Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Seemingly random ethernet link drops, usually at DHCP lease T1

    Scheduled Pinned Locked Moved DHCP and DNS
    16 Posts 2 Posters 533 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Andy142 @Gertjan
      last edited by

      @Gertjan

      In the system logs it's just as if the cable was unplugged and plugged back in.

      I currently have a switch in the middle waiting for another drop out, then I can review the camera footage and see which one it was. I have adjusted the gateway monitoring times to detect short dropouts now since I may not have a link change notification if its the ISP box.

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @Andy142
        last edited by Gertjan

        @Andy142 said in Seemingly random ethernet link drops, usually at DHCP lease T1:

        I can review the camera footage and see which one it was

        The system log, pfSense side, will mention that event, even if it happened during one millisecond.

        If there were no dpinger messages to signal packet loss then it would not activate it's action :

        5b3fb153-a42e-4619-b983-73a2fcf3b395-image.png

        the dpinger action is : pulling down and up the WAN interface so it get re init.

        You could even, for a while, check this "Disable Gateway Monitoring Action" so dpinger would only measure the ICMP latency, and nothing else.

        Btw : the DHCP client on WAN gets an CGNAT IP. The one starting with "100."
        Is this normal ?

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        A 1 Reply Last reply Reply Quote 0
        • A
          Andy142 @Gertjan
          last edited by Andy142

          @Gertjan Thanks for the info, so from what I understand you're saying it could be better to turn off monitoring so any interruption wouldn't pull the interface down to re-init on the pfSense side?

          The 100. IP is normal from my understanding. It's not PPPoE, its IPoE so maybe thats why it looks a little different?

          1 Reply Last reply Reply Quote 0
          • A
            Andy142
            last edited by Andy142

            So I have some results back.

            Since adding a dumb switch in between the ISP box and pfSense I haven't had any link drops. My partner has also noted the internet has been much better compared to how it use to be.

            However..... I am still getting drops on the gateway at the same times as I was seeing the link drop previously, just now the link stays active through the switch. There is also no alignment with the DHCP lease renewal atm so I think I can rule that out. This is really puzzling me. Looking at the switch lights during these events now shows they stay on.

            Gateway Log:
            gateway log.png

            System Log:
            sys log.png

            Gateway Monitoring settings:
            Screenshot 2025-05-02 152402.png

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @Andy142
              last edited by

              @Andy142 said in Seemingly random ethernet link drops, usually at DHCP lease T1:

              Since adding a dumb switch in between the ISP box and pfSense I haven't had any link drops.

              Which means it was the ISP box pulling it's LAN port, the one connected to the pfSense WAN, down.
              Power issue ?
              Is this a modem type device, for example cable modems tend to do this to signal a 'bad uplink'.
              If its a router type, I would consider that behavior as 'not normal'.

              Like a clock : every 30 minutes sharp you the connection drops packets (== the monitor pings ), to re establish 10 a 20 seconds later.
              Welll... what to say ? "Not all ISPs are equal ^^" ?!

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              A 1 Reply Last reply Reply Quote 0
              • A
                Andy142 @Gertjan
                last edited by

                @Gertjan I'm not sure if it's power related.... I have a security camera setup on the switch, pfSense NIC and ISP box. Before adding the switch int he middle the link lights would go out at the same time as the lag spike. Now with the switch in the middle the link lights for both stay active on all 3 devices. I even changed it out to a smart switch to see if that replicated the issue but the lights stayed active.

                I've sent an email to the ISP with the logs for them to investigate.

                1 Reply Last reply Reply Quote 0
                • A
                  Andy142
                  last edited by

                  ISP asked me to take some logs using pingPlotter. You can see a significant lag spike at hop 2.

                  Screenshot 2025-05-05 141609.png

                  GertjanG 1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan @Andy142
                    last edited by

                    @Andy142

                    Something missing : your avaible bandwidth.
                    After all, what happens with ICMP packets when the upstream or downstream "pipe" is full ? They get discard. And that shows up as a rising latency, or even packet loss, and it looks like the connection went 'bad'.
                    But its none of all this : it just queuing = delays.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    A 1 Reply Last reply Reply Quote 0
                    • A
                      Andy142 @Gertjan
                      last edited by

                      @Gertjan Is there a way I can get this? I wasn't using any internet at the time.

                      GertjanG 1 Reply Last reply Reply Quote 0
                      • GertjanG
                        Gertjan @Andy142
                        last edited by Gertjan

                        @Andy142 said in Seemingly random ethernet link drops, usually at DHCP lease T1:

                        I wasn't using any internet at the time

                        Like you as a person ? Maybe.
                        And your devices ? When a PC decides to upgrade to the last 2H24, or your phone has the newest OS version avaible, it won't ask you for permission, it just starts downloading.

                        pfSense can show you what happened when :

                        573fef66-0694-446b-940a-4748aa2f7f63-image.png

                        If no traffic goes ever the WAN at the moment latency started to rise, then ... well, be ready to "never have the answer".
                        As ISPs normally do not reserve your 1 Gbit symmetrical (if that's what you have) just for you.
                        They will rent out the same bandwidth to many of their clients and then they hope you guys won't use their bandwidth all at the same time, because if that happens, while you doing nothing, cellmate will spike.
                        An ISP normally never admits that this happens ^^
                        Read the contract : somewhere you'll find written : 'connection speed is best effort'.

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        A 1 Reply Last reply Reply Quote 0
                        • A
                          Andy142 @Gertjan
                          last edited by

                          @Gertjan Unfortunately no gigabit symmetric connection here. I'm lucky to get 120/8. I'll put a isolated fresh VM with updates disabled overnight to see what happens. Given the every 30 minutes nature of the problem I can't see this being a bandwidth issue.

                          Will see what the ISP comes back with, I have some good data so far.

                          Still interested to see why the ethernet link drops. I disabled gateway monitoring actions and tried again without the switch, still issues.

                          GertjanG 1 Reply Last reply Reply Quote 0
                          • GertjanG
                            Gertjan @Andy142
                            last edited by

                            @Andy142 said in Seemingly random ethernet link drops, usually at DHCP lease T1:

                            Still interested to see why the ethernet link drops. I disabled gateway monitoring actions and tried again without the switch, still issues.

                            Test with the switch in the "WAN line" and "monitoring action" disabled.
                            If then still issues, stop looking : it's the ISP device or ISP connection.

                            No "help me" PM's please. Use the forum, the community will thank you.
                            Edit : and where are the logs ??

                            A 1 Reply Last reply Reply Quote 0
                            • A
                              Andy142 @Gertjan
                              last edited by

                              @Gertjan said in Seemingly random ethernet link drops, usually at DHCP lease T1:

                              n the "WAN line" and "monitoring

                              With or without monitoring actions enabled it's stable when the switch is in the middle.

                              GertjanG 1 Reply Last reply Reply Quote 0
                              • GertjanG
                                Gertjan @Andy142
                                last edited by

                                @Andy142

                                Pretty solid proof then that the ISP device, connected to the pfSense WAN port took down the interface.
                                Afaik : reasons can be : if its a modem type device : they do this to signal down stream a data carrier loss.
                                Bad power.
                                Bad NIC.

                                Most often, these ISP devices have also a GUI. It's time to have a look at, maybe there are details about the loss available.

                                No "help me" PM's please. Use the forum, the community will thank you.
                                Edit : and where are the logs ??

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.