New 4200 slows down periodically
-
I recently replaced a community pfsense install with a 4200 appliance. The 4200 is running 24.03-RELEASE. I am still using the dnsmasq forwarder and the ISC DHCP. The appliance will be running fine with fast DNS responses, routing etc. but all the sudden the DNS responses crawl and the webadmin logins take FOREVER. SSH login is the same so I suspect it is a reverse lookup issue? Any change to the configuration that causes the firmware to reload solves the slowdown for a while but then it will occur again in several hours. Has anyone else seen this issue?
-
Do you see anything logged when this happens? In the DNS logs perhaps? Do you see latency on the gateway?
Steve
-
The only thing suspicious in the logs was a lot of ntopng entries. There was no latency in the gateway, only in DNS queries and logins.
This appliance was configure by importing a backup from the community edition. This wasn't a smooth experience as the interface names are different and when VLANs are involved on the LAN interface all kinds of errors happen. I corrected the interface configuration manually and then the appliance booted and seemed to work until this slowdown happened.
It appears that the import didn't properly configure something. I disabled snort, ntopng and the dashboard autoupdate. Since I have made those changes the appliance has been operating properly. If it doesn't slow down again in 24 hours I will start re-enabling things until it breaks.
-
Ah, yes. Disabling ntopng as a test is what I would recommend.