Reply packets in logs



  • I'm running pfSense 1.2 RC4 on a WRAP with 3 interfaces and I see blocked reply packets in my firewall logs like this :

    2008-01-21 08:03:40	Jan 21 08:04:11 pfsense.home.net pf: 000307 rule 102/0(match): block in on sis2: (tos 0x0, ttl  64, id 52807, offset 0, flags [none], proto: TCP (6), length: 48) 172.16.0.4.80 > 192.168.0.2.8762: S, cksum 0x0645 (correct), 1142604953:1142604953(0) ack 2321564573 win 5840 
    
    • 172.16.0.4 is in my DMZ network (172.16.0.0/24) connected on sis2, 192.168.0.2 is in my standard LAN network (192.168.0.0/24).
    • The HTTP requests were initialized by the 192.168.0.2 machine in LAN.
    • The HTTP connections from 192.168.0.2 to 172.16.0.4 are authorized and work.

    So, I think I shouldn't see such logs about reply packets, do I ?


Log in to reply