Re: [pfSense] Strange packetloss
Yes both mashines complety the same. I disabled actually everything. Packloss starts when traffic (20-30mbit) will pass the interface. I am pretty sure there is something misconfigured on pfSense side. Am 21.10.17, 00:09 schrieb "list-boun...@lists.pfsense.org im Auftrag von mad.scientist.at.la...@tutanota.com": are the 2 machines you have setup to firewall identical machines with identical ethernet interfaces set up the same way (i.e. offloading some packet processing to the card on one machine but not the other? Could it be that one machine just can't keep up. I assume you've reinstalled pfsense on the problem machine? Is the slow machine clean? as i'm sure you know many machines will reduce the clock speed if the cpu is getting too hot, the slow machine may just need a good cleaning. mad.scientist.at.large (a good madscientist) -- I find it ironic that at a time when Americans are concerned about violence and Bullying in schools and elsewhere that we would elect a Grand Poohbah who's a violent bully and hates everyone, including himself, as demonstrated by speech and action. I've known 2 year olds that behaved more appropriately. Besides, there can be no rule of law when those in charge are contemptuous of the whole frame work on which our country is based . 20. Oct 2017 10:00 by dan...@linux-nerd.de: > Hi Everyone, > > > > actually i have an any/any rule applied on all my interfaces. This I did actually only for debugging issues. > > But I can see that packets still get blocked: > > > > Oct 20 17:48:34 gw02 filterlog: 5,,,100103,igb0,match,block,in,4,0x0,,56,64553,0,DF,6,tcp,52,93.220.211.99,212.168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > Oct 20 17:48:34 gw02 filterlog: 5,,,100103,igb0,match,block,in,4,0x0,,56,64554,0,DF,6,tcp,52,93.220.211.99,212.168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > Oct 20 17:48:35 gw02 filterlog: 5,,,100103,igb0,match,block,in,4,0x0,,55,37998,0,DF,6,tcp,52,109.44.1.50,212.168.31.112,34675,443,0,FA,1545664688,2414488008,40,,nop;nop;TS > > Oct 20 17:48:35 gw02 filterlog: 5,,,100103,igb0,match,block,in,4,0x0,,56,64555,0,DF,6,tcp,52,93.220.211.99,212.168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > Oct 20 17:48:36 gw02 filterlog: 5,,,100103,igb0,match,block,in,4,0x0,,56,64556,0,DF,6,tcp,52,93.220.211.99,212.168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > Oct 20 17:48:38 gw02 filterlog: 5,,,100103,igb0,match,block,in,4,0x0,,56,64557,0,DF,6,tcp,52,93.220.211.99,212.168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > Oct 20 17:48:42 gw02 filterlog: 5,,,100103,igb0,match,block,in,4,0x0,,56,64558,0,DF,6,tcp,52,93.220.211.99,212.168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > > > Why? Normaly all traffic can pass the interfaces. > > > > Main problem is that I have 1% packetloss when it pass the Intenet connection to my Upstream. I have a second firewall configured identical and here is no packetloss. > > I Changed all cables and so… I am absolutely without any glue what can cause such a problem. > > > > Could it be a problem that I have serval different networks applied on one Interface without vlans? > > I Realy don’t know what I can do. This issue is very hard and all thinks I already tested doesn’t not help to fix the issue. > > > > Kernel Messages and logs also looking OK for me. > > > > Maybe someone can help me out and give me some ideas > > > > Cheers > > > > Daniel > > ___ > pfSense mailing list > https://lists.pfsense.org/mailman/listinfo/list > Support the project with Gold! > https://pfsense.org/gold ___ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support the project with Gold! https://pfsense.org/gold ___ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support the project with Gold! https://pfsense.org/gold
