I’m seeing these packets in firewall INPUT whenever back-to-home-vpn is enabled:
13:55:40 firewall,info input: in:(unknown 1) out:(unknown 0), connection-state:new proto UDP, 127.0.0.1:41878->0.0.0.0:0, len 176
13:55:45 firewall,info input: in:(unknown 1) out:(unknown 0), connection-state:new proto UDP, 127.0.0.1:41878->0.0.0.0:0, len 176
13:55:50 firewall,info input: in:(unknown 1) out:(unknown 0), connection-state:new proto UDP, 127.0.0.1:41878->0.0.0.0:0, len 176
13:55:55 firewall,info input: in:(unknown 1) out:(unknown 0), connection-state:new proto UDP, 127.0.0.1:41878->0.0.0.0:0, len 176
13:56:00 firewall,info input: in:(unknown 1) out:(unknown 0), connection-state:new proto UDP, 127.0.0.1:41878->0.0.0.0:0, len 176
13:56:06 firewall,info input: in:(unknown 1) out:(unknown 0), connection-state:new proto UDP, 127.0.0.1:41878->0.0.0.0:0, len 176
13:56:11 firewall,info input: in:(unknown 1) out:(unknown 0), connection-state:new proto UDP, 127.0.0.1:41878->0.0.0.0:0, len 176
13:56:16 firewall,info input: in:(unknown 1) out:(unknown 0), connection-state:new proto UDP, 127.0.0.1:41878->0.0.0.0:0, len 176
13:56:21 firewall,info input: in:(unknown 1) out:(unknown 0), connection-state:new proto UDP, 127.0.0.1:41878->0.0.0.0:0, len 176
13:56:26 firewall,info input: in:(unknown 1) out:(unknown 0), connection-state:new proto UDP, 127.0.0.1:41878->0.0.0.0:0, len 176
13:56:31 firewall,info input: in:(unknown 1) out:(unknown 0), connection-state:new proto UDP, 127.0.0.1:41878->0.0.0.0:0, len 176
13:56:36 firewall,info input: in:(unknown 1) out:(unknown 0), connection-state:new proto UDP, 127.0.0.1:41878->0.0.0.0:0, len 176
13:56:41 firewall,info input: in:(unknown 1) out:(unknown 0), connection-state:new proto UDP, 127.0.0.1:41878->127.0.0.1:0, len 176
13:56:46 firewall,info input: in:(unknown 1) out:(unknown 0), connection-state:new proto UDP, 127.0.0.1:41878->127.0.0.1:0, len 176
13:56:51 firewall,info input: in:(unknown 1) out:(unknown 0), connection-state:new proto UDP, 127.0.0.1:41878->127.0.0.1:0, len 176
These are Back-to-Home VPN packets because port 41878 is the chosen port of the service:
/interface wireguard
add comment=back-to-home-vpn listen-port=41878 mtu=1420 name=back-to-home-vpn
As soon as back-to-home-vpn is disabled, the packets also stop arriving in INPUT.
I would like to know if this is somehow some misconfiguration in the back-to-home-vpn Wireguard service. I also have another, different Wireguard instance and don’t observe such packets in the firewall from that service. The packets above are caught by the DROP all final INPUT rule in my firewall setup, and even though they are dropped, back-to-home-vpn continues to function normally.