Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Netgate 7100 needing reboot to being internet back

    Scheduled Pinned Locked Moved General pfSense Questions
    16 Posts 5 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      wifi-will
      last edited by

      Hi All.

      I have 2 different sites where the netgate just randomly stops providing internet to all subnets and vlans.

      The internet connection is still live, and the device is still reachable, but a rebooted is needed to bring all the internet back.

      Whilst i know that's not a lot of information, I don't really have much more to provide as I'm not sure where to look as to what might be the issue.

      100 room hotel, 4 or 5 subnets, pretty standard firewall rules, not a crazy network.

      NollipfSenseN R 2 Replies Last reply Reply Quote 0
      • NollipfSenseN
        NollipfSense @wifi-will
        last edited by

        @wifi-will You could provide log when you reboot the device Status > System logs > System > General.

        Do you have access to the GUI when the device is still reachable?

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        W 1 Reply Last reply Reply Quote 0
        • W
          wifi-will @NollipfSense
          last edited by

          @nollipfsense thanks for your reply.

          I had a look at the logs but they are out of range now as it was a few days ago the last time.

          Yeah, we still have access to the GUI when the customers report all internet is off. We perform a standard reboot and it comes back on.

          I do notice this which is curious 22.01-RELEASE (amd64)
          built on Mon Feb 07 16:37:59 UTC 2022
          FreeBSD 12.3-STABLE

          Unable to check for updates

          Unable to check for updates seems concerning

          NollipfSenseN S 2 Replies Last reply Reply Quote 0
          • NollipfSenseN
            NollipfSense @wifi-will
            last edited by

            @wifi-will Have you confirmed that it's not your ISP...it sounds more like your ISP could have been down which would trigger WAN interface been down on the logs.

            pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
            pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

            W 1 Reply Last reply Reply Quote 0
            • W
              wifi-will @NollipfSense
              last edited by

              @nollipfsense yep, confirmed not ISP, still able to access GUI remotely. ISP confirmed uptime aswell

              1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @wifi-will
                last edited by

                @wifi-will said in Netgate 7100 needing reboot to being internet back:

                Unable to check for updates

                Probably unrelated, I'd guess. Could mean DNS on pfSense itself isn't working, or see https://docs.netgate.com/pfsense/en/latest/troubleshooting/upgrades.html#upgrade-not-offered-library-errors. 22.01 should be offering 22.05.

                When the outage happens can you ping out with an internal interface as the source?

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote 👍 helpful posts!

                1 Reply Last reply Reply Quote 0
                • R
                  rcoleman-netgate Netgate @wifi-will
                  last edited by

                  @wifi-will Check Status->Gateways before rebooting next time. If it is offline look at setting the Monitoring IP on the firewall to something that responds 24x7.

                  Ryan
                  Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                  Requesting firmware for your Netgate device? https://go.netgate.com
                  Switching: Mikrotik, Netgear, Extreme
                  Wireless: Aruba, Ubiquiti

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    SteveITS Galactic Empire @rcoleman-netgate
                    last edited by

                    @rcoleman-netgate if the WAN is accessible remotely it’s not a WAN gateway problem…? :)

                    Might be interesting to NAT a port to LAN:443 and see if that doesn’t work.

                    Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                    Upvote 👍 helpful posts!

                    R 1 Reply Last reply Reply Quote 1
                    • R
                      rcoleman-netgate Netgate @SteveITS
                      last edited by rcoleman-netgate

                      @steveits said in Netgate 7100 needing reboot to being internet back:

                      if the WAN is accessible remotely it’s not a WAN gateway problem…? :)

                      you're right, I missed that.

                      Ryan
                      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                      Requesting firmware for your Netgate device? https://go.netgate.com
                      Switching: Mikrotik, Netgear, Extreme
                      Wireless: Aruba, Ubiquiti

                      1 Reply Last reply Reply Quote 1
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by stephenw10

                        It could be a bad default gateway issue though. If the default IPv4 gateway in System > Routing > Gateways is still set to auto set it to the WAN gateway specifically.
                        If you have more than one gateway on the system and the WAN has a brief outage pfSense will switch the default to whatever else is available and that can be something incorrect. Rebooting resets that back to the first entry, usually WAN.

                        Steve

                        W 1 Reply Last reply Reply Quote 1
                        • W
                          wifi-will @stephenw10
                          last edited by

                          @stephenw10 we only have 1 gateway. But there is a /29 assigned to it as well. Not sure how they would relate to that, however. Manual outbound NAT is in place and uses NO NAT to send out the right public IP.

                          dd8aa468-7393-4845-87da-306f9b6ec464-image.png

                          R 1 Reply Last reply Reply Quote 0
                          • R
                            rcoleman-netgate Netgate @wifi-will
                            last edited by

                            @wifi-will I would change the gateway from a {blank} monitoring IP to something that replies to public pings just to play it safe. Google DNS is a good choice as it always replies, does so quickly, and doesn't block pinging IPs.

                            Ryan
                            Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                            Requesting firmware for your Netgate device? https://go.netgate.com
                            Switching: Mikrotik, Netgear, Extreme
                            Wireless: Aruba, Ubiquiti

                            W 1 Reply Last reply Reply Quote 0
                            • W
                              wifi-will @rcoleman-netgate
                              last edited by

                              @rcoleman-netgate thanks Ryan. Ill give that a try. I have also upgrade to 22.05 from 22.01. We had an issue whereby the guest vlan wasn't passing traffic again. I changed the PFSense captive portal idle timeout to 120 mins from 30 mins and saw traffic again. Could these events somehow be related? and is 22.05 pretty stable ?

                              R 1 Reply Last reply Reply Quote 0
                              • R
                                rcoleman-netgate Netgate @wifi-will
                                last edited by

                                @wifi-will 22.05 is quite stable but there are known captive portal issues that are resolved in the pending 23.01 release -- hopefully we will be making that available soon but a timeline is not set yet.

                                The issues with CP have to do with UDP traffic so if that is what you are experiencing I would get the last config you have from 22.01 and back it up, open a ticket at the URL in my signature for the 22.01 firmware, and roll back.

                                You should not use the config from 22.05 on older releases.

                                Ryan
                                Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                Requesting firmware for your Netgate device? https://go.netgate.com
                                Switching: Mikrotik, Netgear, Extreme
                                Wireless: Aruba, Ubiquiti

                                W 1 Reply Last reply Reply Quote 0
                                • W
                                  wifi-will @rcoleman-netgate
                                  last edited by

                                  @rcoleman-netgate Ok well i might roll it back then until 23.1 is out of BETA

                                  1 Reply Last reply Reply Quote 0
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Yes, make sure WANGW is set as default and not auto.

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.