• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Limiter config disappered

General pfSense Questions
4
19
643
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    michmoor LAYER 8 Rebel Alliance
    last edited by michmoor Feb 14, 2025, 2:32 PM Feb 14, 2025, 2:27 PM

    Ive had very strange problems dealing with limiters in the past and the strangness continues. The symptoms I have after a configured Limiter and applied to a firewall rule is that after a few days or maybe a week, the Internet stops working. Further investigation shows that DNS stops working. Inter-vlan routing is still fine if i try to access resources using IP instead of DNS.

    Another symptom is during troubleshooting if i see what is taking up the most CPU resources its always 'if_io_tgg_2' which is traffic related. See below.
    🔒 Log in to view

    Right away once i saw all of these issues i knew this was related to my Limiter i configured a week ago. So the first step is just delete the limiter. To my surprise.....The configuration is gone..

    🔒 Log in to view

    This is extremely odd. When i checked the firewall rule it is applied to it shows that its there.
    I check the config.xml file and its there.

    🔒 Log in to view

    Santiy check of my configuration history shows that no deletions or modifications were done to this limiter after its applied.

    Limiters are causing me a lot of grief but these situations i can reproduce but the problem is that its sporadic when it happens and it takes down the entire network.

    The solution to when the network gets in this state is to pull the power on the firewall. Performing a reboot through the GUI doesn't do anything.

    Firewall: NetGate,Palo Alto-VM,Juniper SRX
    Routing: Juniper, Arista, Cisco
    Switching: Juniper, Arista, Cisco
    Wireless: Unifi, Aruba IAP
    JNCIP,CCNP Enterprise

    M 1 Reply Last reply Feb 14, 2025, 2:55 PM Reply Quote 1
    • M
      michmoor LAYER 8 Rebel Alliance @michmoor
      last edited by michmoor Feb 14, 2025, 2:56 PM Feb 14, 2025, 2:55 PM

      This seems close to my issue. Only different is that i set mine to 50Mbps as you can see from the previous screen shot.

      https://redmine.pfsense.org/issues/15982

      <dnshaper>
      		<queue>
      			<guestnet-upload-50mb>
      				<name>GuestNet-Upload-50Mb</name>
      				<number>2</number>
      				<qlimit></qlimit>
      				<plr></plr>
      				<description></description>
      				<bandwidth>
      					<item>
      						<bw>50</bw>
      						<burst></burst>
      						<bwscale>Mb</bwscale>
      						<bwsched>none</bwsched>
      					</item>
      				</bandwidth>
      				<enabled>on</enabled>
      				<buckets></buckets>
      				<mask>none</mask>
      				<maskbits></maskbits>
      				<maskbitsv6></maskbitsv6>
      				<delay>0</delay>
      				<sched>wf2q+</sched>
      				<aqm>droptail</aqm>
      				<ecn></ecn>
      			</guestnet-upload-50mb>
      			<guestnet-download-50mb>
      				<name>GuestNet-Download-50Mb</name>
      				<number>1</number>
      				<qlimit></qlimit>
      				<plr></plr>
      				<description></description>
      				<bandwidth>
      					<item>
      						<bw>50</bw>
      						<burst></burst>
      						<bwscale>Mb</bwscale>
      						<bwsched>none</bwsched>
      					</item>
      				</bandwidth>
      				<enabled>on</enabled>
      				<buckets></buckets>
      				<mask>none</mask>
      				<maskbits></maskbits>
      				<maskbitsv6></maskbitsv6>
      				<delay>0</delay>
      				<sched>wf2q+</sched>
      				<aqm>droptail</aqm>
      				<ecn></ecn>
      			</guestnet-download-50mb>
      		</queue>
      

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      M 1 Reply Last reply Feb 14, 2025, 3:58 PM Reply Quote 0
      • M
        michmoor LAYER 8 Rebel Alliance @michmoor
        last edited by Feb 14, 2025, 3:58 PM

        Adding one more bit.

        When the limiter malfunctions and the network becomes unstable, CPU is through the roof.
        This is the exact same condition that happened last year when i was trying to troubleshoot this problem. I later figured out it was due to a configured limiter. Once I deleted it all my instability went away.
        Good thing i remembered because those symptoms are back...
        Solution: Delete the limiter all together. But when i went to go do that, its no longer in the GUI.

