Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    frozen pfsense, administration interface, openvpn...

    Scheduled Pinned Locked Moved CE 2.7.0 Development Snapshots (Retired)
    19 Posts 4 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG
      Gertjan @rds25
      last edited by

      @rds25 said in frozen pfsense, administration interface, openvpn...:

      Can you tell me the procedure to know the reason?

      At a distance with no connection ?
      Not that I know.

      If you can access the device, console/SSH into it and check the logs. That why they are there.
      Still, a hardware failure, or some power spike failure doesn't produce any logs, the machine just locks up.
      Use option 11 to restart the webConfigurator - and check the logs for good startup.
      Re try the GUI.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      R 1 Reply Last reply Reply Quote 0
      • R
        rds25 @Gertjan
        last edited by rds25

        @gertjan
        Hello,

        Nslookup revolver - OK
        ping - OK
        Access internet - OK
        access to webconfigurator on LAN - KO
        Access to OpenVPN on WAN and LAN - KO

        I have not enabled SSH access and I have no screen
        I will have to reboot in any case, I have a 502 Bad Gateway nginx. on IP PFsense.

        However, I don't think it's just the web configuration service, because I can't connect to the OpenVPN either, or is it related to the webconfigurator?

        I saw the logs, but I'm not sure where. in any case hardware side everything is OK.

        edit:
        In the log I have 6 files system.log Gz :
        example:
        Dec 26 17:15:16 check_reload_status 404 Could not connect to /var/run/php-fpm.socket
        4ba1be1d-5fcf-4c39-b50c-0f434c534fff-image.png

        Do you have a command to extract from the logs the critical errors related to the webgui and OpenVPN which falls?

        The oldest system log I have dates back not even an hour:
        8a113004-6b52-4700-838b-0e2c73574a18-image.png
        Impossible to have the logs of the day...
        872d4ae0-c107-47fc-9526-1a6713f065b9-image.png
        helpme :'(

        GertjanG 1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan @rds25
          last edited by

          @rds25 said in frozen pfsense, administration interface, openvpn...:

          I have not enabled SSH access and I have no screen

          For later : "never leave home without it". But a console access is also good.

          @rds25 said in frozen pfsense, administration interface, openvpn...:

          The oldest system log I have dates back not even an hour:

          Look at your first image.
          During the same second '40' you have many identical lines telling that PHP isn't running.
          pfSense panics because it needs PHP to do some maintenance tasks, and of course, PHP is used together with nginx, the web server, to handle the GUI.
          So log files are filled up very fast, and rotated as soon as they are 'full'. Which happens very fast right now.

          Btw : what happens here :

          8ae49af6-1d2d-4ef5-9fb3-2cf86392e2a6-image.png

          Is this just an isolated case ? Did you attached the LAN cable ?

          @rds25 said in frozen pfsense, administration interface, openvpn...:

          Do you have a command to extract from the logs

          Also : the gateway 502 error means to me : nginx, the web server is running, but not the PHP part.

          Normally, you would run
          tail -f /var/log/system.log
          in SSH sessions,
          and you use option 11 in the other to retestart PHP + nginx.

          Now, use option 11, and then go to 8, and paste
          ee /var/log/system.log
          (ee is an text editr never used ee myself, prefer nano, but that editor has to be installed as a manually as a freebsd/pfSense using "pkg ..." )

          OpenVPN is start by the same web server + PHP. So, when the GUI is back online, OpenVPN will most probably also start working again.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          1 Reply Last reply Reply Quote 0
          • R
            rds25
            last edited by

            Is this just an isolated case ? Did you attached the LAN cable ?

            Unfortunately no, this is not an isolated case, I have to restart the router almost every day.

            For the cable, I'm not at home and the only PC connected to the lan interface is off.

            I activated SSH like that when I come back if PHP is dead without explanation I paste the logs to you.

            GertjanG 1 Reply Last reply Reply Quote 0
            • Cool_CoronaC
              Cool_Corona
              last edited by

              Can you pls. check if you have any kind of power management on the pfsense machine?

              It could be a NIC going into hybernation.

              R 1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan @rds25
                last edited by

                @rds25 said in frozen pfsense, administration interface, openvpn...:

                the only PC connected to the lan interface is off.

                Poor router firewall. It needs two interfaces to exist, and you disable one 😢 ?
                Maybe it works just fine, but I'm not a member of the club that tries to run a router with one or even less interfaces. As it makes no sense.
                What about adding a switch between that one PC and pfSense ?
                At least pfsense will have its two NIC up all the time.

                Btw : this is just me thinking out loud. Dono what happens when LAN goes away. Never tried that. If LAN goes away, might as well shut down pfSense all together.

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                R 1 Reply Last reply Reply Quote 0
                • R
                  rds25 @Cool_Corona
                  last edited by

                  @cool_corona
                  indeed if PFsense attach services on an int which goes into hibernation, this is a problem.

