Netgate SG-1000 microFirewall

Author Topic: Block ULA what/why  (Read 182 times)

0 Members and 1 Guest are viewing this topic.

Offline senseii

  • Newbie
  • *
  • Posts: 11
  • Karma: +2/-0
    • View Profile
Block ULA what/why
« on: January 27, 2018, 03:36:12 pm »
I have one private IP that my firewall is blocking. Why would a private IP that would be blocked ULA not be an external IP address? How can someone investigate what/who/why such an address is trying to make contact?

Offline senseii

  • Newbie
  • *
  • Posts: 11
  • Karma: +2/-0
    • View Profile
Re: Block ULA what/why
« Reply #1 on: January 27, 2018, 03:37:55 pm »
I think it might be a tunnel from my ISP giving me my DHCP address.
It's a 10.x.x.x:67 UDP.

Offline senseii

  • Newbie
  • *
  • Posts: 11
  • Karma: +2/-0
    • View Profile
Re: Block ULA what/why
« Reply #2 on: January 28, 2018, 07:10:49 am »
anyone have experience with this scenerio or information why private ips are show in the fireall?

Offline johnpoz

  • Hero Member
  • *****
  • Posts: 15126
  • Karma: +1412/-206
  • Not a pfSense employee, they cannot fire me...
    • View Profile
Re: Block ULA what/why
« Reply #3 on: January 28, 2018, 08:03:47 am »
If its rfc1918 why are you hiding it.. Is that dest or source?

Dest 67 from an IP makes little sense with dhcp.. So assume that is a source and is either a offer or an ack?

Please full details, do a packet capture on pfsense and you can see the full details of what it is.  But its not uncommon to see noise on your isp connection that is rfc1918 space..
- An intelligent man is sometimes forced to be drunk to spend time with his fools.
- Please don't PM me for personal help
- if you want to say thanks applaud or https://www.freebsdfoundation.org/donate/
1x SG-2440 2.4.2-RELEASE-p1 (work)
1x SG-4860 2.4.2-RELEASE-p1 (home)

Offline senseii

  • Newbie
  • *
  • Posts: 11
  • Karma: +2/-0
    • View Profile
Re: Block ULA what/why
« Reply #4 on: January 28, 2018, 01:24:22 pm »
ok i will give me some time.