This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion
I'mseeingalargenumberofpacketsbeingreportedasblockedbythefirewall.Theyareudpport53.Most,butnotall,ofthemarefromlink-localipv6addresses.Thedestinationisutm.Iunderstandtheyarednspackets.Whatistheproperpracticeforthesepackets.ShouldIallowthem?
This thread was automatically locked due to age.
- Cancel
Hi,areyourunningIPv6ontheUTMandyournetworks?
Ifyou'renot,ignorethemorsetuparuletodropthemwithoutlogging.
Barry
- Cancel
- Vote Up0Vote Down
- Cancel
0bimmerdriverin reply to BarryG
I'mfollowinguponthis.I'mseeingDOMAIN(udp/53)trafficfromseveralofthecomputersonmyinternalnetworkdirectedtowardutm,mostlyonipv6,butalsosomeonipv4.I'dliketomakearuletoallowthistraffic.ShouldIexplicitlyidentifytheipv4andipv6addressofutmasthedestination?ShouldIusetheinternalnetworkasthesource?Thanks.
- Cancel
- Vote Up0Vote Down
- Cancel
Icreatedarule,internalnetwork>DNS>InternalAddress.Itdoesn'tseemtobedoinganything.Theaddressesarealllinklocalipv6andipv4toutm.HowdoIallowthistraffic?
- Cancel
- Vote Up0Vote Down
- Cancel
AddthenetworkstotheallowedlistontheDNSconfigurepage?Addingsubnetstherewillcreatehiddenallowrulesinthefirewall.
Linklocaladdressusesthefe80::rangeifIrecall.
- Cancel
- Vote Up0Vote Down
- Cancel
0bimmerdriverin reply to TheDrew
Ilookedbackoverthelast30daysandinterestinglynoticedthatthetrafficisfrombothipv4andipv6link-localaddresses,aswellasipv4andipv6internaladdresses.Therewasonlyoneblockedpacketfromanaddressoutsidetheinternalnetworkoutofalmost100kpackets.Ialsofoundthesourceoftheipv6link-localpackets.Theyareandroidphones.Notsureabouttheipv4linklocaladdresses(169.254/16).
Icreatedanetworkcalledlink-localwith169.254/16andfe80::/64,andaddedittotheDNS.SinceIaddedit,therehavebeenacoupleofblockedpackets,soperhapsthat'snottheanswer.I'llrunitovernightandseewhathappens.MaybeIhavetoaddthelink-localnetworkasasourcetothefirewallrulethatpassestheport53traffic.
- Cancel
- Vote Up0Vote Down
- Cancel
0bimmerdriverin reply to bimmerdriver
I'mhappytosaythataddingtheipv4andipv6link-localaddressrangestothelistofalloweddnsnetworksseemstohavecuredtheproblemwiththeblockeddnspackets.Thanksforthehelp.
- Cancel
- Vote Up0Vote Down
- Cancel