Recommended Posts

I'm having a problem with my internet connectivity with pfSense, my WAN interface keeps going offline after a set of actions that regularly appear in the logs.

 

My WAN interface remains up at all times, it has a public IP via DHCP from my ISP, via a bridged modem. I think this repeating offline/online cycle is affecting my line speed and I can't reach anywhere near my lines capability. Description of problem below, can anyone advise what is going on or how to troubleshoot this?

 

This is a screenshot of the log showing the actions that appear to coincide with the WAN gateway going offline. I'm not saying this is the cause, just that this happens repeatedly at the same time, not sure if cause or effect, or I suppose, if even unrelated to the gateway going offline.

Screen Shot 2016-08-21 at 09.39.15 redacted.png

 

And this is what the gatway log shows for the WAN going offline. Note the times of the instances match those of the set of actions in the system log.

Screen Shot 2016-08-21 at 09.38.20 redacted.png

 

Any help appreciated, this is doing my head in! :yes:

 

rancid

if your wan goes offline, or the monitoring system thinks it does because of high latency then yeah it can reset the states and disconnect you..  This can be a problem if your starting to load up your pipe and your buffer bloat causes your latency to go way up.. So monitor thinks your gateway is offline and resets all the states.

 

You can turn that function off here

 

System / Advanced / Miscellaneous

flushstates.jpg

 

Other option is to disable gateway monitoring.. But that is not good idea.  Other option is work with traffic shaping to prevent buffer bloat increasing the latency to your gateway IP your monitoring, etc..  Another option is to change the monitor values to really really high latency doesn't count as your gateway being offline so the states flush.. The quick easy fix is to just uncheck that box ;)

 

That function is really for when you have more than 1 wan, and you want to use say your 2nd wan when 1st goes down then yeah you would want to flush all the states on that 1st gateway so your clients create new connections via the 2nd failover gateway, etc..  But in a 1 wan configuration that option really has no use, not really a reason to reset your states..  And as you can see if monitoring thinks your connection is down because your latency exceeds a specific threshold wack go all your sessions ;)

 

 

  • Like 1

That sounds logical, only problem is that box is unchecked already! :s

 

Also, not sure if it is related to loading the pipe up, it seems to be more time based, as in every half hour it does this, regardless of what I am doing.

 

Any thoughts?!

clearly dpinger is giving you a warning about your connectivity - showing 20% packet loss, etc.  So maybe your wan connection is just sucks?  Did you contact your isp?

 

Just because the interface is up doesn't mean your not having line issues..

 

What does your quality graph look like.. Also you have ipv6 on your wan - are you using it?  If not you could try turning off ipv6 on pfsense wan..

packetloss.jpg

 

see last night I had a bit of a problem for a bit.. Connection just went belly up for a bit.. Interface never went down.. But pinging to gateway that dpinger monitors wasn't answering.. See normally I get about 10ms response time to my gateway..

 

Here is same graph for my ipv6 tunnel.

 

tunnel.jpg

 

you can see same exact time having a problem with it.. This rides on top of my ipv4 connection, so not just gateway wasn't answering ping, etc..

 

Here is my connection to my vps via a vpn connection..

vpnconnection.jpg

 

You can see same exact time some sort of issue!!  It has some minor connection issues later while you don't see those on the other graphs for normal ipv4 wan, my ipv6 tunnel, etc..  So what does your quality graph look like when you say you have these problems?

 

if I zoom in

zoomin.jpg

 

You can see I was offline for a few minutes.. I was not actually on then so didn't notice it..

 

From log you can see showed same alarms as you, and then they cleared once the packetloss dropped below threshold..

logclear.jpg

 

Normally my connection is rock solid stable - but as of late they have been having some minor hiccups now and then.. It think its prob related to the gig rollout that is coming to chicagoland from comcast.. I have my name on list.. Going to be freaking sweet!!! ;)

 

This topic is now closed to further replies.
  • Posts

    • The actual download size is ~130–180 MB, not 100 MB.
    • Slight change of pace for me! Gunnar & the Grizzly Boys - Standard American (Official)  
    • draw.io Desktop 30.2.4 by Razvan Serea draw.io desktop is a downloadable security-first diagramming application that runs on Windows, MacOS and Linux. Creating diagrams in the desktop app doesn’t need an internet connection. This is useful when you are disconnected or when you must create diagrams in a highly secure environment, where data protection is of the utmost importance. When you use the draw.io desktop app, your diagrams will be stored on your local device. Because this is a stand-alone application, also designed to run offline, there are no interfaces to cloud storage platforms available. Of course, you can still store your diagrams in folders that are synchronised to your cloud storage if you wish. Easy-to-use diagram editor The draw.io apps work just like the office and drawing tools you are used to using. Drag and drop shapes from the shape libraries and drag to draw connectors between them. Drag connectors to add waypoints and set a precise shape and position, or let them reroute automatically. Double click and start typing to add a label to anything. Create tables and swimlane flows with a familiar tool. Style shapes and connectors with customisable palettes, sketch options, fonts and text formatting tools. Search for shapes, including in open-source icon libraries. Use our vast libraries of shapes and templates, organised into logical categories, to create a range of diagrams and infographics. Generate diagrams from text descriptions using our smart templates. Diagram faster with keyboard shortcuts. draw.io Desktop 30.2.4 changelog: Uses electron 42.4.1 Updates to draw.io core 30.2.4. Download: draw.io 64-bit | Standalone ~100.0 MB (Open Source) Download: draw.io 32-bit | ARM64 | ARM64 Standalone Links: draw.io Home Page | Project page @GitHub | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Microsoft will soon allow some users to block Copilot from analyzing their Office files by Usama Jawad Microsoft Purview is a pretty useful data governance, security, and management service that allows customers to gain enhanced visibility and control over their content. It's meant for commercial customers, such as organizations that are storing data at scale. As AI continues to expand and infiltrate every corner of a firm, many are a bit conscious about the technology gaining access to their confidential data. Microsoft is now making a configuration change that will allow such customers to rest easy. Right now, users within an organization have the option to apply Purview sensitivity labels (when available) to secure certain files and label them as such. For example, if you apply the "Confidential" label on an Excel file, the file will be encrypted, and a "confidential" watermark will be applied to it. So, if this file is shared with anyone, they are aware that its access is supposed to be restricted. Up until now, Microsoft was allowing some connected experiences, like its AI services, to analyze files, regardless of their sensitivity label. This is of major concern to most organizations, as a recent example highlighted how confidential emails with data loss prevention (DLP) policies like privacy labels were being uploaded to Copilot for analysis. As such, Microsoft is updating an existing Purview data label sensitivity setting that prevents "some connected experiences that analyze content", from being blocked completely from doing this. The label isn't changing, but the blocking is now being enforced across all connected services (including Copilot and other AI tools), and now extends to Microsoft Word, Excel, and PowerPoint. Files with the label applied already will get this enhancement automatically too once it becomes available. Microsoft has urged IT admins to inform their respective helpdesk and compliance teams, update internal documentation, and review sensitivity labels to ensure that they meet their respective compliance needs. This change is tagged as MC1297982 in the Message Center. General availability is scheduled to begin in a phased manner soon and will complete by the end of next month. That said, it is important to note that this only applies to commercial customers who have a license that allows them to use Purview.
    • llamas are unruly going haywire in New Guinea.
  • Recent Achievements

    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
    • First Post
      BizSAR earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      589
    2. 2
      +Edouard
      190
    3. 3
      Michael Scrip
      76
    4. 4
      PsYcHoKiLLa
      75
    5. 5
      neufuse
      72
  • Tell a friend

    Love Neowin? Tell a friend!