Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Comcast IPv6 dual now working - but now lots of noise in firewall logs

    Scheduled Pinned Locked Moved IPv6
    2 Posts 1 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      So awhile back I had started a thread about comcast native ipv6 not working, no RA being seen, etc.

      Not getting my /64 on lan while using track interface and 0, etc.

      Well they fixed something - because now its working..  Im on comcast native ipv6, inbound to my pool ntp server on its new comcast ipv6 address working, etc.  Problem is is seeing a flood of this in my firewall log now

      block Dec 29 11:23:43 WAN fe80::201:5cff:fe31:da01 ff02::1:ff00:1 none
      block Dec 29 11:23:18 WAN fe80::201:5cff:fe31:da01 ff02::1:ff00:1 none
      block Dec 29 11:21:38 WAN fe80::201:5cff:fe31:da01 ff02::1:ff00:1 none
      block Dec 29 11:21:14 WAN fe80::201:5cff:fe31:da01 ff02::1:ff00:1 none
      block Dec 29 11:20:12 WAN fe80::201:5cff:fe31:da01 ff02::1:ff00:1 none
      block Dec 29 11:19:32 WAN fe80::201:5cff:fe31:da01 ff02::1:ff00:1 none
      block Dec 29 11:18:07 WAN fe80::201:5cff:fe31:da01 ff02::1:ff00:1 none

      that fe80::201:5cff:fe31:da01 is my gateway, but ff02::1:ff00:1 is ipv6 multicast is not?  Why is it being block by default rule?

      multicastblocked.png
      multicastblocked.png_thumb

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        So there is some more info

        Clearly its not protocol NONE Like the firewall log is saying, I captured some packets

        Protocols in frame: eth:ipv6:icmpv6

        My question is really what would be the best type of rule to not log this sort of traffic.  It's noise in the log.  And why is the protocol not listed correctly?  BTW running

        2.1-BETA1 (i386)
        built on Fri Dec 28 20:54:16 EST 2012
        FreeBSD 8.3-RELEASE-p5

        captureblocked.png
        captureblocked.png_thumb
        whyblocked.png
        whyblocked.png_thumb

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.