Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    update_alias_url_data stalls packet flow

    Scheduled Pinned Locked Moved General pfSense Questions
    19 Posts 2 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • pitchforkP
      pitchfork @stephenw10
      last edited by

      @stephenw10 yes, pf counters patch is applied but it doesn't fix the issue entirely. it still happens on occasion.

      this is the patched kernel i was looking for https://redmine.pfsense.org/issues/12827#note-22. unless this has been superseded by the pf counters patch, in which case I'd have to upgrade to a non stable version. since I can't do that, i will have to figure out a way to disable this reload until 2.7 is out.

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Just how much interruption are you still seeing with the counters patch in place?

        I see nothing here with that.

        There is no 2.6 kernel with those patches in, they were only committed to 2.7. Running a 2.6 kernel with those patches is completely untested. More so than 2.7. By a lot! I would definitely recommend at least testing 2.7 before attempting that. If only to prove they will actually help your situation.

        Steve

        pitchforkP 1 Reply Last reply Reply Quote 0
        • pitchforkP
          pitchfork @stephenw10
          last edited by

          @stephenw10 hmm, i don't have an exact count but I will guess 50-60% less? not enough days have passed since I installed the patch, so even a precise count would be statistically meaningless.

          I don't have pfBlockerNG installed. no Snort/Suricata either. i would like to pause updating this list entirely until 2.7 is stable. since i don't know what is triggering it, i can only remove the list entirely.

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            But what sort of interruption are you seeing? Lose one ping in a ping stream? Completely loss of connectivity?

            pitchforkP 1 Reply Last reply Reply Quote 0
            • pitchforkP
              pitchfork @stephenw10
              last edited by pitchfork

              @stephenw10 my applications require sub second liveliness and they get knocked out for a good 30 to 40 seconds. I wouldn't care if it was just a monitor saying the connection is iffy... the applications are failing to perform and those are the alarms i see every night.

              the uptime monitors (minute resolution) don't even register the downtime.

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Ah, OK. Then that is something different. Even without the patch that delay loading the filter was only ever a few seconds.
                What do you actually see logged at that time?

                pitchforkP 1 Reply Last reply Reply Quote 0
                • pitchforkP
                  pitchfork @stephenw10
                  last edited by pitchfork

                  89b0d050-a3a2-4627-89b3-f673045e2cce-image.png

                  It is possible that it harms performance for 30 to 40 seconds because if the application is offline for a few seconds it has to catch up with the lost time.

                  BUT I have done pings (one per second between 2:15 and 2:20) and there are several failures over that 30-40 sec time span:

                  dd7e90f1-4d58-4899-89d8-87df9a0279a3-image.png

                  the 02:15:02.413719768 can be ignored. it's a random failure. but the cluster from 02:17:45.909412786 to 02:18:36.380112182 is when the outage occurred.

                  PS: any rough idea when 2.7 will ship? as in 1 month? 6 months?

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Not at this time but 22.05, which includes that same fix, is imminent.

                    Steve

                    pitchforkP 1 Reply Last reply Reply Quote 1
                    • pitchforkP
                      pitchfork @stephenw10
                      last edited by

                      @stephenw10 said in update_alias_url_data stalls packet flow:

                      Not at this time but 22.05, which includes that same fix, is imminent.

                      Steve

                      hmmm, I'm inclined to upgrade sooner or later, but the same fix won't solve it... happy to go private with you if you'd like to dig further. thank you very much for all your help!

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        That's not the counters workaround it's the fixes to pf to prevent the delays. Same as 2.7.

                        If you manually the update command: /etc/rc.update_alias_url_data
                        Do you see the same thing?

                        pitchforkP 1 Reply Last reply Reply Quote 0
                        • pitchforkP
                          pitchfork @stephenw10
                          last edited by

                          weird, running /etc/rc.update_alias_url_data manually doesn't show up in the log at all (and no downtime either)

                          good to know, i will look to upgrade. any rough idea when the free enrollment will be over? Happy to be a paying customer, just a solo guy though, budget is tight.

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            Mmm, yeah it seems likely that's just part of something else that is called at that time. Nothing else is logged at that point?

                            pitchforkP 1 Reply Last reply Reply Quote 0
                            • pitchforkP
                              pitchfork @stephenw10
                              last edited by

                              @stephenw10 nada!

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.