arne_f
(Arne.F)
20 March 2024 15:33
21
The DHCP rules will added if the dhcp is configured on red also. But port 5678 is not dhcp.
My guess is still that there is a misconfigured microtik router before the IPFire or the ISP not correct filter connections from other customers.
I would add a DROP rules without logging to get rid of the logentries.
3 Likes
UPDATE: It seems whatever was causing these 0.0.0.0 entries has either been fixed or taken offline as I have not seen any entries for last 2 days. Letās hope it stays that way. Thank you to all who assisted.
bbitsch
(Bernhard Bitsch)
24 March 2024 12:08
23
This means, it originated on a āmisbehavedā ISP device. As we supposed.
johntk22
(sam john)
26 March 2024 22:56
24
In firewall log the IP address 0.0.0.0 represents the unknown destination, used for outbound traffic without a specific destination IP address.