This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

'Any -> Any -> Any' and we still see "Default Drop"???

I never tried this before, opening everything and logging traffic then looking at the packet filter log.  How can ANYTHING get default dropped?


This thread was automatically locked due to age.
Parents Reply Children
  • Packets hitting the Network or Broadcast addresses don't get covered by a ANY rule.
    You'd need another rule to Allow them (although there's not point unless you're bridging) or Drop them with or without logging.

    Normally I drop internal broadcasts without logging.

    Barry
  • These were coming from the outside and hitting external IPs.

    Ohhh, wait a minute.  Those were to Additional Addresses on ports NOT relayed by my DNAT rule; of course they were dropped - where was the poor firewall gonna send those messages anyway?

    Pay no attention to the man behind the curtain!*

    Cheers - Bob
    *A "Wizard of Oz" reference.