DStvNothingOn
Expert Member
Was messing around with logging on my MikroTik's WAN drop rule tonight and noticed ether1 (straight off the Frogfoot ONT) is picking up a constant stream of DHCP discovers (0.0.0.0:68 -> 255.255.255.255:67) from MACs that aren't mine. So presumably other people's routers on the same segment looking for DHCP, and no port isolation on my segment at least.
Firewall drops it all, just surprised it's not isolated. Checked ARP and there's nothing from foreign MACs, so it looks limited to DHCP broadcast flooding rather than full L2 visibility. Anyone else on Frogfoot seeing this? Wondering if it's area specific or just how they run their segments. Also keen to hear if the Vumatel/Openserve guys see the same or if it's a Frogfoot thing.
Getting the usual port scans from Bulgaria and China in the same log but that's every public IP ever.
Firewall drops it all, just surprised it's not isolated. Checked ARP and there's nothing from foreign MACs, so it looks limited to DHCP broadcast flooding rather than full L2 visibility. Anyone else on Frogfoot seeing this? Wondering if it's area specific or just how they run their segments. Also keen to hear if the Vumatel/Openserve guys see the same or if it's a Frogfoot thing.
Getting the usual port scans from Bulgaria and China in the same log but that's every public IP ever.