Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Unknown block “to any no-df max-mss 1400 fragment reassemble”

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 3 Posters 239 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      deleted
      last edited by

      Hello everyone,

      I have a lot of entries in the log and I’m not sure yet how they’re generated or if this is even a problem at all:

      When I hover over the entry in the dashboard with the mouse, the following is displayed:
      rule_fw.png

      In the logs, it looks like this:
      rule_fw2.png

      Traffic from every port and every NIC is affected.
      I have turned off VPN and anything else that might be blocking it, but without success.

      Furthermore, the block description only appears in the pop-up. Not in the log.

      A search online for “scrub from <vpn_networks:*> to any no-df max-mss 1400 fragment reassemble” was unsuccessful, except for one reference to the “Disable Firewall Scrub” function in the advanced settings.

      Scrub is usually disabled. However, changing this setting does not resolve the issue.

      Does anyone know what this is?

      1 Reply Last reply Reply Quote 0
      • M Offline
        marcosm Netgate
        last edited by marcosm

        The widget doesn't do a good job matching the right rule in some situations. The one from the log page is correct.

        D 1 Reply Last reply Reply Quote 0
        • D Offline
          deleted @marcosm
          last edited by

          @marcosm

          Thanks for the info.

          But what exactly does that tell me?
          I haven't actively made any changes to the configuration, and it happens even when I don't have any block systems active.

          Except for the FW itself, of course.

          tinfoilmattT 1 Reply Last reply Reply Quote 0
          • tinfoilmattT Offline
            tinfoilmatt LAYER 8 @deleted
            last edited by

            Need to see block details.

            1 Reply Last reply Reply Quote 0
            • D Offline
              deleted
              last edited by

              Sorry for the delay.

              An update to Sense “fixed” the problem—but I suspect the issue was caused by the client rather than Sense.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.