Re: [pfSense] Strange packetloss
Nope it is not active on any interface. Am 20.10.17, 18:39 schrieb "List im Auftrag von Ivo Tonev": On each interface you have "Block bogon networks". Is that option active ? On Fri, Oct 20, 2017 at 2:00 PM, Daniel wrote: > Hi Everyone, > > > > actually i have an any/any rule applied on all my interfaces. This I did > actually only for debugging issues. > > But I can see that packets still get blocked: > > > > Oct 20 17:48:34 gw02 filterlog: 5,,,100103,igb0,match, > block,in,4,0x0,,56,64553,0,DF,6,tcp,52,93.220.211.99,212. > 168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > Oct 20 17:48:34 gw02 filterlog: 5,,,100103,igb0,match, > block,in,4,0x0,,56,64554,0,DF,6,tcp,52,93.220.211.99,212. > 168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > Oct 20 17:48:35 gw02 filterlog: 5,,,100103,igb0,match, > block,in,4,0x0,,55,37998,0,DF,6,tcp,52,109.44.1.50,212.168. > 31.112,34675,443,0,FA,1545664688,2414488008,40,,nop;nop;TS > > Oct 20 17:48:35 gw02 filterlog: 5,,,100103,igb0,match, > block,in,4,0x0,,56,64555,0,DF,6,tcp,52,93.220.211.99,212. > 168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > Oct 20 17:48:36 gw02 filterlog: 5,,,100103,igb0,match, > block,in,4,0x0,,56,64556,0,DF,6,tcp,52,93.220.211.99,212. > 168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > Oct 20 17:48:38 gw02 filterlog: 5,,,100103,igb0,match, > block,in,4,0x0,,56,64557,0,DF,6,tcp,52,93.220.211.99,212. > 168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > Oct 20 17:48:42 gw02 filterlog: 5,,,100103,igb0,match, > block,in,4,0x0,,56,64558,0,DF,6,tcp,52,93.220.211.99,212. > 168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > > > Why? Normaly all traffic can pass the interfaces. > > > > Main problem is that I have 1% packetloss when it pass the Intenet > connection to my Upstream. I have a second firewall configured identical > and here is no packetloss. > > I Changed all cables and so… I am absolutely without any glue what can > cause such a problem. > > > > Could it be a problem that I have serval different networks applied on one > Interface without vlans? > > I Realy don’t know what I can do. This issue is very hard and all thinks I > already tested doesn’t not help to fix the issue. > > > > Kernel Messages and logs also looking OK for me. > > > > Maybe someone can help me out and give me some ideas > > > > Cheers > > > > Daniel > > ___ > pfSense mailing list > https://lists.pfsense.org/mailman/listinfo/list > Support the project with Gold! https://pfsense.org/gold -- Ivo R. Tonev +55 61 98409-2642 i...@tonev.com.br ___ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support the project with Gold! https://pfsense.org/gold ___ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support the project with Gold! https://pfsense.org/gold
Re: [pfSense] Strange packetloss
On each interface you have "Block bogon networks". Is that option active ? On Fri, Oct 20, 2017 at 2:00 PM, Danielwrote: > Hi Everyone, > > > > actually i have an any/any rule applied on all my interfaces. This I did > actually only for debugging issues. > > But I can see that packets still get blocked: > > > > Oct 20 17:48:34 gw02 filterlog: 5,,,100103,igb0,match, > block,in,4,0x0,,56,64553,0,DF,6,tcp,52,93.220.211.99,212. > 168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > Oct 20 17:48:34 gw02 filterlog: 5,,,100103,igb0,match, > block,in,4,0x0,,56,64554,0,DF,6,tcp,52,93.220.211.99,212. > 168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > Oct 20 17:48:35 gw02 filterlog: 5,,,100103,igb0,match, > block,in,4,0x0,,55,37998,0,DF,6,tcp,52,109.44.1.50,212.168. > 31.112,34675,443,0,FA,1545664688,2414488008,40,,nop;nop;TS > > Oct 20 17:48:35 gw02 filterlog: 5,,,100103,igb0,match, > block,in,4,0x0,,56,64555,0,DF,6,tcp,52,93.220.211.99,212. > 