OPNsense Forum

English Forums => 26.7 Series => Topic started by: vimage22 on September 06, 2026, 04:45:24 PM

Title: block events without Label? Firewall: Log Files: Live View
Post by: vimage22 on September 06, 2026, 04:45:24 PM
I did a clean install to 26.7.3_11 and now see events in Live Log that did not seem to be there before. Is this normal? Without a label, there is no way to track the specific rule that triggered it?


Title: Re: block events without Label? Firewall: Log Files: Live View
Post by: lmoore on September 06, 2026, 05:27:51 PM
Looking at the list of automatically generated rules, it should be allowed.

(https://forum.opnsense.org/index.php?action=dlattach;attach=58006)


[Edit] Rephrased response.
Title: Re: block events without Label? Firewall: Log Files: Live View
Post by: vimage22 on September 06, 2026, 06:00:06 PM
Agreed, but then shouldn't this be displayed as the Label? "IPv6 RFC4890 requirements (ICMP)"
Title: Re: block events without Label? Firewall: Log Files: Live View
Post by: lmoore on September 06, 2026, 06:14:15 PM
Check setting for Disable RFC4890 requirement rules in Firewall -> Settings -> Advanced, is it unticked?
Title: Re: block events without Label? Firewall: Log Files: Live View
Post by: vimage22 on September 06, 2026, 06:36:31 PM
All loggings settings in Advanced are unchecked. And this is how it was setup in older versions. So still puzzled why these appear.
Also, just realized the rule is set to Pass, not block.
And "Disable RFC4890 requirement rules" is unchecked.

Does this show anything interesting?

action    [block]
class      0x00
dir       [in]
dst      ff02::16
dsthostname   ff02::16
flow      0x00000
hoplimit   1
interface   bridge0
ipversion   6
label   
length      76
protoname   icmp
protonum   1
reason      ip-option
src      ::
srchostname   ::
status      2