OPNsense Forum

English Forums => Zenarmor (Sensei) => Topic started by: SuperMiguel on September 02, 2022, 06:35:38 am

Title: Apps Breakdown 90% DNS
Post by: SuperMiguel on September 02, 2022, 06:35:38 am
I have like 10 cameras that are just making DNS requests like there is no tomorrow, so 90% of my app breakdown are dns request from this cameras. The firewall rules for that VLAN are block all, but i guess DNS requests still making it to Zenarmor, should i just delete that VLAN from the Zenarmor list? or is there a way to get rid of all them requests. Thanks!
Title: Re: Apps Breakdown 90% DNS
Post by: dinguz on September 02, 2022, 07:25:26 pm
This happens probably because the default view in the dashboard displays the number of Sessions. Because DNS is UDP based, with lots of small packets, and every packet is a session, these numbers rise quite fast, giving a skewed view.
If you change the view to Volume, it gives a better impression of the amount of traffic, and the distribution thereof. You'll probably come to the conclusion that this is nothing to worry about.
Title: Re: Apps Breakdown 90% DNS
Post by: SuperMiguel on September 03, 2022, 02:53:31 pm
Is there a way to block all of these requests? so they dont show?
Title: Re: Apps Breakdown 90% DNS
Post by: Taunt9930 on September 03, 2022, 08:03:15 pm
Is there a way to block all of these requests? so they dont show?

Add a filter, surely?
Title: Re: Apps Breakdown 90% DNS
Post by: sy on September 05, 2022, 08:41:05 pm
Hi,

Do you want to block them or just hide them from the reports?
Title: Re: Apps Breakdown 90% DNS
Post by: SuperMiguel on September 07, 2022, 09:56:32 pm
Block them, These are PoE cameras that dont have internet access and shouldnt make any DNS requests...

I added firewall rules to reject All IN/Out traffic from this VLAN, but still making it to Sensei, I click the block button on Sensei and they still show as blocked

I got tired of it one day and even removed the vlan from sensei and added the vlan to the  Exempted VLANs & Networks  and they still show... So not sure whats going on...
Title: Re: Apps Breakdown 90% DNS
Post by: sy on September 09, 2022, 02:52:22 pm
Hi,

Can you share a bug report? They shouldn't be shown if you added in Exempted VLAN and Network.