25.07: protocol "options" in default block all rule
-
I upgraded my 1100 from 24.11 to 25.07 yesterday. Since then I have seen a ton of blocks on my OPT (wireless) interface of IPv6 traffic, see attached screenshot, with protocol "options"
This seems to be ICMP broadcast traffic -- I cannot find the addresses ending in 4497 and 69fa in the NDP table or anywhere else so I don't know the source.
I went into the advanced area of the rule and turned on "allow packets with IP options to pass". That did not quell the block msgs. Plus I don't want ICMP traffic to be tracking my devices anyway. I tried both "block" and "reject", no difference. The rule looks like:
What is going on here?
-
-
@beerguzzle ff02::16 is not icmp it is multicast "All MLDv2-capable routers"
If you want to create a rule to allow that doesn't log that you would need to set options in the rule, and then set it not to log.
what is the order of rules on your opt interface? outbound is only available in the floating tab.
-
https://redmine.pfsense.org/issues/16194
Hover your mouse over the action icon and look at the details it shows you there.
-
This rule is the last (bottom) rule for my OPT interface, a default "block anything not allowed above" rule. I have a similar rule for LAN, that also fires this "options" blurb too in 25.07. Hovering over the action shows:
which looks similar to (but not identical) to redmine 16194.
I went into advanced options for the rule and turned on "Allow IP options", but nothing changed after the rules reloaded.
I also searched the pfsense docs for MLD, not much came up. In head scratch mode. Is this a redmine 16194 style "feature"?
-
If you can find the line that corresponds to those log messages in
/var/log/filter.log
, copy/paste it here. It may be a similar packet to the redmine issue but maybe not identical.Since I was able to reproduce the one I was seeing I got a packet capture of it to see what it was, but depending on what you are seeing that may not be viable.
-
Here it is:
Aug 5 13:49:59 cleo filterlog[66564]: 247,,,1649447902,mvneta0.4092,match,block,in,6,0x00,0x00000,1,Options,0,56,fe80::417:952d:77be:4497,ff02::16,HBH,PADN,RTALERT,0x0000,
which should match with this from the gui: