cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
502
Views
0
Helpful
1
Replies

RV260P: System log list a firewall block even though Access Rule has Log unchecked

ReedMikel1
Level 1
Level 1

I have a RV260P with latest firmware (1.0.01.01).  I have several Access Rules defined and enabled to block some Source IP Ranges.  One example is 149.11.0.0 to 149.11.255.254.  I also have unchecked the Access Rule's "Log" box.  My assumption is that I should not see any mention of traffic related to this Access rule being blocked, right?  HOWEVER, I do see it in the logs as shown below.  Bug - or maybe I'm not understanding something?

 

2020-11-17T15:30:46+00:00 <warning>kernel: [1186128.788497] FIREWALL:PACKET DROPIN=eth2.1 OUT=eth0 DST_MAC=68:9c:e2:a0:e2:39 SRC_MAC=:54:10:ec:f3:82:32 src=10.10.0.107 DST=149.11.44.35 LEN=40 TOS=0x00 PREC=0x00 TTL=99 ID=17899 PROTO=TCP SPT=4923 DPT=443 WINDOW=1000 RES=0x00 ACK RST URGP=0 MARK=0x100

1 Accepted Solution

Accepted Solutions

ReedMikel1
Level 1
Level 1

My bad - I wasn't paying attention to the fact that I was only blocking that IP range if it was Source.  It was DST in the log...

View solution in original post

1 Reply 1

ReedMikel1
Level 1
Level 1

My bad - I wasn't paying attention to the fact that I was only blocking that IP range if it was Source.  It was DST in the log...