Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Endless spam .... how to get rid of it? Is it a rule change? Is it 2.7?

    Scheduled Pinned Locked Moved CE 2.7.0 Development Snapshots (Retired)
    8 Posts 4 Posters 647 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      louis2
      last edited by

      Today I noticed an endless number of spam related warnings in my firewall log. See picture.

      I am not really surprised that it is there, but of cause I would like to block it and I do not want to see it in the log.

      But what is causing that its in the logs now and in such enormous quantities !?

      • did I unintentionally made a change, which causes the FW to generate these messages?
      • is the related to the latest builds?
      • is there a change in network or browser behavoir??
      • is it related to the installed HA-proxy?

      I simply do not know!

      If some one has suggestions!

      1f723841-e192-488a-8007-13125526d943-image.png

      bingo600B 1 Reply Last reply Reply Quote 0
      • bingo600B
        bingo600 @louis2
        last edited by bingo600

        @louis2
        You didn't block anything

        All the log listed messages was "made" by the Default deny rule IPv4.
        That rule is a built-in "hidden/invisible" deny/block any any , at the bottom of every interface ruleset.

        This is "just" the standard "background noise / hacker probes" , coming from being connected to the internet.

        I'm surprised you haven't noticed that "noise" before ....
        It would always have been there, on a "standard install"

        AKA ... If it's not handled by one of your rules on the interface, it will be caught by the "default deny rule"

        /Bingo

        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

        pfSense+ 23.05.1 (ZFS)

        QOTOM-Q355G4 Quad Lan.
        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

        L 1 Reply Last reply Reply Quote 0
        • L
          louis2 @bingo600
          last edited by

          @bingo600

          No it is not hacking, it is mainly related to data collection and marketing.

          I try to block and filter as much as possible. I have not seem this behavoir, which I do not understand at the moment, for a long time.

          It are really hundreds of messages flooding my log. Each example shown in the picture does not occur one's, but many times!

          bingo600B GertjanG 2 Replies Last reply Reply Quote 0
          • bingo600B
            bingo600 @louis2
            last edited by bingo600

            @louis2
            Those messages are unfortunately : the "normal" consequence of having a device connected directly to the internet. There is absolutely nothing wrong with your setup, wrt. logging these.

            The good news is that pfSense is made to handle precisely that situation (and many other).

            Don't worry , and as long as it's incoming traffic from the WAN (Internet), don't worry about the "Flags" you mentioned in the first post. You can't control what flags a packet from the internet has set (the bad guy can ... and will)

            Relax , and be happy about how much garbage pfSense is filtering out (& logging), and thereby protecting your devices.

            Edit:
            If you previously have had an ISP device (L3 router) in front of your pfSense, and now have the pfSense connected "directly to the internet", an ISP L2 connection.
            That could explain the "noise" you see. It has always been there , but an ISP L3 router filter it out, before it would reach pfSense.

            You would often get a L2 connection if you have switched to a fiber based connection.

            I'll stop here, there is IMHO not much more to say on this subject.

            /Bingo

            If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

            pfSense+ 23.05.1 (ZFS)

            QOTOM-Q355G4 Quad Lan.
            CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
            LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

            1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @louis2
              last edited by Gertjan

              @louis2

              About the "default deny rule IPv4 1000000103" :
              Uncheck :

              edcaaf42-e10f-478d-96d7-72d8280becc1-image.png

              edit : I corrected the image.

              and done ^^

              Keep in mind : the traffic is still there, on the WAN port.
              This is 'normal' as you are connected to a public network (aka : the Internet) that is accessible to many people. We don't have leave our beds to try to access your IP, or my IP, or everybody's IP.

              To stop it : one solution : rip out the WAN cable.
              ( or find an ISP that filters for you ... )

              @louis2 said in Endless spam .... how to get rid of it? Is it a rule change? Is it 2.7?:

              I try to block and filter as much as possible

              By default, the WAN firewall page is empty.
              This means that there is actually one rule : the hidden default rule "1000000103".
              And that one does just one thing : block all incoming connection - no exception.
              And by default, it isn't logging.
              So, by default, nothing to 'try' 😊

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              L 1 Reply Last reply Reply Quote 0
              • L
                louis2 @Gertjan
                last edited by

                @gertjan

                I changed this setting to off

                0dd60960-0c4d-4de4-9140-267c0823bb88-image.png

                I wonder if I already did that in the past and that one of the very recent snapshot updates it ^turned on^ again. Or that I did that by accident.
                I can hardly imagine, however I did access the page a couple of times to clear the logging (I made significant changes to the FW, because I am changing my internal network and added HA-proxy.

                1 Reply Last reply Reply Quote 0
                • bingo600B
                  bingo600
                  last edited by

                  Covering your eyes - Won't make the Tiger disappear

                  If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                  pfSense+ 23.05.1 (ZFS)

                  QOTOM-Q355G4 Quad Lan.
                  CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                  LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    Those look more like out-of-state packets not random probing. Still normal and expected:

                    https://docs.netgate.com/pfsense/en/latest/troubleshooting/log-filter-blocked.html

                    Something may be causing more states to be dropped from your table faster than expected, but AFAIK there haven't been any changes in the code that would do that, so it may be something in your config or situational. But really those are normal, servers just keep sending packets to old connections in hopes that they're still open because it can be faster than setting up new ones.

                    Remember: Upvote with the šŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.