<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[PfSense wan (em1) constantly pinging my modem. Anyone knows Why?]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I was looking at my suricata alerts and with in the last days.  It was not always like this pfSense Wan interface (em1) is pinging ISP modem internal interface.</p>
<p dir="auto">from the suricata log</p>
<blockquote>
<p dir="auto">04/26/2016  22:03:56 2 ICMP Attempted Information Leak SOURCE.IP    8 DESTINATION.IP  0 1:2100469  GPL SCAN PING NMAP</p>
</blockquote>
<p dir="auto">If I do a tcpdump on the em1 interface</p>
<p dir="auto">I see continuous pinging.</p>
<blockquote>
<p dir="auto">21:37:40.212064 IP (tos 0x0, ttl 64, id 55590, offset 0, flags [none], proto ICMP (1), length 28)<br />
    SOURCE.IP  &gt; DESTINATION.IP: ICMP echo request, id 18862, seq 1229, length 8<br />
21:37:40.212478 IP (tos 0x0, ttl 64, id 9112, offset 0, flags [none], proto ICMP (1), length 28)<br />
    DESTINATION.IP &gt; SOURCE.IP: ICMP echo reply, id 18862, seq 1229, length 8</p>
</blockquote>
<p dir="auto">How can i track down and stop whatever is doing this.</p>
]]></description><link>https://forum.netgate.com/topic/99018/pfsense-wan-em1-constantly-pinging-my-modem-anyone-knows-why</link><generator>RSS for Node</generator><lastBuildDate>Thu, 16 Apr 2026 04:30:20 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/99018.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 27 Apr 2016 02:05:56 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to PfSense wan (em1) constantly pinging my modem. Anyone knows Why? on Wed, 27 Apr 2016 03:08:31 GMT]]></title><description><![CDATA[<p dir="auto">Thanks!<br />
I'll re-enable it for 1 time per second and disable that rule in suricata.</p>
<p dir="auto">No i its not a fancy setup just connected to the ISP fiber router/switch/modem.</p>
]]></description><link>https://forum.netgate.com/post/620068</link><guid isPermaLink="true">https://forum.netgate.com/post/620068</guid><dc:creator><![CDATA[pfsenseboonie]]></dc:creator><pubDate>Wed, 27 Apr 2016 03:08:31 GMT</pubDate></item><item><title><![CDATA[Reply to PfSense wan (em1) constantly pinging my modem. Anyone knows Why? on Wed, 27 Apr 2016 03:03:37 GMT]]></title><description><![CDATA[<p dir="auto">That's always been done. Its interval is adjustable under System&gt;Routing, edit the gateway. The default is 2 per second in 2.3 (with a 0 byte payload, so a trivially small amount of data), 1 per second in 2.2.x and earlier (at default payload size, so less bandwidth used in 2.3). If you aren't using multi-WAN (where you might need fast failover), then once a second or once every few seconds might be fine. You definitely don't want it set to hours or even minutes, it'll lose all its usefulness at that kind of interval.</p>
<p dir="auto">No it won't DoS anything.</p>
<p dir="auto">If your Suricata config is logging every ping, it's not exactly sane. It's pointless to have that, even without gateway monitoring it'll just log useless noise.</p>
]]></description><link>https://forum.netgate.com/post/620066</link><guid isPermaLink="true">https://forum.netgate.com/post/620066</guid><dc:creator><![CDATA[cmb]]></dc:creator><pubDate>Wed, 27 Apr 2016 03:03:37 GMT</pubDate></item><item><title><![CDATA[Reply to PfSense wan (em1) constantly pinging my modem. Anyone knows Why? on Wed, 27 Apr 2016 02:59:51 GMT]]></title><description><![CDATA[<p dir="auto">Ahhh I see in advance features the default is set to 500ms.<br />
Whats a useful setting to set it too.  Like once every 12 hours?</p>
]]></description><link>https://forum.netgate.com/post/620065</link><guid isPermaLink="true">https://forum.netgate.com/post/620065</guid><dc:creator><![CDATA[pfsenseboonie]]></dc:creator><pubDate>Wed, 27 Apr 2016 02:59:51 GMT</pubDate></item><item><title><![CDATA[Reply to PfSense wan (em1) constantly pinging my modem. Anyone knows Why? on Wed, 27 Apr 2016 02:57:06 GMT]]></title><description><![CDATA[<p dir="auto">Wow. That worked.<br />
I disabled it altogether, "to consider" the isp modem/router up.</p>
<p dir="auto">I have been oblivious to this and its the first time i am seeing such entries in suricata log.  A ping ever 5 seconds or 10 seconds I understand but continuous pinging like multipe times per second isnt that like performing a ddos on the isp modem?  Is it safe to have that enabled?<br />
It just fills the suricata log with junk.<br />
Is it a recent feature?</p>
]]></description><link>https://forum.netgate.com/post/620064</link><guid isPermaLink="true">https://forum.netgate.com/post/620064</guid><dc:creator><![CDATA[pfsenseboonie]]></dc:creator><pubDate>Wed, 27 Apr 2016 02:57:06 GMT</pubDate></item><item><title><![CDATA[Reply to PfSense wan (em1) constantly pinging my modem. Anyone knows Why? on Wed, 27 Apr 2016 02:31:48 GMT]]></title><description><![CDATA[<p dir="auto">It's most likely the gateway monitoring feature of pfSense. It doesn't usually ping modems, unless they're acting as routers (and would thus be a default gateway for pfSense). You can change the IP address pinged for monitoring purposes under System &gt; Routing, then changing the <strong>Monitor IP</strong> for that gateway.</p>
]]></description><link>https://forum.netgate.com/post/620061</link><guid isPermaLink="true">https://forum.netgate.com/post/620061</guid><dc:creator><![CDATA[MikeV7896]]></dc:creator><pubDate>Wed, 27 Apr 2016 02:31:48 GMT</pubDate></item></channel></rss>