• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Upgrade to 2.6.0 causes voip to no longer work and I can't ping the internet

Scheduled Pinned Locked Moved General pfSense Questions
39 Posts 7 Posters 4.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    revengineer @Keithunder
    last edited by revengineer Feb 19, 2022, 12:59 PM Feb 19, 2022, 12:58 PM

    @keithunder said in Upgrade to 2.6.0 causes voip to no longer work and I can't ping the internet:

    why can't I download a 2.5 version which worked?

    2.5.2 is still available. Go to the download page, DO NOT SELECT AN ARCHITECTURE, simply hit download. You end up in a directory that still includes the 2.5.1 and 2.5.2 versions.

    K 1 Reply Last reply Feb 19, 2022, 12:59 PM Reply Quote 0
    • K
      Keithunder @revengineer
      last edited by Feb 19, 2022, 12:59 PM

      @revengineer Excellent thank you

      1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @Keithunder
        last edited by Feb 19, 2022, 7:43 PM

        @keithunder said in Upgrade to 2.6.0 causes voip to no longer work and I can't ping the internet:

        Which of these services can safely go?

        Did you enable pcscd? It's supposed to be disabled by default in 2.6/22.01 because it's rarely needed and had a memory leak in the prior version. If you're not using IPSec you can just stop it.

        As for the others, you'll have to tell us which packages you have installed that you're not using.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        K 1 Reply Last reply Feb 19, 2022, 9:06 PM Reply Quote 0
        • K
          Keithunder @SteveITS
          last edited by Feb 19, 2022, 9:06 PM

          @steveits It don't know what pcscd is if 2.6 had disabled it then I can't see that as the problem it does not appear on my 2.6.0 rig.

          I have set up a test rig with 2.6 and have tried turning services and firewall rules off .. nothing seems to fix my problem

          I am using captive portal and snort .. I am not using open vpn

          I don't know what the other are and if I need them

          S 1 Reply Last reply Feb 19, 2022, 9:21 PM Reply Quote 0
          • S
            SteveITS Galactic Empire @Keithunder
            last edited by Feb 19, 2022, 9:21 PM

            @keithunder Interesting, pcscd is not listed on my 2.6 router after upgrading. Although I had at least stopped it...don't recall if I bothered putting in the patch on that one. If you leave it running check used memory every month or so in case it still has the leak.
            Here's the release note section with the bullet point about it being optional.

            For OpenVPN you probably have a server and client configured. Presumably enabled SNMP and captive portal as well. Bandwidthd is a package to monitor bandwidth usage. The others I think are all defaults. Mine has these, besides a couple packages:

            ntpd NTP clock sync
            dpinger Gateway Monitoring Daemon
            radvd Router Advertisement Daemon
            sshd Secure Shell Daemon
            syslogd System Logger Daemon
            unbound DNS Resolver (instead of Forwarder)

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote 👍 helpful posts!

            K 1 Reply Last reply Feb 20, 2022, 4:08 PM Reply Quote 0
            • K
              Keithunder @SteveITS
              last edited by Feb 20, 2022, 4:08 PM

              @steveits Thank everyone for the responses

              I disabled all the firewall rules except the pass all one and shut down all the non vital services
              I still can't ping 8.8.8.8
              Is there anything I can do to work out why this is happening? I can ping 8.8.8.8 from the pfsense box so the problem must be with pfsense

              I tried installing 2.6.0 from scratch but I could not log into the web interface ... so I gave up :(
              Maybe I will try again :(

              I can't upgrade to 2.6.0 until I have resolved this

              1 Reply Last reply Reply Quote 0
              • S
                stephenw10 Netgate Administrator
                last edited by Feb 20, 2022, 4:20 PM

                Start a ping to 8.8.8.8. Then check Diag > States to make sure the correct states are being opened. You should see a state on the internal interface and a state with NAT on the WAN.

                Steve

                K 1 Reply Last reply Feb 20, 2022, 4:30 PM Reply Quote 0
                • K
                  Keithunder @stephenw10
                  last edited by Feb 20, 2022, 4:30 PM

                  @stephenw10 the states relating to 8.8.8.8 all say 0.0

                  I have no idea what this means though :)

                  S S 2 Replies Last reply Feb 20, 2022, 5:28 PM Reply Quote 0
                  • S
                    SteveITS Galactic Empire @Keithunder
                    last edited by Feb 20, 2022, 5:28 PM

                    @keithunder I don't see where you answered my question about having any limiters configured...? In that other thread limiters seem fine for some but problematic for others.

                    Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                    Upvote 👍 helpful posts!

                    K 1 Reply Last reply Feb 20, 2022, 5:36 PM Reply Quote 0
                    • K
                      Keithunder @SteveITS
                      last edited by Feb 20, 2022, 5:36 PM

                      @steveits I don't think I have any limiters configured.. How would I find out if I had?

