Something to be worried about? Block private networks from WAN block 192.168/16 (12004)
-
A short while ago, I heard it was wise to stop logging the "Default deny rule IPv4 (1000000103)". After that I started seeing things like "Block private networks from WAN block 172.16/12 (12003)"
Is this something to be worried about? I don't even recognized the IP addresses such as 192.168.131.194.
-
@larryjb you might want to not post your public IP that 38.x.x.x one
You can disable logging of the rfc1918 rule as well..
They are blocked so nothing to worry about - I wouldn't be worried, I would be curious.. That you are seeing hits from cgnat ips 100.105 and multiiple different 192.168 is very odd..
What is your pfsense wan actually connected to?
-
192.169.131.194 is a private address. so not routable over the internet. So if you are not blocking it out the WAN your ISP should at there end.
For network comparison here is what I have employed for private networks.
this rule per the PFS recipes:https://docs.netgate.com/pfsense/en/latest/recipes/rfc1918-egress.html
-
@Uglybrian completely agree with you on rfc1918 not routable over public net.. You would assume those are coming from a network his wan is connected to - could be his isp.. I could be elsewhere - and no even if he wanted to answer it wouldn't work. You would think his isp would be filtering that sort of traffic before it gets to one of their clients.
Wondering if there is other stuff on pfsense wan, and just not a connection to the isp.
-
@johnpoz said in Something to be worried about? Block private networks from WAN block 192.168/16 (12004):
@larryjb you might want to not post your public IP that 38.x.x.x one
You can disable logging of the rfc1918 rule as well..
They are blocked so nothing to worry about - I wouldn't be worried, I would be curious.. That you are seeing hits from cgnat ips 100.105 and multiiple different 192.168 is very odd..
What is your pfsense wan actually connected to?
I'm not quite sure how to answer your question here, but here is my setup:
Modem > Netgate 1100 > dlink unmanaged switch > desktop, unifi AC, printers, etc etc. -
@johnpoz said in Something to be worried about? Block private networks from WAN block 192.168/16 (12004):
@larryjb you might want to not post your public IP that 38.x.x.x one
You can disable logging of the rfc1918 rule as well..
They are blocked so nothing to worry about - I wouldn't be worried, I would be curious.. That you are seeing hits from cgnat ips 100.105 and multiiple different 192.168 is very odd..
What is your pfsense wan actually connected to?
And I am unable to edit that post anymore. Can an admin delete the image and I can post a new one in a reply?
-
@johnpoz Could some one have hacked my wifi?
I don't see those ips on my DHCP leases or ARP table.
-
@larryjb no your wifi wouldn't show up on your wan.. You could sniff some of the traffic.. And look to see what the mac is.. If you see different macs - its devices connected to the same L2 as your wan. But most likely you will just your modem mac, ie your upstream gateway mac.. This means it came from somewhere on your isp network, or beyond that and they continued to send on the traffic to you.. When really they shouldn't have if source rfc1918 or bogon.. I mean your never going to be able to answer anyway.. Chalk it up to noise on the internet - but it sure is curious.. I mean if your really interested you could reach out to your isp - and say wtf am I seeing source traffic from rfc1918 or bogon.. But I doubt you get a reply from any of the 1st level - you need to talk to someone like 3rd level or up.
-
Here is a repost of the firewall logs:

-
When I first saw these logs, I thought the 192.168 address were from my private network, and I couldn't figure it out. From what you're telling me, they are address coming from outside my private network trying to access my isp.
I'm sorry, but I do find that the explanations of networking rather vague. I would gladly use a simple consumer grade setup, but I found the Internet connectivity to be flaky at best. Using Netgate 1100 with the Unifi AC seemed the best compromise. In general, it has worked far better than the consumer stuff, but when something does go wrong I'm faced with a steep learning curve. Sometimes it's like rock climbing!
So, thank you for your patience.
-
@johnpoz When you say I could look to see what the mac is, how the heck can I do that? If I type the ip address in to contact the device, I just get "This site can't be reached".
-
@larryjb if those are "outbound rules" then the traffic originates on your network somewhere - so if some device on your network.. Is that 38 IP yours? You are not talking to the forum from that address. Only IPv6 I show on your account.
I forgot to look it up when you posted it.. Can you dm me that 38.x IP and can look it up if its not yours.
So here is the thing - if your device wanted to talk to some random rfc1918 IP, or some public IP then sure pfsense would route it out your default route, ie out your wan. Your rule blocks that... I have a sim rule, because in no scenario should some unknown IP go out to my isp.

