.. I have seen android phones generate quite a bit of out of state.. But it wasn't constant.. Would be sporadic at best.. not constant flood of noise.</p>
<p dir="auto">Seeing the out of state traffic can help you fix problems in your network.. I would suggest only turning off the default log rule if the out of state traffic is caused by some bad client and can not be fixed and the amount of noise is keeping you from seeing more interesting traffic your interested in.</p>
<p dir="auto">kpa is correct many firewalls do not log out of state traffic out of the box.. Shoot the usg 3p that I have had some recent experience with doesn't even have a simple way to view any firewall logs ;)  Be it a syn block or out of state block.. They just do not show you any thing blocked by the firewall unless you specifically go looking for it, or take the time to send it to a syslog so you can view it..</p>
<p dir="auto">But yes viewing everything can be sometimes overwhelming to new users watching the log.  Especially on the wan side - there is a shit ton of UDP noise that pretty much just noise if you ask me, which is why I only log tcp syn traffic.. Just interesting to see what ports are being attempted.. ssh, 1433, telnet, 3389 (rdp) and ftp are very very common bots and scripts looking for open shit they can try and access.</p>
]]></description><link>https://forum.netgate.com/post/740888</link><guid isPermaLink="true">https://forum.netgate.com/post/740888</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Wed, 13 Dec 2017 13:01:28 GMT</pubDate></item><item><title><![CDATA[Reply to Cleaning TCP: FA FPA RA logs. How to remove them from the logs? on Wed, 13 Dec 2017 11:44:47 GMT]]></title><description><![CDATA[<p dir="auto">The default logging is only there for you to take note of the amount of noise there is among regular TCP/IP traffic and then turn it off and write your own rules for more precise logging. PfSense is slightly different compared to other firewall distributions that by default hide that noise to put the user's mind at ease.</p>
]]></description><link>https://forum.netgate.com/post/740870</link><guid isPermaLink="true">https://forum.netgate.com/post/740870</guid><dc:creator><![CDATA[kpa]]></dc:creator><pubDate>Wed, 13 Dec 2017 11:44:47 GMT</pubDate></item><item><title><![CDATA[Reply to Cleaning TCP: FA FPA RA logs. How to remove them from the logs? on Wed, 13 Dec 2017 10:33:52 GMT]]></title><description><![CDATA[<p dir="auto">Thank you both for the answers. I will therefore remove this rule and yes I had that in mind but after different readings I ended up trying :) but I agree it doesn't make sense to have rule if we are speaking about out of the state messages.</p>
<p dir="auto">I may just do what johnpoz was proposing (turn off logging and activate it only for the SYN packets)</p>
]]></description><link>https://forum.netgate.com/post/740865</link><guid isPermaLink="true">https://forum.netgate.com/post/740865</guid><dc:creator><![CDATA[XabiX]]></dc:creator><pubDate>Wed, 13 Dec 2017 10:33:52 GMT</pubDate></item><item><title><![CDATA[Reply to Cleaning TCP: FA FPA RA logs. How to remove them from the logs? on Tue, 12 Dec 2017 21:11:54 GMT]]></title><description><![CDATA[<p dir="auto">As a rule of thumb, not sure if there are any exceptions, the rules you specific in the UI only apples to newly created states. Packets that are out of state will never hit your manually created rules.</p>
]]></description><link>https://forum.netgate.com/post/740774</link><guid isPermaLink="true">https://forum.netgate.com/post/740774</guid><dc:creator><![CDATA[Harvy66]]></dc:creator><pubDate>Tue, 12 Dec 2017 21:11:54 GMT</pubDate></item><item><title><![CDATA[Reply to Cleaning TCP: FA FPA RA logs. How to remove them from the logs? on Mon, 11 Dec 2017 18:12:18 GMT]]></title><description><![CDATA[<p dir="auto">From you putting in a rule - its like you didn't read the link you posted too.. Those are out of state packets.. Your allow rule would not allow something that is out of state.</p>
<p dir="auto">If you do not want to see out of state logged then turn off default logging.  Then create a block rule at the end of your lan rules that logs but only when SYN..</p>
]]></description><link>https://forum.netgate.com/post/740561</link><guid isPermaLink="true">https://forum.netgate.com/post/740561</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 11 Dec 2017 18:12:18 GMT</pubDate></item></channel></rss>