Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Too many Block IPv4 link-local (1000000101) in log, how to find devices related on network?

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 3 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      Elrick75
      last edited by Elrick75

      Hi,

      I just take a look to firewall logs and i see a lots of error Block IPv4 link-local (1000000101), i would like to identify the root cause on my LAN.
      Is there a simple and effective way to identify device that causes this problem?

      cfbfc192-dc2e-4c85-988d-7432ac9d4ca8-image.png

      00bc75ca-db7e-457e-b7ae-7597e69fb206-image.png

      Many thanks for your help.

      luckman212L 1 Reply Last reply Reply Quote 0
      • luckman212L
        luckman212 LAYER 8 @Elrick75
        last edited by

        @elrick75 Do you have a DHCP server enabled on the VLAN_MY_LAN interface? Those source IPs are self-assigned APIPA addresses, indicating the devices have invalid IP info. You have 3 options basically:

        • turn off logging of those private IPs in System Logs > Settings
        • add a specific rule to block & not log them
        • fix the devices so they have properly assigned IPs...
        E 1 Reply Last reply Reply Quote 0
        • E
          Elrick75 @luckman212
          last edited by

          @luckman212 said in Too many Block IPv4 link-local (1000000101) in log, how to find devices related on network?:

          ces so they have properly assigned IP

          Hi,

          Making logs disabled could not be useful for me because I won't see verbose devices that cause problems afterwards.
          I think that it was more interessting to identify and fix this "shitty" device :)
          How can i do that please?

          luckman212L johnpozJ 2 Replies Last reply Reply Quote 0
          • luckman212L
            luckman212 LAYER 8 @Elrick75
            last edited by

            @elrick75 See if you can find the MAC addresses of the device(s) in Diagnostics > ARP. If not, try pinging one of those 169.xx IPs and then check ARP again. Once you have the MAC, you can look on the device itself (sticker) or look it up in an online database such as https://www.wireshark.org/tools/oui-lookup.html to help identify...

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @Elrick75
              last edited by

              @elrick75 you most likely want to just sniff for those IP(s) so you can find the mac - then from that you can figure out what device is doing it - then correct the device so its not using 169.254 addresses.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              E 1 Reply Last reply Reply Quote 0
              • E
                Elrick75 @johnpoz
                last edited by

                @johnpoz How can i sniff devices from the subnet in cause?
                Topology is currently three LAN with Cisco switch.
                VLAN is applied on Cisco port switch.

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @Elrick75
                  last edited by johnpoz

                  @elrick75 do a packet capture on the interface your logging the trafffic - whatever that vlan_my_lan is..

                  Packet capture is under the diagnostic menu..

                  From the mac, you can look on your switch to what port the device is connected to, or if from a wireless network that is a bit harder. But the first 3 octets of the mac you can look up the maker of the device and that should give you some clue to what it is..

                  If I had to guess, its plex GDM discovery

                  https://support.plex.tv/articles/201543147-what-network-ports-do-i-need-to-allow-through-my-firewall/
                  UDP: 32410, 32412, 32413, 32414 (current GDM network discovery)

                  So maybe a firestick or something trying to discover your plex server? Or a plex server..

                  But seems like you have multiple devices doing it because your source 169.254.x.x are different IPs..

                  From the packet capture - what are the mac of the devices sending out that directed broadcast to 169.254.255.255.. You can look up the maker here

                  https://www.macvendorlookup.com/

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  E 1 Reply Last reply Reply Quote 0
                  • E
                    Elrick75 @johnpoz
                    last edited by

                    @johnpoz You were right, the problem came from the Plex application, I updated the package in question, this error is no longer present.
                    Thanks a lot for your help.
                    By the way, I learned how to use Capture, which could be useful for later.

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @Elrick75
                      last edited by

                      @elrick75 said in Too many Block IPv4 link-local (1000000101) in log, how to find devices related on network?:

                      I learned how to use Capture, which could be useful for later.

                      Very useful to say the least ;)

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.