Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unbound is still crashing, at least once daily.

    Scheduled Pinned Locked Moved DHCP and DNS
    11 Posts 4 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • mtarboxM
      mtarbox
      last edited by

      Netgate 2100/22.05 No VLANS, two openVPN clients, pfBlockerNG-devel
      Unbound has been crashing at least once daily, usually after the midnight updates, but with the occasional oddball times as well.
      Prior to the 22.05 update, I did modify the pfblocker.inc file, and included the space as it was crashing far more often. Post 22.05 update, the crashes have been less.
      Our system runs 24/7 as we have ambulances and crews that are out at all times.

      Some of the log from last night.

      Jul 13 00:00:01 php 74992 [pfBlockerNG] Starting cron process.
      Jul 13 00:01:31 kernel pid 81621 (unbound), jid 0, uid 59, was killed: out of swap space
      Jul 13 00:02:00 sshguard 53848 Exiting on signal.
      Jul 13 00:02:00 sshguard 76348 Now monitoring attacks.
      Jul 13 00:02:01 php 75169 servicewatchdog_cron.php: Service Watchdog detected service unbound stopped. Restarting unbound (DNS Resolver)
      Jul 13 00:02:14 php 77530 notify_monitor.php: Message sent to pfsense@.org OK
      Jul 13 00:06:20 kernel pid 9301 (unbound), jid 0, uid 59, was killed: out of swap space
      Jul 13 00:07:01 php 84917 servicewatchdog_cron.php: Service Watchdog detected service unbound stopped. Restarting unbound (DNS Resolver)
      Jul 13 00:07:14 php 86000 notify_monitor.php: Message sent to pfsense@.org OK

      What else can I look at to submit to the forums for a possible solution?

      I did follow the below forum, but it didn't solve my problem as I don't have DHCP mappings checked.

      Re: [Unbound crashes daily]('out of swap space')

      Si vis pacem, para pactum.

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @mtarbox
        last edited by

        @mtarbox "out of swap space" indicates it is running out of memory. What is the memory usage on your router? What packages are installed besides pfBlockerNG? Do you have pfBlockerNG loading lots of feeds? Can you see what's using the memory in Diagnostics/Activity?

        "Message sent to pfsense@.org" looks like an invalid email address was entered to receive notifications?

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote ๐Ÿ‘ helpful posts!

        1 Reply Last reply Reply Quote 0
        • mtarboxM
          mtarbox
          last edited by mtarbox

          @steveits
          the email address is modified. I get daily reports from pfSense just fine.
          currently memory is at 12% of 3397mb.
          edit post update is now at 30% of 3397mb.

          The screen snip is from when I just forced an update.

          Capture.PNG

          Si vis pacem, para pactum.

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @mtarbox
            last edited by

            @mtarbox Unless that's during the update that looks like a lot of CPU usage for pfB. Did you hear about this correction?

            https://forum.netgate.com/topic/173072/high-cpu-usage-after-upgrading-to-22-05/16

            That OISD list is 30.7 MB so could take a long time and a lot of memory to process.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote ๐Ÿ‘ helpful posts!

            mtarboxM 1 Reply Last reply Reply Quote 0
            • mtarboxM
              mtarbox @SteveITS
              last edited by

              @steveits said in Unbound is still crashing, at least once daily.:

              https://forum.netgate.com/topic/173072/high-cpu-usage-after-upgrading-to-22-05/16

              I did the modification to pfblocker.inc before I upgraded to 22.05. Of course I forgot the space, saw no changes, and quickly figured out I missed the space.

              Overall, I need something to block PRON. Supposed medical "professionals" will push limits, plus we have Junior Members here.

              UT1 was turning this 2100 into a slug, and I just saw OISD do the same.

              Si vis pacem, para pactum.

              S lohphatL 2 Replies Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @mtarbox
                last edited by

                @mtarbox said in Unbound is still crashing, at least once daily.:

                I did the modification to pfblocker.inc before I upgraded to 22.05

                Did you check after? I believe if you don't uninstall/reinstall the package pfSense will do so for you...

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote ๐Ÿ‘ helpful posts!

                mtarboxM 1 Reply Last reply Reply Quote 0
                • mtarboxM
                  mtarbox @SteveITS
                  last edited by

                  @steveits
                  $r = explode(' ', $result, 2);
                  looks legit.

                  Si vis pacem, para pactum.

                  mtarboxM 1 Reply Last reply Reply Quote 0
                  • mtarboxM
                    mtarbox @mtarbox
                    last edited by mtarbox

                    Okay, I disabled OISD, enabled one of Chad Mayfields lists. I forced an update cycle and the memory is sitting at 10%, instead of 30%.
                    I will check the logs tomorrow morning, and see if those changes made any impact, and if Service Watchdog had to restart anything on the overnight.

                    @SteveITS thank you for the assistance so far. Obviously networking is not in my job title.

                    Si vis pacem, para pactum.

                    mtarboxM 1 Reply Last reply Reply Quote 0
                    • mtarboxM
                      mtarbox @mtarbox
                      last edited by

                      Everything is looking much better now. No email regarding unbound stopping, service watchdog restarting, etcetera.
                      And this was the system load this morning. Much, MUCH better!

                      cpu_mem_usage.PNG

                      Si vis pacem, para pactum.

                      GertjanG 1 Reply Last reply Reply Quote 0
                      • lohphatL
                        lohphat @mtarbox
                        last edited by

                        @mtarbox said in Unbound is still crashing, at least once daily.:

                        Overall, I need something to block PRON. Supposed medical "professionals" will push limits, plus we have Junior Members here.

                        Cadaver lab not good enough for them?

                        Sheesh...

                        SG-3100 24.11-RELEASE (arm) | Avahi (2.2_6) | ntopng (5.6.0_1) | openvpn-client-export (1.9.5) | pfBlockerNG-devel (3.2.1_20) | System_Patches (2.2.20_5)

                        1 Reply Last reply Reply Quote 0
                        • GertjanG
                          Gertjan @mtarbox
                          last edited by

                          @mtarbox said in Unbound is still crashing, at least once daily.:

                          service watchdog restarting, etcetera

                          Be careful with that one.
                          To keep things close to your profession : what happens when you electro choc a patients heart when it is still beating ? Right, you stop it, and thus you're making things worse.

                          When ever possible, stop using the "service watchdog".

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.