Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Allow specific ip private address from WAN

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 5 Posters 2.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W Offline
      WSchweizer
      last edited by

      I'm getting lots of firewall log messages:

      block/1000001581 Apr 10 17:21:13 WAN Block private networks from WAN block 10/8 (1000001581) 10.139.160.1:67 255.255.255.255:68 UDP
      block/1000001581 Apr 10 17:21:11 WAN Block private networks from WAN block 10/8 (1000001581) 10.139.160.1:67 255.255.255.255:68 UDP
      block/1000001581 Apr 10 17:21:08 WAN Block private networks from WAN block 10/8 (1000001581) 10.139.160.1:67 255.255.255.255:68 UDP

      In the filterlog they are loking like that:
      Apr 10 17:21:08 TheFirewall filterlog: 59,16777216,,1000001581,em0,match,block,in,4,0x0,,64,3594,0,none,17,udp,328,10.139.160.1,255.255.255.255,67,68,308
      Apr 10 17:21:11 TheFirewall filterlog: 59,16777216,,1000001581,em0,match,block,in,4,0x0,,64,4069,0,none,17,udp,328,10.139.160.1,255.255.255.255,67,68,308
      Apr 10 17:21:13 TheFirewall filterlog: 59,16777216,,1000001581,em0,match,block,in,4,0x0,,64,4253,0,none,17,udp,328,10.139.160.1,255.255.255.255,67,68,308

      I think, this messages are coming from my cable modem or the provider.

      I didn't find a possibility to add a rule which allows this trafic as long as the RFC 1918 blocking rules are active.
      Is there a way to place such a rule before the "Block private networks" rule?

      Thanks
      Werner

      pfSense 2.2.2 on Soekris net6501 and APU 1d4

      1 Reply Last reply Reply Quote 0
      • KOMK Offline
        KOM
        last edited by

        Unfortunately, that isn't a rule that you can unset the logging on.  Go to Interfaces - WAN - Private Networks - Block private networks.  Uncheck it.  That will stop the block as well as the log entries.

        1 Reply Last reply Reply Quote 0
        • W Offline
          WSchweizer
          last edited by

          Yes, I know that. But I don't like to open the WAN interface for private network addresses.

          Thanks for your reply.

          pfSense 2.2.2 on Soekris net6501 and APU 1d4

          1 Reply Last reply Reply Quote 0
          • P Offline
            phil.davis
            last edited by

            The IPv4 private networks list is not long anyway, you can easily make your own alias for it and make rules using the alias. That gives you whatever flexible you like to put other rules before or after blocking private networks with or without logging or…

            192.168.0.0/16
            10.0.0.0/8
            172.16.0.0/12

            and just for completeness there is the Carrier-Grade NAT (CGN) block:
            100.64.0.0/10
            that you might see traffic from or might be in a traceroute through your ISP.

            As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
            If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

            1 Reply Last reply Reply Quote 0
            • KOMK Offline
              KOM
              last edited by

              You're not really opening anything on WAN since any traffic still has to make it past your ruleset, just like public IP space.  The Block Private networks option just drops any packets from private space.

              1 Reply Last reply Reply Quote 0
              • W Offline
                WSchweizer
                last edited by

                Solved!

                Thank you KOM and phil.davis for your help.

                Sincerely
                Werner

                pfSense 2.2.2 on Soekris net6501 and APU 1d4

                1 Reply Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  Why would you want to allow that dhcp noise??  That is not your request for dhcp, that is others on your same isp..  There are rules to allow your dhcp request on your wan to work.

                  I really don't see the point of specific blocking private or bogon to be honest.  Everything is blocked on my wan, doesn't matter if your bogon or private anyway.  The allows I have are into my vpn, don't care if you hit that with bogon address or a private - since everyone else on the public net can hit it anyway.  Same goes for my other forwards..

                  If you wanted to block specific shit from hitting your services that are open/forwarded blocking bad countries netblocks might be better than some non routable address anyway.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                  1 Reply Last reply Reply Quote 0
                  • W Offline
                    WSchweizer
                    last edited by

                    My first intention was to ban this garbage from my log by creating a blocking rule without logging it.
                    Second I was wondering what this is by allowing it temporarily while sniffing the traffic.

                    Then the general question came up: is it possible at all to define a rule which is executed before this private and bogon network rules.

                    pfSense 2.2.2 on Soekris net6501 and APU 1d4

                    1 Reply Last reply Reply Quote 0
                    • D Offline
                      doktornotor Banned
                      last edited by

                      @WSchweizer:

                      Then the general question came up: is it possible at all to define a rule which is executed before this private and bogon network rules.

                      No. Just stop logging those.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.