<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Endless spam .... how to get rid of it? Is it a rule change? Is it 2.7?]]></title><description><![CDATA[<p dir="auto">Today I noticed an endless number of spam related warnings in my firewall log. See picture.</p>
<p dir="auto">I am not really surprised that it is there, but of cause I would like to block it and I do not want to see it in the log.</p>
<p dir="auto">But what is causing that its in the logs now and in such enormous quantities !?</p>
<ul>
<li>did I unintentionally made a change, which causes the FW to generate these messages?</li>
<li>is the related to the latest builds?</li>
<li>is there a change in network or browser behavoir??</li>
<li>is it related to the installed HA-proxy?</li>
</ul>
<p dir="auto">I simply do not know!</p>
<p dir="auto">If some one has suggestions!</p>
<p dir="auto"><img src="/assets/uploads/files/1681973155447-1f723841-e192-488a-8007-13125526d943-image.png" alt="1f723841-e192-488a-8007-13125526d943-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/179584/endless-spam-how-to-get-rid-of-it-is-it-a-rule-change-is-it-2-7</link><generator>RSS for Node</generator><lastBuildDate>Sun, 12 Apr 2026 06:43:20 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/179584.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 20 Apr 2023 06:46:09 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Endless spam .... how to get rid of it? Is it a rule change? Is it 2.7? on Thu, 20 Apr 2023 12:24:43 GMT]]></title><description><![CDATA[<p dir="auto">Those look more like out-of-state packets not random probing. Still normal and expected:</p>
<p dir="auto"><a href="https://docs.netgate.com/pfsense/en/latest/troubleshooting/log-filter-blocked.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.netgate.com/pfsense/en/latest/troubleshooting/log-filter-blocked.html</a></p>
<p dir="auto">Something may be causing more states to be dropped from your table faster than expected, but AFAIK there haven't been any changes in the code that would do that, so it may be something in your config or situational. But really those are normal, servers just keep sending packets to old connections in hopes that they're still open because it can be faster than setting up new ones.</p>
]]></description><link>https://forum.netgate.com/post/1100431</link><guid isPermaLink="true">https://forum.netgate.com/post/1100431</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Thu, 20 Apr 2023 12:24:43 GMT</pubDate></item><item><title><![CDATA[Reply to Endless spam .... how to get rid of it? Is it a rule change? Is it 2.7? on Thu, 20 Apr 2023 11:20:50 GMT]]></title><description><![CDATA[<p dir="auto">Covering your eyes - Won't make the Tiger disappear</p>
]]></description><link>https://forum.netgate.com/post/1100424</link><guid isPermaLink="true">https://forum.netgate.com/post/1100424</guid><dc:creator><![CDATA[bingo600]]></dc:creator><pubDate>Thu, 20 Apr 2023 11:20:50 GMT</pubDate></item><item><title><![CDATA[Reply to Endless spam .... how to get rid of it? Is it a rule change? Is it 2.7? on Thu, 20 Apr 2023 10:16:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>gertjan</bdi></a></p>
<p dir="auto">I changed this setting to off</p>
<p dir="auto"><img src="/assets/uploads/files/1681984988887-0dd60960-0c4d-4de4-9140-267c0823bb88-image.png" alt="0dd60960-0c4d-4de4-9140-267c0823bb88-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">I wonder if I already did that in the past and that one of the very recent snapshot updates it ^turned on^ again. Or that I did that by accident.<br />
I can hardly imagine, however I did access the page a couple of times to clear the logging (I made significant changes to the FW, because I am changing my internal network and added HA-proxy.</p>
]]></description><link>https://forum.netgate.com/post/1100420</link><guid isPermaLink="true">https://forum.netgate.com/post/1100420</guid><dc:creator><![CDATA[louis2]]></dc:creator><pubDate>Thu, 20 Apr 2023 10:16:42 GMT</pubDate></item><item><title><![CDATA[Reply to Endless spam .... how to get rid of it? Is it a rule change? Is it 2.7? on Thu, 20 Apr 2023 12:34:56 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/louis2">@<bdi>louis2</bdi></a></p>
<p dir="auto">About the "default deny rule IPv4 1000000103" :<br />
Uncheck :</p>
<p dir="auto"><img src="/assets/uploads/files/1681994081449-edcaaf42-e10f-478d-96d7-72d8280becc1-image.png" alt="edcaaf42-e10f-478d-96d7-72d8280becc1-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">edit : I corrected the image.</p>
<p dir="auto">and done ^^</p>
<p dir="auto">Keep in mind : the traffic is still there, on the WAN port.<br />
This is 'normal' as you are connected to a public network (aka : the Internet) that is accessible to many people. We don't have leave our beds to try to access your IP, or my IP, or everybody's IP.</p>
