Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Websites, apps and services randomly dropping out and needing multiple refreshes to reconnect

    Scheduled Pinned Locked Moved General pfSense Questions
    13 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      Djkáťo
      last edited by

      Heyo!
      Recently got a netgate 1100, using it as my main router with my previous provider supplied modem/router in bridge mode to it, and for some reason some websites and services take multiple tries to get results from. I can be playing a game no hickups and google fails to load during it etc. Random websites I haven't accessed before or in the last few hours just take multiple page refreshes to get a result from all while pinging 1.1.1.1 always works. What could the issue be? All I did was set up PPPoE from a fresh start.

      Network layout:
      52a859c7-2630-4bbe-a779-f93ae5ae7017-image.png
      Firewall log example:
      e2d6de9e-6f86-412f-a941-33e38bdc6bf4-image.png
      Similar forum posts:
      default deny rule ipv4

      DerelictD 1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate @Djkáťo
        last edited by

        @djkáťo The first thing I would do is remove all of your infrastructure. Everything but the modem, 1100, and a single workstation/laptop.

        Restore the 1100 to its default configuration and connect the single, known-good, management workstation to the LAN.

        Get on the webgui at 192.168.1.1 and run through the setup wizard, configuring the WAN.

        And test that.

        If it does not work there are far fewer things to look at.

        My hunch is an MTU/MSS issue over the PPPoE.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • D
          Djkáťo
          last edited by

          Thanks for the reply~
          @derelict I did as you suggested. It did help a little on both the single pc plugged directly in and also the whole network in that it doesn't take multiple refreshes now most of the time, but buffering and slow loading are still a big issue.

          My hunch is an MTU/MSS issue over the PPPoE.

          https://kb.netgear.com/19863/Ping-Test-to-determine-Optimal-MTU-Size-on-Router
          according to this test, mine works up to 1465, basically the default. I let those fields empty, so I assume it picks the correct one anyways?

          DerelictD 1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate @Djkáťo
            last edited by

            @djkáťo What is the MTU setting on Interfaces > WAN?

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            D 1 Reply Last reply Reply Quote 0
            • D
              Djkáťo @Derelict
              last edited by

              @derelict I left it blank. c20fbeda-c957-457a-875b-f422c042934a-image.png

              DerelictD 1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate @Djkáťo
                last edited by Derelict

                @djkáťo I would set that MTU to about 1450 and see if that helps. You should be able to go all the way up to about 1492 but I would start smaller.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                D 1 Reply Last reply Reply Quote 0
                • D
                  Djkáťo @Derelict
                  last edited by

                  @derelict I tried from 1450 down to 1300 and nothing improved sadly...

                  1 Reply Last reply Reply Quote 0
                  • D
                    Djkáťo
                    last edited by

                    I've been trying different MTU sizes but they don't change anything sadly. I'm also getting signed out of many applications mid-using them, forgot to mention that symptom. @Derelict

                    DerelictD 1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate @Djkáťo
                      last edited by

                      @djkáťo That doesn't sound like anything a firewall would have anything to do with.

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Do you have a public IPv6 address? pfSense will use it if it can. Clients will usually try to use it if they think they can but if there's some problem with it it will timeout before falling back to v4. That can present symptoms like you describe.

                        Steve

                        D 1 Reply Last reply Reply Quote 0
                        • D
                          Djkáťo @stephenw10
                          last edited by

                          @stephenw10 Thanks for the tip! Tried turning IPv6 completely off, but sadly that wasn't it either. Still have very slow loading times and get signed off every 2 hours or so. I had it previously on DHCPv6.

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            Then I would try running packet capture whilst trying to connect to something that fails and see what's actually happening.

                            1 Reply Last reply Reply Quote 0
                            • D
                              Djkáťo
                              last edited by

                              It seems to have been a DNS issue. The default settings were set to DNS Resolver after factory reset and first setup, which was probably the culprit. I turned it off and turned on the DNS forwarder instead, and now the internet works better than ever!

                              @stephenw10 @Derelict Thanks for your help~ I still don't exactly understand how that was an issue, but it works now. Have a nice day :)

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.