Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Remove pfblocker settings without package installed?

    Scheduled Pinned Locked Moved pfBlockerNG
    26 Posts 5 Posters 714 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • fireodoF
      fireodo @Klaus2314
      last edited by

      @Klaus2314 said in Remove pfblocker settings without package installed?:

      This is the 24.11 by the way with NO blocker installed and just the most basic setup.

      Take a look with top - maybe you can identify wich process is eating CPU ...

      Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
      SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
      pfsense 2.7.2 CE
      Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

      K 1 Reply Last reply Reply Quote 0
      • K
        Klaus2314 @fireodo
        last edited by

        @fireodo acbfa042-fcfe-47d1-8cc8-30dcc210818d-image.png

        fireodoF 1 Reply Last reply Reply Quote 0
        • fireodoF
          fireodo @Klaus2314
          last edited by

          @Klaus2314

          Hmmm ... I cannot see something very unusual ...

          Have you installed all system patches (if any)?

          Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
          SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
          pfsense 2.7.2 CE
          Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

          K 1 Reply Last reply Reply Quote 0
          • K
            Klaus2314 @fireodo
            last edited by

            @fireodo 24.11 has no patches yes

            K fireodoF 2 Replies Last reply Reply Quote 0
            • K
              Klaus2314 @Klaus2314
              last edited by

              @Klaus2314 173fc27b-17a0-4756-827f-2a4524ab5078-image.png

              1 Reply Last reply Reply Quote 0
              • fireodoF
                fireodo @Klaus2314
                last edited by

                @Klaus2314

                OK. Maybe we should ask @stephenw10 to jump in because he knows the 24.11 better than I do ... this seams to be something else than pfBlockerNG trouble ...

                Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                pfsense 2.7.2 CE
                Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

                K 1 Reply Last reply Reply Quote 0
                • K
                  Klaus2314 @fireodo
                  last edited by

                  @fireodo Yeah, the forum seems to be full of posts about excessive CPU usage with 24.11. At the moment 24.11 doesn't seem to be able to run pfblocker on an SG1100. I'll try and roll back to 24.3 somehow and re-install the pfb version that worked with it last.
                  Thanks for chiming in and happy holidays!

                  fireodoF 1 Reply Last reply Reply Quote 0
                  • fireodoF
                    fireodo @Klaus2314
                    last edited by

                    @Klaus2314 said in Remove pfblocker settings without package installed?:

                    Thanks for chiming in and happy holidays!

                    Thank you - for you too!
                    Sorry I could not help more :-(

                    Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                    SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                    pfsense 2.7.2 CE
                    Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

                    K 1 Reply Last reply Reply Quote 0
                    • K
                      Klaus2314 @fireodo
                      last edited by

                      @fireodo No worries. It seems to be the widgets. Got CPU down to 30% by removing all widgets from the dashboard and just adding back system info.

                      fireodoF 1 Reply Last reply Reply Quote 0
                      • fireodoF
                        fireodo @Klaus2314
                        last edited by

                        @Klaus2314 said in Remove pfblocker settings without package installed?:

                        Got CPU down to 30% by removing all widgets from the dashboard and just adding back system info.

                        Yeah, I remember to have read something related to widgets and high CPU load in 24.11 ...

                        Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                        SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                        pfsense 2.7.2 CE
                        Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

                        1 Reply Last reply Reply Quote 0
                        • S
                          SteveITS Galactic Empire @Klaus2314
                          last edited by

                          @Klaus2314 Remove the section(s) for pfB from your config file and restore.

                          If you install packages ensure you have the correct update branch selected. Installing a package for a later version can break things.

                          The posts I’ve seen about high CPU usage are re: dashboard widget updating. Quick workaround is not to view the dashboard. There is also a patch to revert the changes there.

                          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                          Upvote 👍 helpful posts!

                          K 1 Reply Last reply Reply Quote 0
                          • K
                            Klaus2314 @SteveITS
                            last edited by Klaus2314

                            @SteveITS Your hint about the update path did the trick! I was able to roll back to 24.3 and install the pfb version that used to work. Now all is back to normal.
                            I guess 24.11 and pfb is currently not a good idea to run on an SG1100.

                            Thank you for helping!

                            K 1 Reply Last reply Reply Quote 0
                            • K
                              Klaus2314 @Klaus2314
                              last edited by Klaus2314

                              @Klaus2314 Sorry, spoke too early. 24.3 with the 24.3 update path shows the pfblocker version that only runs on 24.11. Any idea how to install 3.2.0_8 instead of the newer 3.2.0_10 which does not run?

                              S S 2 Replies Last reply Reply Quote 0
                              • S
                                SteveITS Galactic Empire @Klaus2314
                                last edited by

                                @Klaus2314 Each update branch has "the current" (for that version) package. So there's not a way to get "some older version" that isn't in the online repos. It has only one place to look.

                                It sounds like you have ZFS on your 1100 so you can just revert to a previous boot environment...?

                                About the only ways pfBlocker can "not run" are needing more than the 1 GB RAM (i.e. big lists) on the 1100 or using CPU (often, processing/updating big lists) so I would try to figure out why you are seeing high usage, with the dashboard not visible. You could try to track down the changes between those two minor versions but I would not expect to see much significant.

                                https://github.com/pfsense/FreeBSD-ports/commits/devel/net/pfSense-pkg-pfBlockerNG
                                https://forum.netgate.com/topic/187767/pfblockerng-3-2-0_09-to-3-2-0_10
                                https://forum.netgate.com/topic/188162/pfblockerng-v3-2-0_10/6

                                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                Upvote 👍 helpful posts!

                                1 Reply Last reply Reply Quote 0
                                • S
                                  smolka_J @Klaus2314
                                  last edited by

                                  @Klaus2314 I have devel version 3.2.0_20 running great on 24.3 but I am on a 5100 with 32Gb

                                  1 Reply Last reply Reply Quote 0
                                  • J
                                    jrey @Klaus2314
                                    last edited by

                                    @Klaus2314

                                    Maybe this?

                                    https://forum.netgate.com/topic/195336/24-03-24-11-concerns/2?_=1734824003103

                                    K 1 Reply Last reply Reply Quote 0
                                    • K
                                      Klaus2314 @jrey
                                      last edited by

                                      @jrey I've finally managed to roll back to 24.3 after 2 days of messing around and re-install pfb 3.2.0_10 from scratch. Now all is dandy again with much more lists active than under 24.11.

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.