Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Block all IPv6 - Disable logging #3517

Closed
imidoriya opened this issue Jun 5, 2019 · 6 comments
Closed

Block all IPv6 - Disable logging #3517

imidoriya opened this issue Jun 5, 2019 · 6 comments
Labels
help wanted Contributor missing / timeout

Comments

@imidoriya
Copy link

There is no option to disable the logging on the "Block all IPv6" rule. Can you add an option to on that rule to turn off logging? It's at the top of the floating and it doesn't seem I can put a rule above it to do the same thing without logging.

@fichtner fichtner added the support Community support label Jun 5, 2019
@fichtner
Copy link
Member

fichtner commented Jun 5, 2019

From my understanding IPv6 block logging is hardwired to logging option for default blocking (on or off globally).

@imidoriya
Copy link
Author

imidoriya commented Jun 5, 2019

It's not the "Default deny rule" if that's what you're suggesting.

The option is under "Firewall: Settings: Advanced" and unchecking "Allow IPv6". This creates a floating rule that blocks all IPv6 traffic, however, there is no option to not log it. It's filling up my firewall logs and it's not anything I care to see. Since you're specifically disabling it, you would almost think to set logging off by default.

@fichtner
Copy link
Member

fichtner commented Jun 5, 2019

I'm not here to argue, just to help. I'll reiterate more explicitly: when you go to System: Settings: Logging you can disable default block logging.

@imidoriya
Copy link
Author

imidoriya commented Jun 5, 2019

Sorry, not arguing. Just trying to understand and explain. Yeah, I don't want to disable all block logging. If IPv4 traffic is blocked, I want to see that. Since the IPv6 option creates its own rule, it would be nice to have the option to turn just that logging off.

I could turn "Allow IPv6" back on and then create my own FW rule - I've done that before, but it would be nice to have the logging accessible for it.

@fichtner fichtner added help wanted Contributor missing / timeout and removed support Community support labels Jun 5, 2019
@fichtner
Copy link
Member

fichtner commented Jun 5, 2019

Understood. I'm assigning this to the community pool for a contributor to grab and implement.

@AdSchellevis
Copy link
Member

This issue has been automatically timed-out (after 180 days of inactivity).

For more information about the policies for this repository,
please read https://github.com/opnsense/core/blob/master/CONTRIBUTING.md for further details.

If someone wants to step up and work on this issue,
just let us know, so we can reopen the issue and assign an owner to it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
help wanted Contributor missing / timeout
Development

No branches or pull requests

3 participants