Skip to content
Discussion options

You must be logged in to vote

Yes, it is expected with a default-deny incoming policy, and the fix is to allow incoming traffic from the speakers' addresses. Discovery cannot be opened with a port rule, because both ends of the exchange use random ports.

Discovery sends an SSDP search to the multicast address 239.255.255.250:1900 from a socket bound to port 0, so the kernel picks a random port each time (src/main/features/core/dlna/ssdp-discovery.ts). Each speaker answers with a unicast packet from its own IP to that random port. Connection tracking cannot link that answer to the search, because the search went to the multicast address and the answer comes from a different one, so UFW sees a new incoming packet and dr…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@AlexEshoo
Comment options

Answer selected by AlexEshoo
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants