Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS 8000+ms, troubleshooting help

    Scheduled Pinned Locked Moved General pfSense Questions
    75 Posts 4 Posters 9.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator @srytryagn
      last edited by

      @srytryagn you can also dump the data from the file.. Just really need the headers and such.. but just to split it up to post if you have no where else to host it.. splitcap comes to mind.. https://www.netresec.com/?page=SplitCap

      You should also be able to just zip it and split it up that way, 7z can do that really easy.. There is also a truncate option in that wrangler, which can cut out the data of large packets, we just really need to see the headers.

      I just did a quick pcap of wan traffic and fired off a speedtest to make sure it was big.. 226MB, after truncated it down to 18MB.. so something like that could maybe shrink your 7MB file down to size to be able to upload.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      S 1 Reply Last reply Reply Quote 0
      • S
        srytryagn @johnpoz
        last edited by

        @johnpoz I deleted post asking about split, it shrunk in wrangler and I posted it above.

        johnpozJ 1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @srytryagn
          last edited by johnpoz

          @srytryagn ok what is this? 192.168.226.58 trying to talk to stuff and getting told that port is not reachable, etc.

          2024-01-18_150637.jpg

          Where exactly did you sniff this - on the lan interface where your bad guys are? On pfsense.

          So for example in this session.. I see that a syn,ack was sent to

          badf.jpg

          that 226.58 then you gavve what looks like answers back, but then see that seq=29.. that makes no sense they should be in order.. And clearly that 43.x guy never got answer because he is retrans his syn,ack..

          Where exactly was this sniff taken? On pfsense interface?

          edit: what exactly are you trying to run - is this something I could try and duplicate?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          S 1 Reply Last reply Reply Quote 0
          • S
            srytryagn @johnpoz
            last edited by srytryagn

            @johnpoz
            Yes on PC on network 2 running both Apps.
            Pcap is taken from within pfsense webgui (pointed to problematic Lan).
            ICMP is me pining google.com from that same pc.

            I really appreciate your willingness to run it on your end and would happily walk you though how to do that. You will need a wallet address (or donation address), and a partition NVME or SSD with about 200Gb free to run the node and farmer.

            How do want to proceed ?

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @srytryagn
              last edited by johnpoz

              @srytryagn have like 600GB free on my nmve drive, and like 850GB on my 1TB scratch SSD..

              What coin is this? Prob not run it long enough to do anything of worth.. But could I just donate to your wallet?

              Do you have a link to setup/guide - I am really curious on what the connection is suppose to do actually, etc. And also see if it takes down my network ;)

              On a side note - do you have checksums and offloading enabled?

              offload.jpg

              Under advanced networking, what specific nics do you have? Are they realtek?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              S 2 Replies Last reply Reply Quote 0
              • S
                srytryagn @johnpoz
                last edited by

                @johnpoz Will keep this thread to pfsense/networking information for others. Will share info DM.

                1 Reply Last reply Reply Quote 0
                • S
                  srytryagn @johnpoz
                  last edited by

                  @johnpoz opened dm/room with you, please check.

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @srytryagn
                    last edited by

                    @srytryagn saw your chat - so what about these settings for your offloading?

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    S 1 Reply Last reply Reply Quote 0
                    • S
                      srytryagn @johnpoz
                      last edited by

                      @johnpoz Which ones need to be enabled in pfgui?
                      {Running intel quad port NIC, well capable for offload. }

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @srytryagn
                        last edited by johnpoz

                        @srytryagn I would still try disabling them.. Its not going to make it worse.. There have been known issues with offloading. Do what I have set in my picture.

                        You will need to reboot pfsense.. if I find some time tmrw will go through the setup, if not will try over the weekend.. But there is a lot of football on this weekend ;)

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        S 1 Reply Last reply Reply Quote 0
                        • S
                          srytryagn @johnpoz
                          last edited by

                          @johnpoz I have tried configuring hwoffloading as you mentioned, rebooted, and ... same thing, network dead when running apps.

                          johnpozJ 1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator @srytryagn
                            last edited by

                            @srytryagn I have a bunch of stuff going on with real work today.. But I looked at it does seem pretty easy to setup.. Prob do it tmrw before the games start ;)

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            S 2 Replies Last reply Reply Quote 1
                            • S
                              srytryagn @johnpoz
                              last edited by

                              @johnpoz Thought to mention that I am running a pppoe connection from my ISP.
                              Could this be a factor or some setting that is amiss?

                              1 Reply Last reply Reply Quote 0
                              • S
                                srytryagn @johnpoz
                                last edited by

                                @johnpoz Any idea if pppoe passthrough is the potential issue ? Still struggling to find a solution, any input from you or others would be much appreciated.

                                1 Reply Last reply Reply Quote 0
                                • stephenw10S
                                  stephenw10 Netgate Administrator
                                  last edited by

                                  As opposed to having the ISP device doing PPPoE?

                                  There is an MTU reduction due to the overhead unless you can set 'mini-jumbo' frames upstream.

                                  There is a single core restriction running PPPoE on pfSense itself so you can hit a CPU limit without realising it if you don't check the per-core usage.

                                  S 1 Reply Last reply Reply Quote 0
                                  • S
                                    srytryagn @stephenw10
                                    last edited by

                                    @stephenw10 I do not understand what you mean, I am running a ISP combos box pfsense connects through pppoe. Could you expand on your suggestion as it may be helpful -> How do I set 'mini-jumbo' frames upstream ?

                                    Is there any solution to the pppor restriction on pfsense or workwround ?

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      If the ISP router is terminating the PPPoE session then none of that applies. It only applies if that is bridging the PPPoE traffic to pfSense.

                                      If PPPoE is terminated on pfSense then:
                                      https://docs.netgate.com/pfsense/en/latest/hardware/tune.html#pppoe-with-multi-queue-nics

                                      PPPoE adds an 8 byte overhead so to carry the standard 1500B MTU the frames on the parent NIC must be 1508B. Those are referred to as mini-jumbo or baby-jumbo frames (RFC4638).

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.