<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[How to prevent frequent (repeating) firewall-rule related loggings!?]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">Due to an iSCSI software issue on my NAS I get many many messages like this in my log:</p>
<pre><code>May 13 15:43:21 	PC_PLUS_10G 	What did I block !!?? (1646915641) 	192.168.11.34:1532		192.168.18.20:3260		TCP:S 
</code></pre>
<p dir="auto">"What did I block" is the end rule in many of my interface related rulesets.</p>
<p dir="auto">What ever. I want to get rid of these messages of even better see them lets say one per 5 minutes or so.</p>
<p dir="auto">Since "one per 5 minutes" seems to be impossible I tried to get rid of the messages by simply define a rule just before the end rule like this</p>
<p dir="auto"><img src="/assets/uploads/files/1652453977070-whatditiblock.jpg" alt="whatditiblock.JPG" class=" img-fluid img-markdown" /></p>
<p dir="auto">That seems to work, but in this case I would prefer to filter on status TCP:S as well.</p>
<p dir="auto">Is that possible?<br />
Is there a better way to solve this problem?![whatditiblock.JPG](/assets</p>
]]></description><link>https://forum.netgate.com/topic/172162/how-to-prevent-frequent-repeating-firewall-rule-related-loggings</link><generator>RSS for Node</generator><lastBuildDate>Sat, 18 Jul 2026 21:09:38 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/172162.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 13 May 2022 14:58:39 GMT</pubDate><ttl>60</ttl></channel></rss>