Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SG1100 memory starvation - Unbound not restarting

    Scheduled Pinned Locked Moved General pfSense Questions
    13 Posts 3 Posters 484 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      SteveITS Galactic Empire @michmoor
      last edited by

      @michmoor I don’t see that in the docs. Is there an ISP modem that booted? pfSense would see that as a disconnect.

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote 👍 helpful posts!

      M 1 Reply Last reply Reply Quote 0
      • M
        michmoor LAYER 8 Rebel Alliance @SteveITS
        last edited by

        @SteveITS no ISP modem that booted. Two link down events from what appears to be two ports but nothing on the WAN or LAN side was restarted. Maybe these are internal ports as the 1100 has a switch? I dunno

        Firewall: NetGate,Palo Alto-VM,Juniper SRX
        Routing: Juniper, Arista, Cisco
        Switching: Juniper, Arista, Cisco
        Wireless: Unifi, Aruba IAP
        JNCIP,CCNP Enterprise

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Port3 is WAN port2 is LAN. By default at least.

          Screenshot from 2024-10-12 14-03-03.png

          M 1 Reply Last reply Reply Quote 0
          • M
            michmoor LAYER 8 Rebel Alliance @stephenw10
            last edited by

            @stephenw10
            d3c22937-00ee-4ce8-a21d-454e7a8bebbe-image.png

            So based on my syslog, both WAN and LAN went down?

            Firewall: NetGate,Palo Alto-VM,Juniper SRX
            Routing: Juniper, Arista, Cisco
            Switching: Juniper, Arista, Cisco
            Wireless: Unifi, Aruba IAP
            JNCIP,CCNP Enterprise

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Yes, that's what's logged there. Since it's actually the switch driver reporting that it pretty much has to have happened.

              M 1 Reply Last reply Reply Quote 0
              • M
                michmoor LAYER 8 Rebel Alliance @stephenw10
                last edited by

                @stephenw10 hmm than i suspect something is wrong with the unit.

                One port directly connects to a cable modem.
                The other port directly connects to a switch.
                They both go down at the same time?

                Is there anything else I can check to monitor hardware health?

                Firewall: NetGate,Palo Alto-VM,Juniper SRX
                Routing: Juniper, Arista, Cisco
                Switching: Juniper, Arista, Cisco
                Wireless: Unifi, Aruba IAP
                JNCIP,CCNP Enterprise

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  I assume both those things didn't reboot?

                  It could have been pfSense driving the switch ports to re-link of course. A change to the internal switch config perhaps.

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    michmoor LAYER 8 Rebel Alliance @stephenw10
                    last edited by

                    @stephenw10
                    The modem , pfsense and switch are on the same PDU. So it wasn't a loss of power. By some sort of freak act there could be a fault on two outlets but highly unlikely.
                    No configuration changes have taken place on this unit since 10/6 according to Configuration History.
                    Im back to thinking its perhaps a faulty unit. Replacement here would be a real PITA. Hoping there are some other diagnostics i can perform.

                    Firewall: NetGate,Palo Alto-VM,Juniper SRX
                    Routing: Juniper, Arista, Cisco
                    Switching: Juniper, Arista, Cisco
                    Wireless: Unifi, Aruba IAP
                    JNCIP,CCNP Enterprise

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      Is there anything logged running up to that? Some interface change etc?

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        michmoor LAYER 8 Rebel Alliance @stephenw10
                        last edited by

                        @stephenw10

                        This is the only thing i see prior

                        Oct 11 20:16:00 nyc-fw1-inet sshguard[69504]: Exiting on signal.
                        Oct 11 20:16:00 nyc-fw1-inet sshguard[77474]: Now monitoring attacks.
                        Oct 11 20:35:30 nyc-fw1-inet check_reload_status[666]: Linkup starting $e6000sw0port3
                        Oct 11 20:35:30 nyc-fw1-inet kernel: e6000sw0port3: link state changed to DOWN
                        Oct 11 20:35:31 nyc-fw1-inet php-fpm[20159]: /rc.linkup: Hotplug event detected for WAN(wan) dynamic IP address (4: dhcp)
                        Oct 11 20:35:31 nyc-fw1-inet php-fpm[20159]: /rc.linkup: DEVD Ethernet detached event for wan
                        Oct 11 20:35:33 nyc-fw1-inet syslogd: sendto: Network is down
                        Oct 11 20:35:33 nyc-fw1-inet syslogd: sendto: Network is down
                        Oct 11 20:35:33 nyc-fw1-inet syslogd: sendto: Network is down
                        Oct 11 20:35:33 nyc-fw1-inet syslogd: sendto: Network is down
                        Oct 11 20:35:33 nyc-fw1-inet syslogd: sendto: Network is down
                        Oct 11 20:35:33 nyc-fw1-inet syslogd: sendto: Network is down
                        Oct 11 20:35:33 nyc-fw1-inet syslogd: sendto: Network is down
                        Oct 11 20:35:33 nyc-fw1-inet syslogd: sendto: Network is down
                        Oct 11 20:35:33 nyc-fw1-inet syslogd: sendto: Network is down
                        Oct 11 20:35:33 nyc-fw1-inet syslogd: sendto: Network is down
                        
                        

                        I do see that the LAN side had a Hotplug event as well. Looking at the timestamps the LAN side event happened more or less at the same time as the WAN side.
                        To me this indicates either

                        1. As part of any link-status event, pfSense restarts the internal switch ports
                        2. There was some weird failure on both LAN and WAN side which i honestly don't see happening.
                        3. Other cause not yet known.
                        ][admin@nyc-fw1-inet.moore.lan]/var/log: cat system.log | grep "Hotplug"
                        Oct 11 20:35:31 nyc-fw1-inet php-fpm[20159]: /rc.linkup: Hotplug event detected for WAN(wan) dynamic IP address (4: dhcp)
                        Oct 11 20:35:38 nyc-fw1-inet php-fpm[55571]: /rc.linkup: Hotplug event detected for LAN(lan) dynamic IP address (4: 192.168.70.254, 6: track6)
                        Oct 11 20:35:39 nyc-fw1-inet php-fpm[17116]: /rc.linkup: Hotplug event detected for WAN(wan) dynamic IP address (4: dhcp)
                        Oct 11 20:35:54 nyc-fw1-inet php-fpm[20159]: /rc.linkup: Hotplug event detected for LAN(lan) dynamic IP address (4: 192.168.70.254, 6: track6)
                        

                        Firewall: NetGate,Palo Alto-VM,Juniper SRX
                        Routing: Juniper, Arista, Cisco
                        Switching: Juniper, Arista, Cisco
                        Wireless: Unifi, Aruba IAP
                        JNCIP,CCNP Enterprise

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.