168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > Oct 20 17:48:36 gw02 filterlog: 5,,,100103,igb0,match, > block,in,4,0x0,,56,64556,0,DF,6,tcp,52,93.220.211.99,212. > 168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > Oct 20 17:48:38 gw02 filterlog: 5,,,100103,igb0,match, > block,in,4,0x0,,56,64557,0,DF,6,tcp,52,93.220.211.99,212. > 168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > Oct 20 17:48:42 gw02 filterlog: 5,,,100103,igb0,match, > block,in,4,0x0,,56,64558,0,DF,6,tcp,52,93.220.211.99,212. > 168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS > > > > Why? Normaly all traffic can pass the interfaces. > > > > Main problem is that I have 1% packetloss when it pass the Intenet > connection to my Upstream. I have a second firewall configured identical > and here is no packetloss. > > I Changed all cables and so… I am absolutely without any glue what can > cause such a problem. > > > > Could it be a problem that I have serval different networks applied on one > Interface without vlans? > > I Realy don’t know what I can do. This issue is very hard and all thinks I > already tested doesn’t not help to fix the issue. > > > > Kernel Messages and logs also looking OK for me. > > > > Maybe someone can help me out and give me some ideas > > > > Cheers > > > > Daniel > > ___ > pfSense mailing list > https://lists.pfsense.org/mailman/listinfo/list > Support the project with Gold! https://pfsense.org/gold -- Ivo R. Tonev +55 61 98409-2642 i...@tonev.com.br ___ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support the project with Gold! https://pfsense.org/gold
[pfSense] Strange packetloss
Hi Everyone, actually i have an any/any rule applied on all my interfaces. This I did actually only for debugging issues. But I can see that packets still get blocked: Oct 20 17:48:34 gw02 filterlog: 5,,,100103,igb0,match,block,in,4,0x0,,56,64553,0,DF,6,tcp,52,93.220.211.99,212.168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS Oct 20 17:48:34 gw02 filterlog: 5,,,100103,igb0,match,block,in,4,0x0,,56,64554,0,DF,6,tcp,52,93.220.211.99,212.168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS Oct 20 17:48:35 gw02 filterlog: 5,,,100103,igb0,match,block,in,4,0x0,,55,37998,0,DF,6,tcp,52,109.44.1.50,212.168.31.112,34675,443,0,FA,1545664688,2414488008,40,,nop;nop;TS Oct 20 17:48:35 gw02 filterlog: 5,,,100103,igb0,match,block,in,4,0x0,,56,64555,0,DF,6,tcp,52,93.220.211.99,212.168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS Oct 20 17:48:36 gw02 filterlog: 5,,,100103,igb0,match,block,in,4,0x0,,56,64556,0,DF,6,tcp,52,93.220.211.99,212.168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS Oct 20 17:48:38 gw02 filterlog: 5,,,100103,igb0,match,block,in,4,0x0,,56,64557,0,DF,6,tcp,52,93.220.211.99,212.168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS Oct 20 17:48:42 gw02 filterlog: 5,,,100103,igb0,match,block,in,4,0x0,,56,64558,0,DF,6,tcp,52,93.220.211.99,212.168.31.112,52498,80,0,FA,3467799626,3453635053,347,,nop;nop;TS Why? Normaly all traffic can pass the interfaces. Main problem is that I have 1% packetloss when it pass the Intenet connection to my Upstream. I have a second firewall configured identical and here is no packetloss. I Changed all cables and so… I am absolutely without any glue what can cause such a problem. Could it be a problem that I have serval different networks applied on one Interface without vlans? I Realy don’t know what I can do. This issue is very hard and all thinks I already tested doesn’t not help to fix the issue. Kernel Messages and logs also looking OK for me. Maybe someone can help me out and give me some ideas Cheers Daniel ___ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support the project with Gold! https://pfsense.org/gold