• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

WAN Package Loss

Scheduled Pinned Locked Moved Hardware
23 Posts 5 Posters 1.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    derx05 @viragomann
    last edited by derx05 Feb 11, 2022, 2:12 PM Feb 11, 2022, 2:07 PM

    @viragomann
    Oh I think I forgot the write in the first statement that I don‘t have these problems with the 3100. If it would be the fritzbox it would also cause these problems with the 3100 I think. I will download the logs files on my pc later and post them here after I looked through them!

    1 Reply Last reply Reply Quote 0
    • D
      derx05 @NogBadTheBad
      last edited by derx05 Feb 11, 2022, 2:14 PM Feb 11, 2022, 2:10 PM

      @nogbadthebad Sadly a modern Fritzbox doesn‘t even have a modem mode anymore and cause of our provider I can‘t use another modem. They are a local fiber provider and the Fritzboxes are used for metrics and debugging so I am not allowed to directly plug the WAN Cable from the FritzBox in the pfSense. Thats really sad. Of course I put a static route in the FritzBox and disabled the NAT on pfsense, so PortForwarding works like without a FritzBox in between. Also like I said. With the same settings it worked on the SG 3100… So I am a bit helpless

      1 Reply Last reply Reply Quote 1
      • D
        derx05
        last edited by Feb 11, 2022, 2:47 PM

        So here are the logs!
        I just want to mention, that all logs before 10.02 about 12 o‘clock are useless cause thats where I switched hardware from the ProLiant Server to the 6100. So I think you should look at the logs from this morning, cause we had about 3 packages losses today!
        I looked through them and don‘t think that there are any public IPs or else in so should be safe to post them here!

        logs.zip

        1 Reply Last reply Reply Quote 0
        • S
          stephenw10 Netgate Administrator
          last edited by Feb 11, 2022, 2:56 PM

          30% packet loss like that 'feels' like an IP conflict, especially when it's inside the same subnet.

          I would expect to see that reported in the logs though.

          Steve

          D 1 Reply Last reply Feb 11, 2022, 3:00 PM Reply Quote 0
          • D
            derx05 @stephenw10
            last edited by derx05 Feb 11, 2022, 3:02 PM Feb 11, 2022, 3:00 PM

            @stephenw10
            You mean an IP conflict in the subnet from the FritzBox and the pfSense? Well in this subnet are only 2 devices! The FritzBox and the pfSense. Directly connected via a LAN cable. So I don‘t know how an ip-conflict can be created here. Also again. With the 3100 it worked. I am worried that this is a driver or software related issue, what shouldn‘t happen cause it’s a netgate device

            1 Reply Last reply Reply Quote 0
            • S
              stephenw10 Netgate Administrator
              last edited by Feb 11, 2022, 3:42 PM

              Yes, that's what I mean. 30% loss is massive.

              Something wifi connected maybe?

              It's very unlikely to be a driver issue with the 6100.

              Have you actually swapped back in the 3100 since this started to prove it is still unaffected?

              So you have the WAN MAC spoofed?

              Steve

              D 1 Reply Last reply Feb 11, 2022, 4:07 PM Reply Quote 0
              • D
                derx05 @stephenw10
                last edited by Feb 11, 2022, 4:07 PM

                @stephenw10
                Sometimes it’s about 50%!
                Wifi on the FritzBox is off so no Wifi Connection!
                Yes for the last 2 days before the 6100 arrived I switched back to the 3100 and everything worked fine!
                No I don‘t have the MAC spoofed. When I switch the firewall I change which MAC is the exposed host in the FritzBox.

                1 Reply Last reply Reply Quote 0
                • S
                  stephenw10 Netgate Administrator
                  last edited by Feb 11, 2022, 4:13 PM

                  Hmm, well as I say I would expect numerous entries in the system log if it was an IP conflict.

                  I would be running a packet capture when it happens then. Se if there is anything unusual happening with the traffic.

                  Steve

                  D 1 Reply Last reply Feb 11, 2022, 6:55 PM Reply Quote 0
                  • D
                    derx05 @stephenw10
                    last edited by Feb 11, 2022, 6:55 PM

                    @stephenw10
                    Ok i already did a packet capture this morning while we were experiencing the package loss and couldn‘t find any suspicious traffic but also I have to admit I am not very familiar with Wireshark so could also be possible I miss something.

                    I am not sure if its wise to post the data here cause it contains raw network traffic. On the other side all important traffic is encrypted these days and IPs from public servers can be shared?
                    Shall I just post it here?

