Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Blocking SSDP on LAN

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 2 Posters 5.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      godinperson
      last edited by

      After upgrading to 2.0 RC3, I went into my Firewall Log to realize that pfsense was blocking LAN entries on IPv6. It looks like this:

      Jul 6 08:54:17 LAN ย  fe80::2417:7217:98c0:fbae:58490 ย  ff02::c:1900 (?)

      Port 1900 should be a SSDP port. Why is it blocking internal port? I have a rules that should let everything in the LAN go through.

      Thanks

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Are you on the IPv6 branch or the normal RC3? If you're on the normal RC3, IPv6 traffic is all blocked by default. If you really want to control IPv6 traffic in the GUI, you need to be on the IPv6 branch (what will eventually be 2.1). See the IPv6 board of the GUI for more info.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • G
          godinperson
          last edited by

          Guessing I'm on the regular branch. I just enabled IPv6 for internal (Allow IPv6 All IPv6 will be blocked unless this box is checked.)

          This should unblock IPv6 traffic right? It is already checked.

          Thanks

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            It should pass, yes, though that is really broadcast/multicast so it doesn't matter what the firewall does to it, it isn't routed traffic.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • G
              godinperson
              last edited by

              still shows block though. The other thing is that my firewall log gets filled with those lines.

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                Are there any ipv6 rules in your ruleset?

                $ grep ipv6 /tmp/rules.debug
                

                Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • G
                  godinperson
                  last edited by

                  nope, no rule

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.