Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    My IPSEC service hangs

    Scheduled Pinned Locked Moved IPsec
    76 Posts 15 Posters 19.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      glreed735 @ablizno
      last edited by

      @ablizno I'll check that when I submit my status output to Netgate. The odd thing is it only recently started, perhaps it is overall load related.

      A 1 Reply Last reply Reply Quote 0
      • A
        auroramus @glreed735
        last edited by

        I have noticed it only occurs once the maximum amount of logs are hit so if set to 2000 and the logs reach that it crashes ipsec.

        G 1 Reply Last reply Reply Quote 0
        • G
          gassyantelope @auroramus
          last edited by gassyantelope

          @auroramus Out of curiosity, where is the log setting you changed? I'm wondering if it is different than what I changed. I tried increasing the log space from 500KB to 20MB and still had the VPNs crash today within a few hours. So unless there is a different setting I missed, I'm thinking it may not be related.

          1 Reply Last reply Reply Quote 0
          • A
            auroramus
            last edited by

            Hi so i go to Status>IPsec>d2727f2a-0186-4574-b96c-728b096b8d6e-image.png > 965f1c34-da01-4a27-bbf0-20c478b574cd-image.png and there you can set the log entries gui log entries i have set to 5 and left retention blank.

            1 Reply Last reply Reply Quote 0
            • M
              mr.ortizx @glreed735
              last edited by

              @glreed735 Hello, I am experiencing this exact same issue, see my log settings.
              674c5d2e-a64d-432c-9be1-f4bbbe5b62bf-image.png

              Have you received a resolution from support?

              1 Reply Last reply Reply Quote 0
              • A
                auroramus
                last edited by

                I do not have a support package in place.

                G 1 Reply Last reply Reply Quote 0
                • G
                  glreed735 @auroramus
                  last edited by

                  @auroramus - Not yet, the first pass through the logs highlighted some issues, but they wanted a larger sample of data to work from pending the next failure.

                  1 Reply Last reply Reply Quote 0
                  • A
                    auroramus
                    last edited by

                    I am no coding expert but it seems like once logs reach maxiumum capacity rather than overwriting the logs it crashes the ipsec service.

                    Thats what it looks like to me.

                    No matter what setting i change it to wether it is a low log count or high it maxes then kills service and unless you restart it will not work.

                    1 Reply Last reply Reply Quote 0
                    • A
                      auroramus
                      last edited by

                      once i clear the logs i manage to go past the screen above i mentioned of collecting ipsec status info and see my connection but when you hit connect it attemps and stops doesnt do anything only way to get them connected back is restart

                      1 Reply Last reply Reply Quote 0
                      • A
                        auroramus
                        last edited by

                        i also found this post;

                        This might be entirely normal behaviour; IPSec and many other forms of VPN tunnels connect only when there is traffic to transmit.
                        Take for example you have an 8 hour lifetime on the IKE (Phase 1) tunnel. The tunnel will connect upon some traffic being transmitted down the tunnel and will always terminate as soon as 8 hours has passed since it came up. Only if packets are still trying to be sent down the tunnel will the tunnel come back up again and continue transmitting traffic for another 8 hours. The down and up happens very quickly and packets may not even be lost. This is for security reasons to refresh the security associations.
                        Some people choose to run a ping or similar constantly down the tunnels so it always looks to be connected except for the brief milliseconds to reassociate. I find this to be generally unnecessary.

                        abliznoA G 2 Replies Last reply Reply Quote 0
                        • abliznoA
                          ablizno @auroramus
                          last edited by

                          @auroramus were you ever able to run netstat -Lan and provide the output when all your tunnels are down?

                          1 Reply Last reply Reply Quote 0
                          • G
                            gassyantelope @auroramus
                            last edited by

                            @auroramus The behavior occurring is definitely not normal. I understand what that post is saying and completely agree that is normal IPsec behavior. The issue here is completely different though. The tunnels will never come back up once they all go down. I can ping, send data another way, etc., and they won't ever come back up until a restart is performed.

                            I've had multiple cases where I had active connections over the tunnel (sending data the whole time) and then the issue occurs and all tunnels go down. This has occurred way before the default 8 hour life span (sometimes within an hour or two).

                            1 Reply Last reply Reply Quote 0
                            • A
                              auroramus
                              last edited by

                              @gassyantelope Yes 100% the behaviour is wrong.

                              as it seems to crash the service. and this shouldnt happen.

                              1 Reply Last reply Reply Quote 0
                              • M
                                mr.ortizx
                                last edited by

                                I just paid for Enterprise support and I was told the following:

                                "Hello,

                                Unfortunately, this is a somewhat rare issue that has not been solved yet. It is much less prevalent in pfSense CE 2.5.2, 2.7, and pfSense Plus 22.05. There aren't any workarounds currently, so rolling back or upgrading are the only steps you can currently take to mitigate the issue. You may track the issue here:

                                https://redmine.pfsense.org/issues/13014
                                "
                                I hope this helps you guys. event though redmine says all tunnels continue to operate normally, Netgate support mentioned that they also see instances where all tunnels will drop which is the case for all of us.

                                A G 2 Replies Last reply Reply Quote 0
                                • A
                                  auroramus @mr.ortizx
                                  last edited by auroramus

                                  @mr-ortizx really appreciate you letting us know.

                                  1 Reply Last reply Reply Quote 0
                                  • A
                                    auroramus
                                    last edited by

                                    I have updated to 2.7 i will keep you guys updated.

                                    1 Reply Last reply Reply Quote 1
                                    • G
                                      gassyantelope @mr.ortizx
                                      last edited by

                                      @mr-ortizx Thanks man! At least we finally got an official response from them. I'm gonna do what @auroramus did and update to 2.7 as well to see if it helps at all. It can't hurt at this point.

                                      M 1 Reply Last reply Reply Quote 1
                                      • M
                                        mr.ortizx @gassyantelope
                                        last edited by

                                        @gassyantelope @auroramus Please let me know how it went after upgrading to the version 2.7

                                        abliznoA 1 Reply Last reply Reply Quote 0
                                        • A
                                          auroramus
                                          last edited by

                                          Hi Guys

                                          So far so good with 2.7 have not had a single drop in the tunnels for days now soo ye give it a go and let me know.

                                          A 1 Reply Last reply Reply Quote 0
                                          • A
                                            auroramus @auroramus
                                            last edited by auroramus

                                            I have been running 2.7 since 30th June and i have not had a single blip.

                                            Let me know how you guys get on.

                                            G 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.