                    Also a note to something I said before: Since I disabled promiscious mode in suricata I didn‘t have a loss according to the logs. So maybe it has to something promiscious mode?

                    1 Reply Last reply Reply Quote 0
                    • S
                      stephenw10 Netgate Administrator
                      last edited by Feb 11, 2022, 7:14 PM

                      Hmm, well seems likely though I would not expect it.

                      You can PM me link the cap if you want.

                      1 Reply Last reply Reply Quote 0
                      • D
                        derx05
                        last edited by Feb 14, 2022, 5:55 PM

                        Update: So over the weekend the problem sadly didn't occur again.
                        @stephenw10 As promised I will send you a much longer packet capture again when it should happen again. I din't change any settings so it should be only a matter of time. Also I switched the LAN cable between the Fritzbox and the pfSense again, just to make sure.
                        Will keep you updated here.

                        1 Reply Last reply Reply Quote 1
                        • D
                          derx05
                          last edited by Feb 18, 2022, 3:47 PM

                          So as promised an update:
                          The error occured again twice today.
                          Again no useful logs before the loss starts. I just sent @stephenw10 my logs and a 10 minute long packet capture. If we can't solve the problem with these logs and the capture I honestly don't know what else I could try...

                          1 Reply Last reply Reply Quote 0
                          • N
                            NOCling
                            last edited by NOCling Feb 19, 2022, 8:00 AM Feb 19, 2022, 7:57 AM

                            Can you try monitoring a public IP like 1.1.1.1 for the affected WAN gateway?
                            It could be an upstream interferer on your cable segment. Cable devices can then lose their heads if they lack sync.

                            Netgate 6100 & Netgate 2100

                            D 2 Replies Last reply Feb 19, 2022, 9:37 AM Reply Quote 0
                            • D
                              derx05 @NOCling
                              last edited by Feb 19, 2022, 9:37 AM

                              @nocling With an upsteam interferer you mean a problem on the WAN side? Just for your note: We have fiber, not cable. I don't think an upsteam interferer can happen with fiber or am I wrong? But also worth a shot. I think I will change that when I am back at the company next week

                              1 Reply Last reply Reply Quote 0
                              • D
                                derx05 @NOCling
                                last edited by Feb 21, 2022, 9:46 AM

                                @nocling
                                Today I also changed the monitoring IP but still have the package loss. So I will now reset the 6100 and then set ip back up without restoring the config.

                                1 Reply Last reply Reply Quote 0
                                • D
                                  derx05
                                  last edited by derx05 Feb 26, 2022, 12:26 AM Feb 26, 2022, 12:25 AM

                                  So I hope this will be the last update I will have to write. After a long call with the tech support of our provider I ask for the permission to plug the wan directly in the pfsense. I never liked FritzBoxes and this case gives me one more reason to never buy one again. Since 4 days no more problems! I set the PPPoE connection up in the pfsense, set up the MTU size and vlan and everything just works. I don't know what the FritzBox did, that the connection between the pfSense and the FritzBox got so laggy but I would definetly say it's the FritzBox fault. Someone yesterday also told me it could have been the MTU size. But sadly FritzBoxes don't offer settings for that and I also tried setting the MTU to about 1300 3 weeks ago and it didn't help. So I think this is an issue that will never be solved but honestly I don't care anymore.
                                  I don't expect any more problems the next days so I hope I won't have to write again here.
                                  Also I can't explain why the FritzBox worked with the 3100, which was the reason why we tought the FritzBox couldn't be the cause. Seems I was wrong.
                                  Thanks for all your help!

                                  1 Reply Last reply Reply Quote 1
                                  • S
                                    stephenw10 Netgate Administrator
                                    last edited by Feb 26, 2022, 12:31 AM

                                    Nice result! That's a much nicer setup too.

                                    D 1 Reply Last reply Feb 26, 2022, 12:48 AM Reply Quote 0
                                    • D
                                      derx05 @stephenw10
                                      last edited by Feb 26, 2022, 12:48 AM

                                      @stephenw10 Yes it is indeed. I hate to do something like double NAT with static routes. The next time a provider tries to force me to use a FritzBox I won't sign a contract with them :-)

                                      1 Reply Last reply Reply Quote 1
                                      23 out of 23
                                      • First post
                                        23/23
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                        This community forum collects and processes your personal information.
                                        consent.not_received