Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    random no internet. DNS?

    Scheduled Pinned Locked Moved General pfSense Questions
    9 Posts 4 Posters 843 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      gjkrisa
      last edited by

      hi i need help figuring out how to troubleshoot why i and another site randomly loose connection I have tail scale setup on the remote location and when they tell me there is no internet im able to still connect.

      during this time i noticed some packet loss.
      i have pfsense as main dns the 1.1.1.1 , 8.8.8.8 cloudflare being the fastest after local
      only those two in the general setup.
      what way should I track this to troubleshoot the issue.
      currently just got 100% packetloss on dhcp4 but dhcp6 is rtt .07 rttsd 1.0ms 0% loss

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        When this happens what error do you see on clients trying to connect out? A resolution error?

        Are LAN clients using pfSense for DNS? is pfSense running Unbound (the Resolver) in it's default mode?

        Where are you seeing that packet loss? Against what target IP?

        Steve

        G 1 Reply Last reply Reply Quote 0
        • G
          gjkrisa @stephenw10
          last edited by

          @stephenw10
          Dns is mostly pfsense defaults haven’t changed any clients.
          But I now have google and cloud flare set up ask backup dns plus the ipv6 versions so I have 8 dns servers
          There were no ipv6 dns setup so I added that.
          I was seeing loss on the dashboard gateway.

          Next time it happens Ill see what firewall blocks are mostly happening.

          Setting up graylog and maybe zabbix.

          Just need to know what to look at next time it happens.

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @gjkrisa
            last edited by

            @gjkrisa said in random no internet. DNS?:

            I was seeing loss on the dashboard gateway.

            That's a pretty solid proof that your 'random no Internet' is not related to DNS.

            If you see a 'loss' here :
            7c2f804e-6656-4f15-a3d6-3ac6ddc5535c-image.png
            then say to yourself : even a very small ICMP ('pin') packets can't go up, and back anymore.
            Like talking over a phone line which is momentarily ruptured. That doesn't work out very well.

            So, DNS will start to fail, as visiting web servers with your browser, retrieving your mails, or stream something.

            An Internet connection is pretty resilient, so, when traffic gets lost, it will get re demanded, over and over, up until some time out says : stop. That is the moment the user (you) see errors.

            Btw : check also Status > Monitoring and select Quality left axis, with your WAN interface. It should show a stable line, no losses.

            @gjkrisa said in random no internet. DNS?:

            i have pfsense as main dns the 1.1.1.1 , 8.8.8.8 cloudflare being the fastest after local

            @gjkrisa said in random no internet. DNS?:

            But I now have google and cloud flare set up ask backup dns plus the ipv6 versions so I have 8 dns servers

            1.1.1.1 and whatever else you entered isn't needed / neither used.
            Your resolver is resolving.

            @gjkrisa said in random no internet. DNS?:

            There were no ipv6 dns setup so I added that.

            Your are resolving.
            This means that [the resolver uses the one of these](Root name server). See the list and their location.
            They all have an IPv6 and an IPv6. The list with these IPs are build into the resolver - they never change. They were there since DNS was created, that was probably the second day after the birth of Internet.
            They all are heavily CDNed.
            Be aware : you need to have a working IPv6 connection otherwise you will experience big delays. Every modern OS, and also pfSense, based upon FreeBSD, uses first IPv6 and if that fails, if falls back to IPv4.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            G JonathanLeeJ 2 Replies Last reply Reply Quote 2
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Indeed that sounds like a more general connectivity error. The error shown at the client when this fails should give you more info though.

              1 Reply Last reply Reply Quote 0
              • G
                gjkrisa @Gertjan
                last edited by

                @Gertjan
                Seeing 3% loss not complete also able to log in thru Tailscale but everyone else on the network can’t resolve anything

                JonathanLeeJ 1 Reply Last reply Reply Quote 0
                • JonathanLeeJ
                  JonathanLee @Gertjan
                  last edited by

                  @Gertjan cloudflare is so fast compared to others. I use port 853 also for it.

                  Make sure to upvote

                  1 Reply Last reply Reply Quote 0
                  • JonathanLeeJ
                    JonathanLee @gjkrisa
                    last edited by JonathanLee

                    @gjkrisa traffic shaping drops packets what's your limits you set up? Try Codel queus. If the limit is reaching it will drop packets on tail end. Do you use traffic shaping?

                    Make sure to upvote

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      So clients are unable to resolve anything when this happpens but pfSense itself can? In Diag > DNS Lookup?

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.