• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Help a network mostly-illiterate with firewall

kirbyrj

Fully [H]
2FA
Joined
Feb 1, 2005
Messages
31,345
So I'm jumping my home network from a commercial router (Asus using Asuswrt-Merlin firmware) to something new. I installed OPNSense on a N100 based mini PC I had sitting around. No issues. Everything is up and running.

I also have a Synology NAS on my network with dual LAN. Only 1 of the 2 network ports are connected and I have an IP issued from DHCP on the connected port. HOWEVER, the disconnected port has a specific IP address of 169.254.51.136 and is constantly hitting the firewall trying to reach 169.254.255.255 with various ports. A full 1/3 of the source traffic on my network as seen in the liveview from the firewall is from 169.254.51.136 and the destination 169.254.255.255 is twice as large as any other IP address (including DNS). The ports on the destination are close in the range to the default Plex port (32400). None of them are 32400 specifically, but around there...32412, 32414, etc. I have Plex remote access disabled. This occurs every 5 seconds on my network all are UDP protocol.

My question is, why or how is a disconnected IP address even hitting the firewall? How do I stop this?
 
cant you just disable the second port?

For some reason, that isn't really an option in the DSM software. The only options are to use DHCP or manually enter IP address for IPv4. I disabled IPv6. That was my first thought to just disable it.

It's definitely something to do with Plex. I stopped the process and it stops trying to access anything.
 
I'm not familiar with Synology. But.......

169...... is an IP address assigned to an interface that can't get a valid DHCP lease. It's trying to reach the broadcast address of the "network" ending in .255 for local discovery / communication. Even though that interface isn't physically connected there must be something in Synology where that NIC is active and trying to discover other devices on the network and Synology is being dumb.

You can disable the NIC this way: https://community.synology.com/enu/forum/1/post/138881
 
So I guess it's a Plex issue. Their view is that it's only 4 packets every 5 seconds, so it's not a big deal. "It's not like it's thousands every second" according to their forums :rolleyes:. Known issue though.

I guess the wonders of trying OPNSense and seeing the traffic for myself :D.
 
169...... is an IP address assigned to an interface that can't get a valid DHCP lease. It's trying to reach the broadcast address of the "network" ending in .255 for local discovery / communication. Even though that interface isn't physically connected there must be something in Synology where that NIC is active and trying to discover other devices on the network and Synology is being dumb.

Yep. 169.254.0.0/16 is what's known as a link-local subnet.

It does seem odd and poor design that the interface is up and the address is assigned when there is no connection present.
 
So I guess it's a Plex issue. Their view is that it's only 4 packets every 5 seconds, so it's not a big deal. "It's not like it's thousands every second" according to their forums :rolleyes:. Known issue though.

I guess the wonders of trying OPNSense and seeing the traffic for myself :D.
Why not just disable the second interface? It should only take a few seconds to SSH in and find the interface and disable it.

My other thought is if you mentioned it only happens when Plex is running, that Plex is binding to all interfaces. Is there a way that can set Plex to only use your primary NIC?

Also from a quick search it looks like there is a firewall under Control Panel > Security > Firewall. Can you make a rule in there to drop all traffic on eth1 or whatever the interface is?
 
Why not just disable the second interface? It should only take a few seconds to SSH in and find the interface and disable it.

My other thought is if you mentioned it only happens when Plex is running, that Plex is binding to all interfaces. Is there a way that can set Plex to only use your primary NIC?

Also from a quick search it looks like there is a firewall under Control Panel > Security > Firewall. Can you make a rule in there to drop all traffic on eth1 or whatever the interface is?

I was thinking of using both interfaces when I get my new switch.

I'll double check the Plex settings.

Edit: I made a firewall rule for the disconnected port on the Synology. I disabled the rule I made on the OPNSense box to see if it worked and it doesn't show any traffic from the disconnected port. So the Synology firewall rule seemed to have worked. Thanks for your assistance (y).
 
Last edited:
Back
Top