                  1 Reply Last reply Reply Quote 0
                  • R
                    rds25 @Gertjan
                    last edited by rds25

                    @gertjan

                    Indeed, Pfsense needs two interfaces.
                    I have a Wan a Lan and two other interfaces used for servers.
                    The Lan interface is only used to manage the firewall in my case.
                    So, if the interface has a hibernation option, I will not add a switch which is not very ecological, just to have a UP port to look pretty.

                    In the case of figure, if the Lan Switch is down that to crash the firewall by domino effect?
                    Why not link Pfsense’s vital services to a virtual interface??

                    GertjanG 1 Reply Last reply Reply Quote 0
                    • GertjanG
                      Gertjan @rds25
                      last edited by

                      @rds25 said in frozen pfsense, administration interface, openvpn...:

                      which is not very ecological

                      I fully agree.
                      Your pfSense also agrees : a frozen pfSense .... what about removing the power cord ?
                      With just the WAN active, pfSense will check every 12 hours if there is a package update.
                      It will sync NTP.
                      And according to the resolver settings, keep the DNS cache up to date.
                      I mean : what's that good for ?

                      Still, now serious : it should work with LAN going down = no carrier.
                      If it works well if the NIC device goes into sleep mode : that's more a hardware question, like : does the driver support that ? The OS ? pfSense ?
                      It's not a common scenario.

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      R 1 Reply Last reply Reply Quote 0
                      • R
                        rds25 @Gertjan
                        last edited by rds25

                        @gertjan

                        now that the cause is identified.
                        solution 1: connect a switch to the port called LAN which I only use to configure the fw.

                        solution 2: does pfsense offer a function to deactivate hibernation.

                        ps: I have 2.5gbps ports that only work with unstable 2.7.0.

                        fireodoF 1 Reply Last reply Reply Quote 0
                        • fireodoF
                          fireodo @rds25
                          last edited by

                          @rds25 said in frozen pfsense, administration interface, openvpn...:

                          solution 2: does pfsense offer a function to deactivate hibernation.

                          In my knowledge hibernation should be turned off in the BIOS of the machine ...

                          Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                          SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                          pfsense 2.8.0 CE
                          Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                          R 1 Reply Last reply Reply Quote 0
                          • R
                            rds25 @fireodo
                            last edited by

                            @fireodo

                            I only "disabled HCPI hibernation" but if I'm not mistaken, it's for the general sleep mode of the machine and not of one or more interfaces?

                            fireodoF 1 Reply Last reply Reply Quote 0
                            • fireodoF
                              fireodo @rds25
                              last edited by

                              @rds25 said in frozen pfsense, administration interface, openvpn...:

                              @fireodo

                              I only "disabled HCPI hibernation" but if I'm not mistaken, it's for the general sleep mode of the machine and not of one or more interfaces?

                              Power management for individual interfaces is specifically to the interface hardware - you have to dig deep if you want to manipulate that (AFAIK)

                              Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                              SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                              pfsense 2.8.0 CE
                              Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                              R 1 Reply Last reply Reply Quote 0
                              • R
                                rds25 @fireodo
                                last edited by

                                @fireodo

                                So to summarize I will plug a switch on the port to force the lifeline.
                                And I’ll tell you again if the workaround works.

                                fireodoF 1 Reply Last reply Reply Quote 0
                                • fireodoF
                                  fireodo @rds25
                                  last edited by

                                  @rds25 said in frozen pfsense, administration interface, openvpn...:

                                  So to summarize I will plug a switch on the port to force the lifeline.

                                  That could be a workaround. If you dont mind - what hardware (machine) are we talking about?

                                  Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                                  SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                                  pfsense 2.8.0 CE
                                  Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                                  R 1 Reply Last reply Reply Quote 0
                                  • R
                                    rds25 @fireodo
                                    last edited by rds25

                                    @fireodo
                                    Good morning,
                                    Don’t worry, it’s a prototype from the future.
                                    All I can say is that the interfaces are "intel i226-v"
                                    Or the norm is hibernating non-active interfaces.

                                    fireodoF 1 Reply Last reply Reply Quote 0
                                    • fireodoF
                                      fireodo @rds25
                                      last edited by

                                      @rds25 said in frozen pfsense, administration interface, openvpn...:

                                      Don’t worry, it’s a prototype from the future.

                                      ... then I hope the Flux capacitor is still OK! 😂

                                      Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                                      SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                                      pfsense 2.8.0 CE
                                      Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                                      R 1 Reply Last reply Reply Quote 1
                                      • R
                                        rds25 @fireodo
                                        last edited by rds25

                                        @fireodo said in frozen pfsense, administration interface, openvpn...:

                                        Flux capacitor

                                        Yeah, doc, but we gotta cool it!
                                        Thank you all for your intelligence of mind, and your responsiveness, long life to pfSense community. 💌

                                        1 Reply Last reply Reply Quote 1
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.