• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

22.05 and pfblocker

Scheduled Pinned Locked Moved pfBlockerNG
8 Posts 3 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    michmoor LAYER 8 Rebel Alliance
    last edited by Jun 28, 2022, 1:31 PM

    Since the upgrade, i noticed that pfblockerng has been taking up quite a few CPU cycles. Performance hasnt been an issue but the cpu idleness has been noticeable. Monitoring usually has me at 98% idle and now I hover around 74.
    I noticed there is a redmine to pfblocker and 22.05 release but are other seeing the same issue?
    Since yesterday im comfortable to say that pfblocker package isnt healthy since the upgrade (have since re-installed).

    From Diagnostics > System Activity

    e9592e24-bd09-4793-8dd1-ed2c5981e6e9-image.png

    All other packages are functioning normally.

    Firewall: NetGate,Palo Alto-VM,Juniper SRX
    Routing: Juniper, Arista, Cisco
    Switching: Juniper, Arista, Cisco
    Wireless: Unifi, Aruba IAP
    JNCIP,CCNP Enterprise

    M 1 Reply Last reply Jun 28, 2022, 1:41 PM Reply Quote 0
    • J jimp moved this topic from General pfSense Questions on Jun 28, 2022, 1:38 PM
    • M
      mcury @michmoor
      last edited by Jun 28, 2022, 1:41 PM

      @michmoor https://redmine.pfsense.org/issues/13156

      dead on arrival, nowhere to be found.

      M 1 Reply Last reply Jun 28, 2022, 2:09 PM Reply Quote 1
      • M
        michmoor LAYER 8 Rebel Alliance @mcury
        last edited by Jun 28, 2022, 2:09 PM

        @mcury Thanks for that. The hotfix in the thread didnt fix my issue, unfortunately.
        IP Block Stats logging is not working and CPU utilization is still high.
        Looks like i have to wait this out. Appreciate your help!

        Firewall: NetGate,Palo Alto-VM,Juniper SRX
        Routing: Juniper, Arista, Cisco
        Switching: Juniper, Arista, Cisco
        Wireless: Unifi, Aruba IAP
        JNCIP,CCNP Enterprise

        M 1 Reply Last reply Jun 28, 2022, 2:10 PM Reply Quote 0
        • M
          mcury @michmoor
          last edited by Jun 28, 2022, 2:10 PM

          @michmoor After applying the patch, you need to restart the pfblocker service.
          It fixed for me, it should fix for you too..

          dead on arrival, nowhere to be found.

          M 1 Reply Last reply Jun 28, 2022, 2:12 PM Reply Quote 1
          • M
            michmoor LAYER 8 Rebel Alliance @mcury
            last edited by Jun 28, 2022, 2:12 PM

            @mcury did restart the service.
            This is what my line looks like. What do you think?

            $r = explode('', $result, 2);

            Firewall: NetGate,Palo Alto-VM,Juniper SRX
            Routing: Juniper, Arista, Cisco
            Switching: Juniper, Arista, Cisco
            Wireless: Unifi, Aruba IAP
            JNCIP,CCNP Enterprise

            S M 2 Replies Last reply Jun 28, 2022, 2:14 PM Reply Quote 0
            • S
              SteveITS Galactic Empire @michmoor
              last edited by Jun 28, 2022, 2:14 PM

              @michmoor There have been other posts such as https://forum.netgate.com/topic/171527/3-1-0-4-high-cpu-load/2. I haven't noticed this on any of our installs/clients, though haven't looked that closely or watched them over time.

              The Redmine note has a space:
              $r = explode(' ', $result, 2);
              not
              $r = explode('', $result, 2);

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              1 Reply Last reply Reply Quote 0
              • M
                mcury @michmoor
                last edited by mcury Jun 28, 2022, 2:15 PM Jun 28, 2022, 2:14 PM

                07c2a434-9006-4b93-bf37-0672a0c0e09c-image.png

                                       if (substr($result, 0, 1) == '@') {
                  
                                                $r = explode(' ', $result, 2);
                

                As you can see in the reddit post, it fixed the CPU usage for others too:
                https://www.reddit.com/r/pfBlockerNG/comments/v7zp72/ip_block_logging_not_working_in_2205_plus_release/

                dead on arrival, nowhere to be found.

                M 1 Reply Last reply Jun 28, 2022, 2:36 PM Reply Quote 0
                • S SteveITS referenced this topic on Jun 28, 2022, 2:15 PM
                • S SteveITS referenced this topic on Jun 28, 2022, 2:15 PM
                • M
                  michmoor LAYER 8 Rebel Alliance @mcury
                  last edited by Jun 28, 2022, 2:36 PM

                  @mcury Confirmed, it was the spacing issue. Fix has resolved my issue.
                  Truly appreciate you guys. @mcury @SteveITS Thanks for your help !

                  Firewall: NetGate,Palo Alto-VM,Juniper SRX
                  Routing: Juniper, Arista, Cisco
                  Switching: Juniper, Arista, Cisco
                  Wireless: Unifi, Aruba IAP
                  JNCIP,CCNP Enterprise

                  1 Reply Last reply Reply Quote 0
                  • M mcury referenced this topic on Jul 31, 2022, 4:01 PM
                  • M mcury referenced this topic on Jul 31, 2022, 4:01 PM
                  • M mcury referenced this topic on Aug 31, 2022, 2:54 PM
                  • M mcury referenced this topic on Aug 31, 2022, 2:54 PM
                  8 out of 8
                  • First post
                    8/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received