This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos UTM9 dropping all-systems.mcast.net

Hi

I am receiving lots of these every day in the Network Protection / Packet Filter / Firewall log :

/var/log/packetfilter.log:2013:05:06-15:19:22 cable-static-xx-xx-x ulogd[4546]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth7" srcmac="xx:xx:xx:xx:xx:xx" dstmac="yy:yy:yy:yy:yy:yy" srcip="192.168.100.***" dstip="224.0.0.1" proto="2" length="36" tos="0x00" prec="0x00" ttl="1" 

The srcip is a wireless router in our network. Why is the UTM dropping these packets ? What can I do to stop it ?

Thanks in advance
Freddie


This thread was automatically locked due to age.
  • This is Multicast-Traffic. Simplest way would be a rule allowing this traffic from the Router.

    There might be an UPNP/AV server or similar running on the router causing this kind of traffic. It is nothing to worry about.

    ----------
    Sophos user, admin and reseller.
    Private Setup:

    • XG: HPE DL20 Gen9 (Core i3-7300, 8GB RAM, 120GB SSD) | XG 18.0 (Home License) with: Web Protection, Site-to-Site-VPN (IPSec, RED-Tunnel), Remote Access (SSL, HTML5)
    • UTM: 2 vCPUs, 2GB RAM, 50GB vHDD, 2 vNICs on vServer (KVM) | UTM 9.7 (Home License) with: Email Protection, Webserver Protection, RED-Tunnel (server)
  • Thanks for the quick reply. I will create a rule to allow this traffic