Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    After upgrading to 25.07 (6100) Strange empty firewall rules blocking UDP / no port

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 2 Posters 82 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      conover
      last edited by

      Hi,

      after upgrading my 6100 boxes to 25.07 i get strange log entries in the firewall log

      Bildschirmfoto 2025-08-11 um 10.24.53.png

      The IPs are the public IPs of the WAN Interfaces (91.x.x.x of Box 1 and 109.x.x.x of Box 2).
      They have an established IPsec tunnel using the IP addresses above.

      I have the same with the public IPs on pfSense Box 1 with an IPsec tunnel to a non pfSense 3rd device.

      Bildschirmfoto 2025-08-11 um 10.43.43.png

      Did I miss something in the release notes explaining this new behaviour?
      Especially why there is nog rule# and no UDP-port?

      Bob.DigB 1 Reply Last reply Reply Quote 0
      • Bob.DigB Offline
        Bob.Dig LAYER 8 @conover
        last edited by

        @conover Also saw that and it seems related to IPsec indeed.

        C 1 Reply Last reply Reply Quote 0
        • C Offline
          conover @Bob.Dig
          last edited by

          @Bob.Dig said in After upgrading to 25.07 (6100) Strange empty firewall rules blocking UDP / no port:

          @conover Also saw that and it seems related to IPsec indeed.

          Thanks for the confirmation.

          Dose anybody know how to disable the logging of those? I have hundreds of them a day in my log files....

          Bob.DigB 1 Reply Last reply Reply Quote 0
          • Bob.DigB Offline
            Bob.Dig LAYER 8 @conover
            last edited by

            @conover Probably the same way you do it for "the new" IGMP logs, you create a block rule if this should be blocked, it is blocked right now, and make it no-log.

            C 1 Reply Last reply Reply Quote 0
            • C Offline
              conover @Bob.Dig
              last edited by

              @Bob.Dig said in After upgrading to 25.07 (6100) Strange empty firewall rules blocking UDP / no port:

              @conover Probably the same way you do it for "the new" IGMP logs, you create a block rule if this should be blocked, it is blocked right now, and make it no-log.

              Good point - thanks (wasnt aware of the new "IGMP rules").
              But the log for the blocked rules do not say for which UDP port(s) the blocking is.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.