Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    States to undefined net address??

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 3 Posters 495 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      furom
      last edited by furom

      Hi,

      I found more peculiar things I certainly think is odd.

      I have two Synology NAS's I use as NFS storage. These work fine, but in the log I find blocks of ports 137 & 138 originating from them trying to reach an address outside defined scope! Network is a /28 net (14 addresses) and the odd thing is the NAS's somehow have created icmp states to the 15th (non-existent) address in that network...

      In Diagnostics/States I have two identical entries, one for each NAS I suppose
      states.png

      I have checked and rechecked the NAS's (.10 & .11) for the .15 address, but it is not defined anywhere. That is strange, but more so, why does pfSense create states for an address that cannot exist using a /28 netmask?

      R 1 Reply Last reply Reply Quote 0
      • R
        rcoleman-netgate Netgate @furom
        last edited by

        @furom What's in the ARP table for that? Diagnostics->ARP

        Ryan
        Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
        Requesting firmware for your Netgate device? https://go.netgate.com
        Switching: Mikrotik, Netgear, Extreme
        Wireless: Aruba, Ubiquiti

        F 1 Reply Last reply Reply Quote 0
        • F
          furom @rcoleman-netgate
          last edited by

          @rcoleman-netgate said in States to undefined net address??:

          @furom What's in the ARP table for that? Diagnostics->ARP

          Well, the .15 address is not in the ARP table

          R johnpozJ 2 Replies Last reply Reply Quote 0
          • R
            rcoleman-netgate Netgate @furom
            last edited by

            @furom I don't see the point in redacting anything that is internal to your network and doesn't show any external IP addresses -- it's just wasted energy

            I would do an nmap scan of your network and see if there's something sitting on that IP but not responding to requests. You can do a packet capture JUST on that IP address if you prefer. Leave the capture open with a 0 packet limit and let it run an extended period of time. Delete the state, see if it comes back, if it does stop the pcap and look at it.

            Ryan
            Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
            Requesting firmware for your Netgate device? https://go.netgate.com
            Switching: Mikrotik, Netgear, Extreme
            Wireless: Aruba, Ubiquiti

            F 1 Reply Last reply Reply Quote 1
            • F
              furom @rcoleman-netgate
              last edited by

              @rcoleman-netgate said in States to undefined net address??:

              @furom I don't see the point in redacting anything that is internal to your network and doesn't show any external IP addresses -- it's just wasted energy

              I would do an nmap scan of your network and see if there's something sitting on that IP but not responding to requests. You can do a packet capture JUST on that IP address if you prefer. Leave the capture open with a 0 packet limit and let it run an extended period of time. Delete the state, see if it comes back, if it does stop the pcap and look at it.

              Well, I will try the nmap first and if that does not yield anything, the pcap. I don't really like that stuff try to address something that aren't even defined. Thanks for the suggestions

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @furom
                last edited by johnpoz

                @furom said in States to undefined net address??:

                Well, the .15 address is not in the ARP table

                That doesn't stop the creation of a state - state would only be created to something that is routed so if this .1 box is sending traffic to pfsense.. And pfsense rules would allow creation of the state, even if there is nothing actually there..

                You need to figure out why whatever that .1 box is sending traffic to .15

                And with @rcoleman-netgate if those are rfc1918 addresses - why would you hide them?

                as to state thing - for example -- I am pinging a address on one of my other vlans.. And there is nothing on that IP address.

                ping.jpg

                Notice there still a state.. So figure out why that .1 is sending icmp traffic to .15 clearly it is sending traffic, or there would be no state in pfsense. Is pfsense the .1? Maybe you had setup some sort of monitoring to that IP, like for example a HAproxy setup it will create traffic to whatever IP you put in there, even if no longer there..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                F 1 Reply Last reply Reply Quote 1
                • F
                  furom @johnpoz
                  last edited by

                  @johnpoz Hi and sorry for late answer. The icmp was sent to that net's broadcast address. Why is still unknown, I suppose that is a question for my NAS vendor... I have made a habit of masking most addresses, agree rfc1918 is not really necessary

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.