Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall Log shows unfamiliar internal IP

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 3 Posters 552 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      Overbay11
      last edited by

      I was reviewing my firewall log activity and the firewall blocks many attempts internally and the source IP is something unfamiliar (appears to be an IPV6 type) not within my network and it is trying to go to a destination like ff02::3 port 5355 many times. I understand this destination is something usually for multicast.

      Is there something on one of my connected devices internally that is trying to do this and maybe spoofing its source IP ?

      Thanks in advance for any help.

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @Overbay11
        last edited by

        @Overbay11

        Use Packet Capture to see what the MAC address is. You can then compare that to your hardware. You can also check your DHCP Leases to see if there's an IPv4 address assigned.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • O
          Overbay11
          last edited by

          I checked the leases and nothing for the IPv4 address assigned. Is there something I need to install for packet capture ? Thanks.

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            Diagnostics - Packet Capture

            1 Reply Last reply Reply Quote 0
            • O
              Overbay11
              last edited by

              Got it. I did the packet capture and the MAC is a phone that should be on the network. Odd that it would use an IV6 as its source if I don't use that. And some app with the multi cast must be constantly pinging.

              JKnottJ 1 Reply Last reply Reply Quote 0
              • JKnottJ
                JKnott @Overbay11
                last edited by

                @Overbay11 said in Firewall Log shows unfamiliar internal IP:

                Odd that it would use an IV6 as its source if I don't use that.

                Does it use a link local address (starts with fe80)? Every IPv6 capable device has one of those.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                O 1 Reply Last reply Reply Quote 0
                • O
                  Overbay11 @JKnott
                  last edited by

                  @JKnott Correct, it starts with fe80.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.