OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • DHCP responses on WAN interface
« previous next »
  • Print
Pages: [1]

Author Topic: DHCP responses on WAN interface  (Read 4239 times)

TeKK

  • Newbie
  • *
  • Posts: 11
  • Karma: 3
    • View Profile
DHCP responses on WAN interface
« on: April 02, 2019, 10:15:50 am »
Hello,

I am a new user to OPNsense and I am trying to understand some log entries on my WAN interface. I'm getting DHCP OFFER and ACKNOWLEDGE packets on my WAN interface from my cable provider's DHCP server (10.80.212.53).

Code: [Select]
Interface Time Source Destination Proto Label
WAN Apr 2 03:51:36 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:51:36 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:51:16 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:51:11 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:51:05 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:51:02 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:51:00 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:50:55 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:50:55 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:50:55 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:50:46 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:50:42 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:50:42 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:50:40 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:50:37 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:50:33 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:50:21 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:49:55 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:49:53 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:49:49 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:49:49 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:49:32 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:49:09 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN
WAN Apr 2 03:49:06 10.80.212.53:67 255.255.255.255:68 udp Block private networks from WAN



I did a packet capture and viewed the data in Wireshark. What I noticed was that these OFFERs and ACKNOWLEDGEMENTS were responses to other user's (Cable Customers) DHCP DISCOVER and REQUEST messages and not mine. Each packet contains a different Client IP address and MAC address. I know that DHCP can communicate via Broadcast or Unicast. In this case, the responses from the server are being broadcasted back to the clients.

1) Is this normal to see on the WAN interface?
2) Is this traffic supposed to be allowed to the Firewall?
3) Why are the broadcasts only showing up from the server but I am not seeing client broadcasts for the DISCOVER messages?

If somebody could please help me out with these questions, it would be much appreciated.
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: DHCP responses on WAN interface
« Reply #1 on: April 02, 2019, 09:35:33 pm »
...welcome to the club

https://forum.opnsense.org/index.php?topic=12285.0

What I have noticed is that the problems with renewing WAN IP have gone away recently, but I don't know why the DHPC is now on RFC1918 IP range.

Your provider is in Germany?
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

TeKK

  • Newbie
  • *
  • Posts: 11
  • Karma: 3
    • View Profile
Re: DHCP responses on WAN interface
« Reply #2 on: April 03, 2019, 03:40:47 am »
Oh wow, our posts are literally 4 minutes apart from each other.

I am in the US using Spectrum as my provider.
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: DHCP responses on WAN interface
« Reply #3 on: April 03, 2019, 11:05:23 am »
...would love to confirm that other routers (plastic consumer trash) get their DHCP from same servers. Or are the opnsenses singled-out for special treatment?
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • DHCP responses on WAN interface
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2