( solved )Multicast flood "listener reportmax resp delay"

Started by Javier®, February 25, 2025, 04:08:43 PM

Previous topic - Next topic
Hello everyone, with the default firewall rule ff02::/16, there should be no problem for the firewall to accept ff02::1:ff00:1, I have locks every two minutes, I would have to update the card Drivers network ?, thanks

 block in on igc1: (class 0xe0, hlim 1, next-header Options (0) payload length: 32) fe80::2eb:d5ff:feed:2819 > ff02::1:ff00:1: HBH (rtalert: 0x0000) (padn) [icmp6 sum ok] ICMP6, multicast listener reportmax resp delay: 0 addr: ff02::1:ff00:1

igc0: <Intel(R) Ethernet Controller I226-V> mem 0x80800000-0x808fffff,0x80900000-0x80903fff at device 0.0 on pci2
igc0: EEPROM V2.17-0 eTrack 0x80000303
igc0: Using 1024 TX descriptors and 1024 RX descriptors
igc0: Using 4 RX queues 4 TX queues
igc0: Using MSI-X interrupts with 5 vectors
igc0: Ethernet address: xxxxxxxxxxxxx
igc0: netmap queues/slots: TX 4/1024, RX 4/1024

igc1: <Intel(R) Ethernet Controller I226-V> mem 0x80500000-0x805fffff,0x80600000-0x80603fff at device 0.0 on pci3
igc1: EEPROM V2.17-0 eTrack 0x80000303
igc1: Using 1024 TX descriptors and 1024 RX descriptors
igc1: Using 4 RX queues 4 TX queues
igc1: Using MSI-X interrupts with 5 vectors
igc1: Ethernet address: xxxxxxxxxxxxxx
igc1: netmap queues/slots: TX 4/1024, RX 4/1024

** ¯\_(ツ)_/¯ **  C'est la vie  ** ¯\_(ツ)_/¯ **

Hi everyone, this packet the firewall is blocking is an ICMP type 130 packet. This packet is sent every 125 seconds. It's from my ISP's Cisco.
Opsense doesn't allow Type 130 by default.

Cisco MLD
General Query (Type 130)
Sent to learn about listeners on the attached link
Sets the Multicast Address Field to zero
Sent every 125 seconds

https://www.cisco.com/c/dam/global/sk_sk/assets/expo2011/pdfs/IPv6_multicast_security_Stefan_Kollar.pdf
** ¯\_(ツ)_/¯ **  C'est la vie  ** ¯\_(ツ)_/¯ **