<p dir="auto">To stop it : one solution : rip out the WAN cable.<br />
( or find an ISP that filters for you ... )</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/louis2">@<bdi>louis2</bdi></a> said in <a href="/post/1100414">Endless spam .... how to get rid of it? Is it a rule change? Is it 2.7?</a>:</p>
<blockquote>
<p dir="auto">I try to block and filter as much as possible</p>
</blockquote>
<p dir="auto">By default, the WAN firewall page is empty.<br />
This means that there is actually one rule : the hidden default rule "1000000103".<br />
And that one does just one thing : block all incoming connection - no exception.<br />
And by default, it isn't logging.<br />
So, by default, nothing to 'try' <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f60a.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji--blush" style="height:23px;width:auto;vertical-align:middle" title=":blush:" alt="😊" /></p>
]]></description><link>https://forum.netgate.com/post/1100417</link><guid isPermaLink="true">https://forum.netgate.com/post/1100417</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Thu, 20 Apr 2023 12:34:56 GMT</pubDate></item><item><title><![CDATA[Reply to Endless spam .... how to get rid of it? Is it a rule change? Is it 2.7? on Thu, 20 Apr 2023 08:45:31 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/louis2">@<bdi>louis2</bdi></a><br />
Those messages are unfortunately : the "normal" consequence of having a device connected directly to the internet. There is absolutely nothing wrong with your setup, wrt. logging these.</p>
<p dir="auto">The good news is that  pfSense is made to handle precisely that situation (and many other).</p>
<p dir="auto">Don't worry , and as long as it's incoming traffic from the WAN (Internet), don't worry about the "Flags" you mentioned in the first post. You can't control what flags a packet from the internet has set (the bad guy can ... and will)</p>
<p dir="auto">Relax , and be happy about how much garbage pfSense is filtering out (&amp; logging), and thereby protecting your devices.</p>
<p dir="auto">Edit:<br />
If you previously have had an ISP device (L3 router) in front of your pfSense, and now have the pfSense connected "directly to the internet", an ISP L2 connection.<br />
That could explain the "noise" you see. <strong>It has always been there</strong> , but an ISP L3 router filter it out, before it would reach pfSense.</p>
<p dir="auto">You would often get a L2 connection if you have switched to a fiber based connection.</p>
<p dir="auto">I'll stop here, there is IMHO not much more to say on this subject.</p>
<p dir="auto">/Bingo</p>
]]></description><link>https://forum.netgate.com/post/1100416</link><guid isPermaLink="true">https://forum.netgate.com/post/1100416</guid><dc:creator><![CDATA[bingo600]]></dc:creator><pubDate>Thu, 20 Apr 2023 08:45:31 GMT</pubDate></item><item><title><![CDATA[Reply to Endless spam .... how to get rid of it? Is it a rule change? Is it 2.7? on Thu, 20 Apr 2023 07:27:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bingo600">@<bdi>bingo600</bdi></a></p>
<p dir="auto">No it is not hacking, it is mainly related to data collection and marketing.</p>
<p dir="auto">I try to block and filter as much as possible. I have not seem  this behavoir, which I do not understand at the moment, for a long time.</p>
<p dir="auto">It are really hundreds of messages flooding my log. Each example shown in the picture does not occur one's, but many times!</p>
]]></description><link>https://forum.netgate.com/post/1100414</link><guid isPermaLink="true">https://forum.netgate.com/post/1100414</guid><dc:creator><![CDATA[louis2]]></dc:creator><pubDate>Thu, 20 Apr 2023 07:27:17 GMT</pubDate></item><item><title><![CDATA[Reply to Endless spam .... how to get rid of it? Is it a rule change? Is it 2.7? on Thu, 20 Apr 2023 07:10:03 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/louis2">@<bdi>louis2</bdi></a><br />
You didn't block anything</p>
<p dir="auto">All the log listed messages was "made" by the <strong>Default deny rule IPv4</strong>.<br />
That rule is a built-in "hidden/invisible"  <strong>deny/block any any</strong> , at the bottom of every interface ruleset.</p>
<p dir="auto">This is "just" the standard "background noise / hacker probes" , coming  from being connected to the internet.</p>
<p dir="auto">I'm surprised you haven't noticed that "noise" before ....<br />
It would always have been there, on a "standard install"</p>
<p dir="auto">AKA ... If it's not handled by one of your rules on the interface, it will be caught by the "default deny rule"</p>
<p dir="auto">/Bingo</p>
]]></description><link>https://forum.netgate.com/post/1100412</link><guid isPermaLink="true">https://forum.netgate.com/post/1100412</guid><dc:creator><![CDATA[bingo600]]></dc:creator><pubDate>Thu, 20 Apr 2023 07:10:03 GMT</pubDate></item></channel></rss>