Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Problem with inter VLAN Connections

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    14 Posts 2 Posters 888 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sysadminfromhell
      last edited by

      Hello everyone,

      I switched my Intel X550-T2 to an X710-T4L since this change my inter vlan communication or vlan communication in general is instable.
      ssh connections, or tcp connection in general, gets reset sometimes.
      In a packet trace it looks like the dst pc reset the connection but on the other side the connection stays open until the service says timeout.
      So this isnt the case, the pfsense somehow resets the connection but doesnt see it?

      Sometimes in a call /ms teams) or some sort the audio/video stutters also since this change.

      Is there any way to troubleshoot that?

      Ah in the vlan the connections are stable, so if I open a ssh or a tcp connection, to the pfsense for example, nothing happens.
      Any help is appreciated.

      Setup:

      ixl2 - LAN 192.168.178.1/24 - into MikroTik Switch 10G FC off
      ixl3 - VMNET 172.16.24.1/24 - into MikroTik Switch 10G FC off
      ixl3.100 - GUESTWLAN 172.16.23.1/24
      ixl3.30 - LAB 192.168.30.1/24
      Access Point located in ixl3.100 and ixl2 - into MikoTik Switch 1G FC auto

      Kind regards,

      1 Reply Last reply Reply Quote 0
      • S
        sysadminfromhell
        last edited by

        OKAy, I found the problem: the state - somehow - gets exceeded very fast so that the TCP:A flag is not allowed anymore.
        I Try to reboot at first and then try to figure out to make the states waiting times a bit higher. All is default but this is weird.

        1 Reply Last reply Reply Quote 0
        • S
          sysadminfromhell
          last edited by

          Okay I really do need the help of the community here:
          I really cant find any issue with my routing or why the state gets stale so fast.

          Here i Tried to find the issue:

          First I can open an ssh connection, but after 20 Seconds the Flag doesnt get accepted anymore even the Rule is build to accept any TCP Flag
          8016a33a-1ff6-40ab-aad9-2ac0d4dab9eb-image.png
          b551f22c-c599-49d8-ab5d-bdbdf571af36-image.png
          I really cant find an issue with the routing or some sort of, maybe its a flag configuration but the optimazation options are the same as before: Normal
          dfe7205c-ffdf-4d61-92dc-d3da97879c56-image.png
          same as the State Timeouts:
          8eea8bc1-6f82-4b5e-ac22-e7bcf55a24a2-image.png
          Nothing fits with this 20 Seconds, the packet capture shows that its not 20 Seconds but 10 but even that makes no sense.

          P 1 Reply Last reply Reply Quote 0
          • P
            Popolou @sysadminfromhell
            last edited by

            @sysadminfromhell Are you running any part of it through a VM instance?

            S 1 Reply Last reply Reply Quote 0
            • S
              sysadminfromhell @Popolou
              last edited by

              @Popolou no the pfsense is Baremetal but I found that the driver which currently get shipped with pfsense should be broken with the x710. The card is not very populated right now because its hard to get it cheap but I guess this should be the case here maybe. I try ti get more information about it to find a way to troubleshoot that.
              https://forum.netgate.com/topic/162333/intel-x710-issues/36

              P 1 Reply Last reply Reply Quote 0
              • P
                Popolou @sysadminfromhell
                last edited by

                @sysadminfromhell Under System -> Advanced -> Networking towards the bottom under Network Interfaces, can i ask what do you have ticked/unticked?

                S 1 Reply Last reply Reply Quote 0
                • S
                  sysadminfromhell @Popolou
                  last edited by

                  @Popolou as before with the x550:
                  e5526d6b-7957-4f12-9641-5b22e5e1f4af-image.png

                  P 1 Reply Last reply Reply Quote 0
                  • P
                    Popolou @sysadminfromhell
                    last edited by

                    @sysadminfromhell Those seem correct. I had very similar issues (posted about it) and noticed some of the same symptoms. Needed to remove all hardware offloading to restore functionality. Have you disabled the checksum offloading and tested? I've had mixed results with this on an x710 too.

                    S 3 Replies Last reply Reply Quote 0
                    • S
                      sysadminfromhell @Popolou
                      last edited by

                      @Popolou I did not check that, but I can test it and see if this works. I Keep you updated

                      1 Reply Last reply Reply Quote 0
                      • S
                        sysadminfromhell @Popolou
                        last edited by

                        @Popolou unfurtanatly its the same problem:
                        f6a1aa65-a727-43e7-b926-7183b8ad2ecc-image.png

                        I now try to enable all the offload and see if this fixes it.
                        If not, maybe I need and developer to look at it or give me a hint to troubleshoot it more. Maybe I need the new drivers?

                        S 1 Reply Last reply Reply Quote 0
                        • S
                          sysadminfromhell @sysadminfromhell
                          last edited by

                          @sysadminfromhell Even here the same issue:

                          ad5c42dc-55a7-4a8c-b8c2-69fdb3300d43-image.png
                          2cd2b99c-8eb8-469d-84a0-cb372bf6ad86-image.png

                          S 1 Reply Last reply Reply Quote 0
                          • S
                            sysadminfromhell @sysadminfromhell
                            last edited by

                            I will buy a new x550 and replace it once again if not someone has a Idea (driver update or some sort of trick). I just need to inform netgate before because if I change my network card the ndi changes too.

                            1 Reply Last reply Reply Quote 0
                            • S
                              sysadminfromhell @Popolou
                              last edited by

                              @Popolou So I pciked up a x550 locally to replace the broken one and the x710 which appearently doesnt work properly and see there: "almost" no problems. I guess somehow the IPSec is broken and the S2S connection to my lab doesnt work properly.

                              P 1 Reply Last reply Reply Quote 0
                              • P
                                Popolou @sysadminfromhell
                                last edited by

                                @sysadminfromhell I suppose it's possible it could have been a cheap/fake x710 giving you the problems. I'd have probably looked at the firewall rules or checked if there was any rate limiting in place but it sounds like the replacement nic has put you right.

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.