Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WAN traffic passed on ports that are not open

    Scheduled Pinned Locked Moved Firewalling
    2 Posts 2 Posters 265 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      Drusher
      last edited by Drusher

      I periodically check my firewall rules and noticed something concerning today. Over the span of 19 seconds I have 18 entries in my Firewall Log for Passed traffic on the WAN interface. The only 2 ports I have open on my WAN interface are OpenVPN and 8082 for Let's Encrypt validation and these ports aren't in the list of ports where traffic was passed. I'm not sure what Rule @4294967295 is referring to. I searched for the IP address in the screenshot below and it's showing up in multiple blacklists so this is bothering me even more. I have the "Log firewall default blocks" disabled so I'm used to my firewall logs being fairly empty so when, at a glance, I saw entries in it I was curious and then when I saw it was Passed traffic I was in a bit of a panic. I checked the States table and filtered by the IP in the screenshot below and there were no results, but it was a few hours after the logged timestamp that I found all this.

      I have pfBlockerNG running with GeoIP blocking the Top 20 and the basic DNSBL configurations.

      [Edit] I've also done external NMAP scans of the ports listed here and they show as closed. I'm also running version 2.4.4-RELEASE-p3

      Anyone have any ideas or if I should post this on another topic board?

      Firewall_Log_20191017_103.240.140.10.png

      1 Reply Last reply Reply Quote 0
      • kiokomanK Offline
        kiokoman LAYER 8
        last edited by

        @Drusher said in WAN traffic passed on ports that are not open:

        @4294967295

        same as
        https://forum.netgate.com/topic/147248/had-my-pfsense-been-compromised/31

        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
        Please do not use chat/PM to ask for help
        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.