<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Add Firewall Rule Before Block Private Network]]></title><description><![CDATA[<p dir="auto">Is it possible, or do I have to disable the "built in" rule, and create my own.</p>
<p dir="auto">I have an issue, where the firewall logs contain nothing, but this, every few minutes:</p>
<pre><code>Act  	Time  	If  	Source  	Destination  	Proto
	Dec 23 13:00:03 	WAN 	10.252.48.1:67 	255.255.255.255:68 	UDP
	Dec 23 13:00:02 	WAN 	10.252.48.1:67 	255.255.255.255:68 	UDP
	Dec 23 12:59:58 	WAN 	10.252.48.1:67 	255.255.255.255:68 	UDP
	Dec 23 12:59:45 	WAN 	10.252.48.1:67 	255.255.255.255:68 	UDP
	Dec 23 12:59:21 	WAN 	10.252.48.1:67 	255.255.255.255:68 	UDP
	Dec 23 12:58:54 	WAN 	10.252.48.1 	224.0.0.1 	IGMP
</code></pre>
<p dir="auto">So, I cannot see anything else logged, as this floods them.</p>
<p dir="auto">I'm guessing it's caused by misconfigured DHCP server, somewhere on the system, on my side of the cable Head-End.</p>
<p dir="auto">I'd just like to turn off the logging for these, probably based on the IP.</p>
<p dir="auto">Cheers.</p>
]]></description><link>https://forum.netgate.com/topic/20177/add-firewall-rule-before-block-private-network</link><generator>RSS for Node</generator><lastBuildDate>Thu, 14 May 2026 17:19:48 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/20177.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 23 Dec 2009 21:13:09 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Add Firewall Rule Before Block Private Network on Thu, 24 Dec 2009 17:17:29 GMT]]></title><description><![CDATA[<p dir="auto">Sorry, misread the OP.  I saw the comment about logs filling up by 'default deny' and replied to that :)</p>
]]></description><link>https://forum.netgate.com/post/217451</link><guid isPermaLink="true">https://forum.netgate.com/post/217451</guid><dc:creator><![CDATA[danswartz]]></dc:creator><pubDate>Thu, 24 Dec 2009 17:17:29 GMT</pubDate></item><item><title><![CDATA[Reply to Add Firewall Rule Before Block Private Network on Thu, 24 Dec 2009 17:05:41 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/eddiea">@<bdi>EddieA</bdi></a>:</p>
<blockquote>
<p dir="auto">@onhel:</p>
<blockquote>
<p dir="auto">Discussed here in the past</p>
<p dir="auto">http://forum.pfsense.org/index.php/topic,14131.msg75033.html#msg75033</p>
</blockquote>
<p dir="auto">Ha, that's exactly what I ended up doing.  Great minds, etc.</p>
</blockquote>
<p dir="auto">I think I may have seen that post before but couldn't find it. Glad you got it working anyways. :)</p>
]]></description><link>https://forum.netgate.com/post/217448</link><guid isPermaLink="true">https://forum.netgate.com/post/217448</guid><dc:creator><![CDATA[focalguy]]></dc:creator><pubDate>Thu, 24 Dec 2009 17:05:41 GMT</pubDate></item><item><title><![CDATA[Reply to Add Firewall Rule Before Block Private Network on Thu, 24 Dec 2009 16:13:50 GMT]]></title><description><![CDATA[<p dir="auto">@onhel:</p>
<blockquote>
<p dir="auto">Discussed here in the past</p>
<p dir="auto">http://forum.pfsense.org/index.php/topic,14131.msg75033.html#msg75033</p>
</blockquote>
<p dir="auto">Ha, that's exactly what I ended up doing.  Great minds, etc.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/danswartz">@<bdi>danswartz</bdi></a>:</p>
<blockquote>
<p dir="auto">Under Status =&gt; System Logs =&gt; Settings, there is a checkbox "Log packets blocked by the default rule" :)  But if that isn't what you want…</p>
</blockquote>
<p dir="auto">No, that logs packets that make it past all the rules, and get blocked by the "default".  I wanted to stop logging a packet that was logged by the very first rule "Block private networks".</p>
<p dir="auto">Cheers.</p>
]]></description><link>https://forum.netgate.com/post/217444</link><guid isPermaLink="true">https://forum.netgate.com/post/217444</guid><dc:creator><![CDATA[EddieA]]></dc:creator><pubDate>Thu, 24 Dec 2009 16:13:50 GMT</pubDate></item><item><title><![CDATA[Reply to Add Firewall Rule Before Block Private Network on Thu, 24 Dec 2009 13:24:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/eddiea">@<bdi>EddieA</bdi></a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/danswartz">@<bdi>danswartz</bdi></a>:</p>
<blockquote>
<p dir="auto">you could just disable logging for the default block rule.</p>
</blockquote>
<p dir="auto">Errr, no.  The only option is "Block Private Networks", under Interfaces -&gt; WAN, or not.  You can't make any choices beyond that.</p>
