News
:
This forum is now permanently frozen.
m0n0wall Forum
>
m0n0wall Support (English)
>
Firewall/NAT
Topic: Blocked broadcasts show in logs...why?
Pages: [
1
]
Topic: Blocked broadcasts show in logs...why? (Read 1648 times)
Blocked broadcasts show in logs...why?
« on: May 13, 2009, 11:30:04 »
Seb74
Posts: 115
If a host in 192.168.3.0/28 sends UDP traffic to 192.168.3.15:137, that is indeed traffic not destined for other networks....its a local subnet broadcast, and routers block broadcasts. I guess windows always does it at boot to check for a netbios nameserver, or just other hosts or however that works I dont remember the different node-types right now.
Anyway, that traffic shows up in my firewall logs, at least when I have logging turned on in the last default block all rule.
Could you say it shouldn't really belong there...I mean, its default routing behaviour and has nothing to do with that particular "block all rule"....you could as well have had a final "allow all" rule and this traffic would still be blocked cause thats how routers work....right?
Just wondering if I'm thinking all wrong here or not, I dont mind it showing there, its just a thought that crossed my mind (and probably never should have lol).
Re: Blocked broadcasts show in logs...why?
« Reply #1 on: May 13, 2009, 15:47:48 »
Fred Grayson
Posts: 994
Add a rule (or rules for all that NetBIOS trash) just above the drop all rule and make sure logging is disabled for this rule. Then these packets will be caught by this rule invisibly and you can do what you want with the logging for the drop all rule.
--
Google is your friend and Bob's your uncle.
Re: Blocked broadcasts show in logs...why?
« Reply #2 on: May 13, 2009, 16:16:23 »
Seb74
Posts: 115
Thanks, but you missed my intention I think.
I dont mind, I just wonder if my reasoning was correct.
Only theoretically, I dont need anything fixed.
Pages: [
1
]