Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Firewall log 1000 entries in 10 minutes

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 5 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      FasTrak
      last edited by

      Hi I have been using pfsense for 14 days now,
      I think I've got everything set up the way it should be Guest VLANs and portforwarding to my NAS Server and so on;
      but then I saw I those firewall log entries, (1000 in 10 minutes) and came to think about if it was nomal, Or am I under an attack?

      1 Reply Last reply Reply Quote 0
      • C Offline
        Cmellons
        last edited by

        It's hard to say really but the 124.207.63.162 going to your address with a destination port of 23 would have me concerned unless you're doing something with telnet. Some of those could also be states retiring. What does the red x on the left say when clicking on it?

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator
          last edited by

          Looks like noise to me.. Do you P2P?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

          1 Reply Last reply Reply Quote 0
          • ? Offline
            A Former User
            last edited by

            Looks like P2P noise. Are you on a dynamic ip? Maybe the person using it before you was running torrents.

            The port 23 one is a request to connect, which was blocked because that port leads nowhere. Nothing to worry about, just Internet noise.

            1 Reply Last reply Reply Quote 0
            • F Offline
              FasTrak
              last edited by

              Thank you, everyone, yes I have used p2p torrent a few times a while ago but no one is active right now.

              Can it really do that?

              No matter which one I click on it just says EasyRuleBlockHostsWAN.

              But if it's just noise, then I am more calm.

              1 Reply Last reply Reply Quote 0
              • ? Offline
                A Former User
                last edited by

                The torrent client of the other person(s) was told to ask a fragment of the torrent from IP X (yours). Maybe it wasn't told to stop trying to get that fragment, which is why you are still seeing logs for those. Nothing to worry about, it will go away eventually.

                1 Reply Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  yeah once you join a swarm - you can see traffic from that for days for sure..  What you can do if you don't want to see all the noise is create a rule that blocks the udp but not log - which would be blocked anyway by the default rule but.  This way you will see stuff like that tcp attempt to 23, but noise from udp would be not logged and just dropped.

                  This will clear up your logs to only show more interesting stuff ;)

                  I do it now and then if it flairs up with lots of noise..  You could also turn off logging of the default rule - but then you don't see some interesting stuff ;)  The internet is a crazy wild west of traffic..

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

                  1 Reply Last reply Reply Quote 0
                  • F Offline
                    FasTrak
                    last edited by

                    Thank you,

                    It makes good sense, do you have a template to make such a firewall block rule?

                    1 Reply Last reply Reply Quote 0
                    • H Offline
                      Harvy66
                      last edited by

                      @FasTrak:

                      Thank you, everyone, yes I have used p2p torrent a few times a while ago but no one is active right now.

                      Can it really do that?

                      No matter which one I click on it just says EasyRuleBlockHostsWAN.

                      But if it's just noise, then I am more calm.

                      Modern BT uses DHT(Distributed Hash Table), and your IP address may exist in the DHT for several days. At one point, it took me almost a full week before I stopped getting UDP packets.

                      You also want to be careful about any randomization to your listing port. I used a client that did this, and it causes DHT entry pollution, effectively creating an addition entry in the DHT for every port I listen to. Because of this, I would get a LOT of these annoying log filling UDP packets. They're really low bandwidth, but your log gets hit.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                      Privacy Policy · Cookie Policy