Project

General

Profile

Actions

Feature #16068

open

Allow disabling logging of packets blocked due to unmatched IP options

Added by Andrew Almond 7 months ago. Updated about 2 months ago.

Status:
Feedback
Priority:
Normal
Assignee:
Category:
Logging
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
25.11
Release Notes:
Default

Description

Logging of packets with options (IGMP) was added/fixed as mentioned in redmine 15400 , however that was closed without addressing the increased logs messages that occur as a side effect.

While this may be intentional, it is confusing because the default ruleset causes it, but disabling the options "Log packets matched from the default block rules in the ruleset" and "Log packets matched from the default pass rules put in the ruleset" does not stop the log messages.

This fix/new behavior can create a lot of noise in the logs and cause increased disk writes, as discussed in this thread

There is the document Troubleshooting Blocked Log Entries for Legitimate Connection Packets, but it is not intuitive or easy to locate when faced with this issue, especially because it is caused by the default behavior. This is a widespread issue, and having to manually add rules to stop IGMP packets from being logged is a workaround but not a solution.

I suggest adding a setting to not "Log packets with IP options" which either modifies the default ruleset or creates the necessary floating rules. This behavior should also be mentioned and linked on the Log Settings page.


Related issues

Related to Regression #15400: IGMP packets are logged when the filter rule has logging disabledNot a Bug

Actions
Related to Feature #16110: Automatically check ``Allow IP options`` when IGMP is selectedResolvedMarcos M

Actions
Related to Feature #16215: Allow matching on IP Options with firewall match rulesResolvedMarcos M

Actions
Actions

Also available in: Atom PDF