Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Racoon stops without any cause

    Scheduled Pinned Locked Moved IPsec
    25 Posts 6 Posters 14.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Metu69salemi
      last edited by

      Kalu:
      if you're sure that p1 & p2 settings are right, then this log doesn't say anything to me.
      It just shows that it's not liking how the racoon itself works(or not) by killing that process. maybe some developers could help reading this log

      1 Reply Last reply Reply Quote 0
      • S
        stemond
        last edited by

        i have same issue :(
        Racoon stop withou causes and drops all IPSEC tunnels.

        i am using Pfsense 2.0 RC3 and it happens without PPTP tunnel

        this is my log, have you any hint ???

        
         Sep 8 09:58:48 	php: /status_services.php: Forcefully reloading IPsec racoon daemon
        [b]Sep 8 09:52:28 kernel: pid 23362 (racoon), uid 0: exited on signal 11 (core dumped)[/b]
        Sep 8 09:50:04 	kernel: arp: 192.168.126.13 moved from 00:01:02:f9:ea:55 to 00:08:02:45:32:42 on le0
        Sep 8 09:30:04 	kernel: arp: 192.168.126.13 moved from 00:01:02:f9:ea:55 to 00:08:02:45:32:42 on le0
        Sep 8 09:30:04 	kernel: arp: 192.168.126.13 moved from 00:08:02:45:32:42 to 00:01:02:f9:ea:55 on le0
        Sep 8 09:10:04 	kernel: arp: 192.168.126.13 moved from 00:01:02:f9:ea:55 to 00:08:02:45:32:42 on le0
        
        

        S.

        1 Reply Last reply Reply Quote 0
        • T
          TheBlast
          last edited by

          Hi there,
          same issue for me : ~160 ipsec tunnels get stopped after some hours.
          Could someone just paste the magic script to restart racoon if it's stopped (cron inside) ?

          edit : error message
          Sep 17 08:33:49 pfsense kernel: pid 2238 (racoon), uid 0: exited on signal 11 (core dumped)

          Edit 2: new crash
          System log message : Sep 17 19:07:56 kernel: pid 10333 (racoon), uid 0: exited on signal 11 (core dumped)
          Ipsec error message : Sep 17 19:07:56 racoon: [xxx]: [yyy.yyy.yyy.yyy] ERROR: phase1 negotiation failed.

          Edit 3 : no crash since I disabled badly configured tunnel … will keep you informed and check with V2 Release this week.

          So a badly configured tunnel seems to kill racoon ... Will this help ?

          1 Reply Last reply Reply Quote 0
          • D
            dhatz
            last edited by

            You might also want to open a ticket with the ipsec-tools developers:
            http://sourceforge.net/projects/ipsec-tools/

            1 Reply Last reply Reply Quote 0
            • P
              podilarius
              last edited by

              @TheBlast:

              So a badly configured tunnel seems to kill racoon … Will this help ?

              What was badly configured? I have noticed that all that had the problem are showing core dumps. Could be bad memory or bad memory management by raccoon. Are there any other packages being used?

              1 Reply Last reply Reply Quote 0
              • T
                TheBlast
                last edited by

                Hi,
                when I said "badly" it was just a way to say that one side was using an ID and not the other side.
                Anyway I disabled all the "misconfigured" tunnels but I still get the same problem, even with version 2.0 Release.
                Racoon stops once or twice a day. Fortunately some kind of cron restarts it from time to time but looks like a bug.
                Where can I find the core dump and who will be interested in debugging it ?

                1 Reply Last reply Reply Quote 0
                • T
                  TheBlast
                  last edited by

                  The problem remains the same : once or twice a day racoon crashes. Fortunately some king of script restarts it after a while. Is the a way to stop this ?

                  1 Reply Last reply Reply Quote 0
                  • S
                    stemond
                    last edited by

                    @theblast: Can you post your script restart ?

                    thank you!

                    1 Reply Last reply Reply Quote 0
                    • T
                      TheBlast
                      last edited by

                      Hi,
                      no because I don't know which script it is ! I just wanted to point out that a script does the job.

                      1 Reply Last reply Reply Quote 0
                      • P
                        podilarius
                        last edited by

                        Are you running snort or any other packages? What type of hardware do you have? Single/Multiple Core CPU and how much memory?

                        1 Reply Last reply Reply Quote 0
                        • T
                          TheBlast
                          last edited by

                          Hi,
                          Only VPN Client export package is installed.
                          The hardware :

                          • abit motherboard (2011) / Core I3 intel processor
                          • Ram 2 Go
                          • Network : Lan is intel PCI Express Gigabit adapter, others are DLINK DFE 530 Tx 100 mb
                          1 Reply Last reply Reply Quote 0
                          • P
                            podilarius
                            last edited by

                            Except for the DLink, it sounds ideal. Have you run memtest on the machine to make sure memory is good?

                            1 Reply Last reply Reply Quote 0
                            • T
                              TheBlast
                              last edited by

                              @podilarius:

                              Except for the DLink, it sounds ideal. Have you run memtest on the machine to make sure memory is good?

                              Hi Podilarius,

                              • maybe the d-link is not an ideal choice - I agree
                              • No, I did not check the memory, nor the hard drive. It really sounds like a bug to me but I'll do the test one of those days.
                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.