What does it mean if QuFirewall shows blocking packets from 127.0.0.1 (localhost)?
Applicable Products
QuFirewall
Details
- To find out the IP addresses currently blocked by QuFirewall go to QuFirewall > Firewall Profile > Basic Protection > IP access Protection and click [...].
- To record incoming packets for further analysis, use the PacketCapture function in QuFirewall.
- You can also check the Frequently Asked Questions about QuFirewall for more information.
You may receive notification warning messages like this:
System 127.0.0.1 QuFirewall Firewall Events [QuFirewall] In time of 2021-07-06 16:44:00 ~ 2021-07-06 16:49:00, the denied amount reach the set threshold: 50.
Or in QuLog Center like this:
The source IP is 127.0.0.1, but this does not mean that QuFirewall is blocking packets from the system (127.0.0.1).
In this case the source IP does not correspond to the IP that has blocked the packet. The Source IP 127.0.0.1 corresponds to the Notification Center origin IP, which is the NAS. That means the system is generating the message.
The same happens with other system messages, for example:
The source IP will always be 127.0.0.1 if the message is from the NAS. This is the system IP where the notification is generated.