<p dir="auto">But, even if I could, I'd like to see what's happening, other than this bozo.</p>
<p dir="auto">Cheers.</p>
</blockquote>
<p dir="auto">Under Status =&gt; System Logs =&gt; Settings, there is a checkbox "Log packets blocked by the default rule" :)  But if that isn't what you want…</p>
]]></description><link>https://forum.netgate.com/post/217429</link><guid isPermaLink="true">https://forum.netgate.com/post/217429</guid><dc:creator><![CDATA[danswartz]]></dc:creator><pubDate>Thu, 24 Dec 2009 13:24:52 GMT</pubDate></item><item><title><![CDATA[Reply to Add Firewall Rule Before Block Private Network on Thu, 24 Dec 2009 09:51:11 GMT]]></title><description><![CDATA[<p dir="auto">Discussed here in the past</p>
<p dir="auto">http://forum.pfsense.org/index.php/topic,14131.msg75033.html#msg75033</p>
]]></description><link>https://forum.netgate.com/post/217415</link><guid isPermaLink="true">https://forum.netgate.com/post/217415</guid><dc:creator><![CDATA[AhnHEL]]></dc:creator><pubDate>Thu, 24 Dec 2009 09:51:11 GMT</pubDate></item><item><title><![CDATA[Reply to Add Firewall Rule Before Block Private Network on Thu, 24 Dec 2009 06:01:54 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/danswartz">@<bdi>danswartz</bdi></a>:</p>
<blockquote>
<p dir="auto">you could just disable logging for the default block rule.</p>
</blockquote>
<p dir="auto">Errr, no.  The only option is "Block Private Networks", under Interfaces -&gt; WAN, or not.  You can't make any choices beyond that.</p>
<p dir="auto">But, even if I could, I'd like to see what's happening, other than this bozo.</p>
<p dir="auto">Cheers.</p>
]]></description><link>https://forum.netgate.com/post/217400</link><guid isPermaLink="true">https://forum.netgate.com/post/217400</guid><dc:creator><![CDATA[EddieA]]></dc:creator><pubDate>Thu, 24 Dec 2009 06:01:54 GMT</pubDate></item><item><title><![CDATA[Reply to Add Firewall Rule Before Block Private Network on Thu, 24 Dec 2009 04:20:37 GMT]]></title><description><![CDATA[<p dir="auto">you could just disable logging for the default block rule.</p>
]]></description><link>https://forum.netgate.com/post/217395</link><guid isPermaLink="true">https://forum.netgate.com/post/217395</guid><dc:creator><![CDATA[danswartz]]></dc:creator><pubDate>Thu, 24 Dec 2009 04:20:37 GMT</pubDate></item><item><title><![CDATA[Reply to Add Firewall Rule Before Block Private Network on Thu, 24 Dec 2009 00:08:47 GMT]]></title><description><![CDATA[<p dir="auto">There may very well be another way to do it but I'm not aware of it. I guess my situation wasn't exactly like yours because it was the "Default Deny" rule that was filling up my logs so a rule above it without logging worked fine.</p>
<p dir="auto">I think you may have to look at the config.xml or actually at the pf rules currently running to see what the rules are exactly. If it's private networks, you could just make an alias of all private networks (192.168.0.0/16, 10.0.0.0/8, etc) and then block the alias. Just thinking out loud though. I'm sure there's a way to find the exact rule being used.</p>
]]></description><link>https://forum.netgate.com/post/217377</link><guid isPermaLink="true">https://forum.netgate.com/post/217377</guid><dc:creator><![CDATA[focalguy]]></dc:creator><pubDate>Thu, 24 Dec 2009 00:08:47 GMT</pubDate></item><item><title><![CDATA[Reply to Add Firewall Rule Before Block Private Network on Wed, 23 Dec 2009 22:24:44 GMT]]></title><description><![CDATA[<p dir="auto">I'd like to try and do it, without disabling, and manually re-creating the rules for "Block private networks", but if that's the only way.</p>
<p dir="auto">How can I see exactly what the rules are, that are automatically generated for this.</p>
<p dir="auto">Cheers.</p>
]]></description><link>https://forum.netgate.com/post/217372</link><guid isPermaLink="true">https://forum.netgate.com/post/217372</guid><dc:creator><![CDATA[EddieA]]></dc:creator><pubDate>Wed, 23 Dec 2009 22:24:44 GMT</pubDate></item><item><title><![CDATA[Reply to Add Firewall Rule Before Block Private Network on Wed, 23 Dec 2009 21:51:14 GMT]]></title><description><![CDATA[<p dir="auto">What I've done for this type of thing is create your own rule (yes, disable the built in if it is matching that rule) and set it to not log.</p>
]]></description><link>https://forum.netgate.com/post/217369</link><guid isPermaLink="true">https://forum.netgate.com/post/217369</guid><dc:creator><![CDATA[focalguy]]></dc:creator><pubDate>Wed, 23 Dec 2009 21:51:14 GMT</pubDate></item></channel></rss>