        🔒 Log in to view

        🔒 Log in to view

        Firewall: NetGate,Palo Alto-VM,Juniper SRX
        Routing: Juniper, Arista, Cisco
        Switching: Juniper, Arista, Cisco
        Wireless: Unifi, Aruba IAP
        JNCIP,CCNP Enterprise

        1 Reply Last reply Reply Quote 1
        • S
          stephenw10 Netgate Administrator
          last edited by Feb 14, 2025, 5:49 PM

          Hmm, so the config file itself never changed?

          Do you have MIM enabled on that system?

          Do you see anything in Diag > Limiter Info?

          M 1 Reply Last reply Feb 14, 2025, 5:54 PM Reply Quote 0
          • M
            michmoor LAYER 8 Rebel Alliance @stephenw10
            last edited by Feb 14, 2025, 5:54 PM

            @stephenw10
            Config file never changed.
            I do have MIM enabled.
            Diag > Limiter says i have no limiters configured. Which is crazy! Even my firewall rule using the Limiter stated it was there (gear icon denoting the advanced options being used). When i went into the firewall rule, the limiter In/Out configuration was set to None.
            Its like it never happened but for sure the limiter was what was causing my connectivity issue.

            I think i am hitting that redmine bug about the disappearing configuration but why at 50Mbps..?

            Firewall: NetGate,Palo Alto-VM,Juniper SRX
            Routing: Juniper, Arista, Cisco
            Switching: Juniper, Arista, Cisco
            Wireless: Unifi, Aruba IAP
            JNCIP,CCNP Enterprise

            1 Reply Last reply Reply Quote 0
            • S
              stephenw10 Netgate Administrator
              last edited by Feb 14, 2025, 6:12 PM

              Doers it return if you reload the ruleset in Status > Filter Reload?

              Does it return if you reboot?

              M 1 Reply Last reply Feb 14, 2025, 6:22 PM Reply Quote 0
              • M
                michmoor LAYER 8 Rebel Alliance @stephenw10
                last edited by Feb 14, 2025, 6:22 PM

                @stephenw10

                Performing a Filter Reload

                🔒 Log in to view

                Sadly, the Limiters configuration is not present in the GUI.

                I don't want to restart the firewall now that its working but i don't think it will help in this case (could be wrong tho)

                Firewall: NetGate,Palo Alto-VM,Juniper SRX
                Routing: Juniper, Arista, Cisco
                Switching: Juniper, Arista, Cisco
                Wireless: Unifi, Aruba IAP
                JNCIP,CCNP Enterprise

                1 Reply Last reply Reply Quote 0
                • S
                  stephenw10 Netgate Administrator
                  last edited by Feb 14, 2025, 6:30 PM

                  Do they exist in /tmp/config.cache?

                  M 1 Reply Last reply Feb 14, 2025, 6:35 PM Reply Quote 0
                  • M
                    michmoor LAYER 8 Rebel Alliance @stephenw10
                    last edited by Feb 14, 2025, 6:35 PM

                    @stephenw10 Yes sir

                    🔒 Log in to view

                    Firewall: NetGate,Palo Alto-VM,Juniper SRX
                    Routing: Juniper, Arista, Cisco
                    Switching: Juniper, Arista, Cisco
                    Wireless: Unifi, Aruba IAP
                    JNCIP,CCNP Enterprise

                    1 Reply Last reply Reply Quote 0
                    • P
                      provels
                      last edited by Feb 14, 2025, 6:35 PM

                      Just spitballing, but could it be a browser/browser cache issue? Try another browser, another machine? 🤷

                      Peder

                      MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                      BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                      M 1 Reply Last reply Feb 14, 2025, 6:39 PM Reply Quote 0
                      • M
                        michmoor LAYER 8 Rebel Alliance @provels
                        last edited by Feb 14, 2025, 6:39 PM

                        @provels nothing is off the table.

                        I just tried FF and the problem is still there.

