Getting hundreds of 'block drop in log all label "Default deny rule"'



  • I am running pfSense within VMware, connected to a router in modem-mode, using ppoe.
    There are two switches between pfSense and the modem.

    My firewall is reporting hundreds of,

    @1 scrub on em1 all fragment reassemble
    @1 block drop in log all label "Default deny rule"

    These are happening every few seconds.

    Can anyone point me in the right direction?

    I guess one of the questions is, where is this "Default deny rule", and can I turn off the firewall temporarily?



  • ok, so it's normal for a stateful firewall  ::)

    http://forum.pfsense.org/index.php/topic,14259.0.html

    It just makes it difficult IMHO to see proper firewall issues in amongst all this "harmless" noise.
    Maybe better filtering options could help here.


  • Rebel Alliance Developer Netgate

    2.1 has a lot better filtering in the firewall log.

    You can also add your own block rules without log set to match traffic that you don't want to see in the logs.


Log in to reply