                      S 1 Reply Last reply Feb 20, 2022, 5:39 PM Reply Quote 0
                      • S
                        SteveITS Galactic Empire @Keithunder
                        last edited by Feb 20, 2022, 5:39 PM

                        @keithunder Firewall/Traffic Shaper/Limiters, and there would be firewall rules and/or floating rules configured to use them. (in the rule, Advanced Options, In / Out pipe)

                        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                        Upvote 👍 helpful posts!

                        K 1 Reply Last reply Feb 20, 2022, 5:45 PM Reply Quote 0
                        • K
                          Keithunder @SteveITS
                          last edited by Feb 20, 2022, 5:45 PM

                          @steveits Oh yess I don't have any limiters set up and I have disabled all firewall rules except the default ones on the lan the anti lockout one and the allow all are the only ones I have

                          S 1 Reply Last reply Feb 20, 2022, 7:32 PM Reply Quote 0
                          • S
                            SteveITS Galactic Empire @Keithunder
                            last edited by Feb 20, 2022, 7:32 PM

                            @keithunder You do have captive portal though, and there is at least one comment about disabling that fixing connectivity:

                            https://forum.netgate.com/topic/170084/upgrade-21-05-2-to-22-01-no-vlan-internet-conection/10

                            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                            Upvote 👍 helpful posts!

                            K 1 Reply Last reply Feb 20, 2022, 8:29 PM Reply Quote 0
                            • K
                              Keithunder @SteveITS
                              last edited by Feb 20, 2022, 8:29 PM

                              @steveits I have disabled the captive portal

                              1 Reply Last reply Reply Quote 0
                              • S
                                stephenw10 Netgate Administrator @Keithunder
                                last edited by Feb 21, 2022, 3:50 PM

                                @keithunder said in Upgrade to 2.6.0 causes voip to no longer work and I can't ping the internet:

                                the states relating to 8.8.8.8 all say 0.0

                                They exist on both interfaces though and have NAT correctly on WAN? Can we see them?

                                Steve

                                1 Reply Last reply Reply Quote 0
                                • P
                                  Pieter_SA
                                  last edited by Mar 2, 2022, 6:42 AM

                                  Hello

                                  I am also having this issue.
                                  I can confirm that Captive Portal is the cause, and that using "Allowed IP Addresses" or disabling Captive Portal restores SIP calling.

                                  I am not sure if this is caused by VLAN interfaces conbined with Captive Portal because both of my pfsense systems use VLAN for Wireless, and both are affected.

                                  Please let me know if I can provide more information to get this fixed.
                                  Thanks

                                  GertjanG 1 Reply Last reply Mar 2, 2022, 9:22 AM Reply Quote 0
                                  • GertjanG
                                    Gertjan @Pieter_SA
                                    last edited by Mar 2, 2022, 9:22 AM

                                    @pieter_sa said in Upgrade to 2.6.0 causes voip to no longer work and I can't ping the internet:

                                    VLAN interfaces conbined with Captive Portal because both of my pfsense systems use VLAN for Wireless, and both are affected.

                                    VLAN's or not. using Wireless devices, or devices using "cables", the issue stays.
                                    Only TCP passes, no ICMP, no UDP. It looks like it's an ipfw issue, or worse, related so 'something' in FreeBSD 12.3, which means a simple 'patch' can't repair this. These are my thought of course.
                                    If you need a working captive portal, consider going back to 2.5.2.

                                    No "help me" PM's please. Use the forum, the community will thank you.
                                    Edit : and where are the logs ??

                                    1 Reply Last reply Reply Quote 0
                                    • S
                                      stephenw10 Netgate Administrator
                                      last edited by Mar 2, 2022, 2:02 PM

                                      We have discovered the root cause of this now. It should be possible to patch the ipfw ruleset to allow it. https://redmine.pfsense.org/issues/12834

                                      Steve

                                      K GertjanG 2 Replies Last reply Mar 2, 2022, 2:17 PM Reply Quote 1
                                      • K
                                        Keithunder @stephenw10
                                        last edited by Mar 2, 2022, 2:17 PM

                                        @stephenw10 Wow that is brilliant how do I patch? or should I wait till the next version?

                                        I am currently using the backup computer for live

                                        1 Reply Last reply Reply Quote 0
                                        • GertjanG
                                          Gertjan @stephenw10
                                          last edited by Mar 2, 2022, 2:19 PM

                                          @stephenw10

                                          https://redmine.pfsense.org/issues/12834 doesn't contain "patch" info, just the issue itself and a the related forum thread " UDP/ICMP is not working after upgrade to 2.6.0 ".

                                          I'm logged into redmine, but that doesn't show more info.
                                          Is it 'not ready yet' ?
                                          I have a captive portal up and running with several connected clients that are willing to test drive.

                                          No "help me" PM's please. Use the forum, the community will thank you.
                                          Edit : and where are the logs ??

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received