                        Hate to say it again but this looks like that redmine bug i noted above. Limiter just disappears after a reboot. The only difference is that the OP was setting a high limit (~4Gbps) while i am using 50Mbps

                        Firewall: NetGate,Palo Alto-VM,Juniper SRX
                        Routing: Juniper, Arista, Cisco
                        Switching: Juniper, Arista, Cisco
                        Wireless: Unifi, Aruba IAP
                        JNCIP,CCNP Enterprise

                        1 Reply Last reply Reply Quote 0
                        • S
                          stephenw10 Netgate Administrator
                          last edited by Feb 14, 2025, 7:01 PM

                          I would think that rebooting to make sure the Limiters are loaded from the config as expected should be the next step if you can.

                          1 Reply Last reply Reply Quote 0
                          • M
                            marcosm Netgate
                            last edited by Feb 14, 2025, 11:01 PM

                            Thanks for the report. I've opened a redmine for this here https://redmine.pfsense.org/issues/16051 and will post a workaround there later.

                            M 1 Reply Last reply Feb 14, 2025, 11:05 PM Reply Quote 0
                            • M
                              michmoor LAYER 8 Rebel Alliance @marcosm
                              last edited by michmoor Feb 14, 2025, 11:07 PM Feb 14, 2025, 11:05 PM

                              @marcosm dont think that redmine is relevant here, no?

                              edit:
                              You mean this one. https://redmine.pfsense.org/issues/16051

                              So its something to do with MIM enabled. Very interesting. Is there a commitID i can try to test?

                              Firewall: NetGate,Palo Alto-VM,Juniper SRX
                              Routing: Juniper, Arista, Cisco
                              Switching: Juniper, Arista, Cisco
                              Wireless: Unifi, Aruba IAP
                              JNCIP,CCNP Enterprise

                              M 1 Reply Last reply Feb 14, 2025, 11:12 PM Reply Quote 0
                              • M
                                marcosm Netgate @michmoor
                                last edited by Feb 14, 2025, 11:12 PM

                                @michmoor Not yet - I need to work on it further on Monday.

                                M 1 Reply Last reply Feb 14, 2025, 11:13 PM Reply Quote 1
                                • M
                                  michmoor LAYER 8 Rebel Alliance @marcosm
                                  last edited by Feb 14, 2025, 11:13 PM

                                  @marcosm no problem. Enjoy the weekend.

                                  Firewall: NetGate,Palo Alto-VM,Juniper SRX
                                  Routing: Juniper, Arista, Cisco
                                  Switching: Juniper, Arista, Cisco
                                  Wireless: Unifi, Aruba IAP
                                  JNCIP,CCNP Enterprise

                                  1 Reply Last reply Reply Quote 0
                                  • M
                                    marcosm Netgate
                                    last edited by Feb 19, 2025, 1:21 AM

                                    I've updated the redmine with additional info that you can test out if you'd like.

                                    M 1 Reply Last reply Feb 24, 2025, 4:16 PM Reply Quote 0
                                    • M
                                      michmoor LAYER 8 Rebel Alliance @marcosm
                                      last edited by michmoor Feb 24, 2025, 4:17 PM Feb 24, 2025, 4:16 PM

                                      @marcosm

                                      Confirmed that once i applied the PHP code the limiters came back (no reboot needed) and can be applied.

                                      Got this notice as well.

                                      🔒 Log in to view

                                      If i reboot my firewall again, do i have to re-apply this PHP code?

                                      25.03 i take it has the perm fix.

                                      Firewall: NetGate,Palo Alto-VM,Juniper SRX
                                      Routing: Juniper, Arista, Cisco
                                      Switching: Juniper, Arista, Cisco
                                      Wireless: Unifi, Aruba IAP
                                      JNCIP,CCNP Enterprise

                                      1 Reply Last reply Reply Quote 1
                                      • S
                                        stephenw10 Netgate Administrator
                                        last edited by stephenw10 Feb 24, 2025, 4:21 PM Feb 24, 2025, 4:21 PM

                                        No, patches survive a reboot. They may not survive an update but, yes, this would be in 25.03 anyway so you shouldn't need to do anything.

                                        1 Reply Last reply Reply Quote 1
                                        4 out of 19
                                        • First post
                                          4/19
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.