Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
Multicast storm created by firewall
« previous
next »
Print
Pages: [
1
]
Author
Topic: Multicast storm created by firewall (Read 1905 times)
Andreas_
Jr. Member
Posts: 61
Karma: 1
Multicast storm created by firewall
«
on:
April 09, 2019, 12:08:07 pm »
From time to time, we're suffering from some strange issue:
Triggered by a workstation on LAN1 sending a ws-discovery multicast on port 3702 (or some other service, just as example), some thousand duplicated packets can be seen on LAN2 (with LAN1-address as sender and mcast as destination), with the source MAC address of the backup firewall of a CARP pair.
Or in other words:
The carp backup firewall, which should be listening passively, creates IP Multicast packets with its own LAN2 MAC source address, LAN1 IP source Address of a client, with a rate of about 5000/s and will not stop until the firewall is kicked with pfctl -d;pfctl -e
Hotfix is to drop UDP traffic to specific ports (such as 3702) on the LAN1 network, but a firewall shouldn't create such packets on its own, right? It's 19.1 (had this already with 18.1/18.7), no specific Multicast/IGMP settings or modules.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
Multicast storm created by firewall