But only do it being a good netizen - zero reason to send out noise out to my isp sort of thing.. But notice not much traffic, and my pfsense has been up a really long time and only 3.5MB total - and most of that is my own generated traffic on purpose, or my work laptop when the vpn disconnects and tries to talk to work stuff that is on some rfc1918 address.
I would sniff on your lan or other lan side interfaces and look for that 38.x IP stuff is trying too talk to, you can filter your packet capture and then from that you can get the mac address of what on your network is wanting to talk to that 38.x IP.
But here is the thing don't your lan side rules limit to only their network? Ie lan subnets.. If some random IP hits pfsense, it shouldn't route that unless it comes from an IP on that network, and it sure wouldn't nat it, etc. Since it only nats networks that it actually has been configured for.
I might be confusing another thread about blocking stuff on wan.. So are these blocks outbound on your wan?
-
@johnpoz Here is a screenshot showing the top of the page so you know what screen I'm looking at in pfsense:

If that traffic is coming from my LAN, I've got something seriously wrong because I don't see any of those IPs in my ARP table or my DHCP leases.
-
All of the IP’s listed under source is the noise , expired connections, probes. of the Internet. 38.xx.xx.xx under destination is your PFS firewall. It’s doing a job of blocking/ dropping unwanted connections. If you want to see who they are just click on the (i) next to the ip.
173.248.4.73 is from Amazon, 20.166.249.171 is from Microsoft, more than likely old connections that have expired. I’m guessing FE80: is from your ISP modem, having something to do with IP options. This is normal we all have it. I don’t normally see this traffic because I have my logging for this turned off.
By the way, what’s with the 790 alerts. -
@Uglybrian Thanks, that is what I've come to realize. I was just surprised to see a few 198.68.xxx.xxx ips at the bottom of the list. I have 3 pages of Default deny rule IPv4. I then learned I could stop logging those. Then I saw the 198.68.xxx, but only a handful a day. So I started freaking thinking some one was hacking my wifi and sending stuff out.
In fact, from what you have told me, that is all stuff knocking at my door. the 198 stuff, according to an old post I dug up here is spoofing. So, I should stop logging these as well. I don't need to know who got blocked, I'd want to know who broke in.
-
@larryjb this is an outbound rule

Seems odd that you would see so much rfc1918 or cgnat inbound to your wan.. More like something on your network talking outbound and this rule blocking it.
-
@johnpoz Thanks, now I have an idea of what your earlier post was about.
I do use Proton VPN sometimes, so I wonder if this was sending stuff out sometimes.
I've created that rule. I have enough trouble getting things to work from a lot of the Netgate and other (such as WINSCP) instructions. I'm still trying to get a public key to work without success. I'll start a different thread if I'm still having trouble later.
-
@larryjb that is why I wanted that 38. address - wanted to look it up, I had assumed it was your public wan IP.. But I looked and you have only ever talked to the forums from IPv6.
Since that is an outbound rule - its something inside generating traffic to that 38.x IP. And the outbound is blocking it - but to be honest normal lan rules should only allow the lan segment so your outbound wan rule should never see anything other than your lan as source.. So I would be curious what your lan side rules are, they must be allow any other than just lan subnets.
-

Could be the root of some of your problems. -
@Uglybrian yeah that is crazy - if I have 1 I have to know what it and clear it ;)
Privacy Policy · Cookie Policy