Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Racoon stops without any cause

    Scheduled Pinned Locked Moved IPsec
    25 Posts 6 Posters 14.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      stemond
      last edited by

      i have same issue :(
      Racoon stop withou causes and drops all IPSEC tunnels.

      i am using Pfsense 2.0 RC3 and it happens without PPTP tunnel

      this is my log, have you any hint ???

      
       Sep 8 09:58:48 	php: /status_services.php: Forcefully reloading IPsec racoon daemon
      [b]Sep 8 09:52:28 kernel: pid 23362 (racoon), uid 0: exited on signal 11 (core dumped)[/b]
      Sep 8 09:50:04 	kernel: arp: 192.168.126.13 moved from 00:01:02:f9:ea:55 to 00:08:02:45:32:42 on le0
      Sep 8 09:30:04 	kernel: arp: 192.168.126.13 moved from 00:01:02:f9:ea:55 to 00:08:02:45:32:42 on le0
      Sep 8 09:30:04 	kernel: arp: 192.168.126.13 moved from 00:08:02:45:32:42 to 00:01:02:f9:ea:55 on le0
      Sep 8 09:10:04 	kernel: arp: 192.168.126.13 moved from 00:01:02:f9:ea:55 to 00:08:02:45:32:42 on le0
      
      

      S.

      1 Reply Last reply Reply Quote 0
      • T
        TheBlast
        last edited by

        Hi there,
        same issue for me : ~160 ipsec tunnels get stopped after some hours.
        Could someone just paste the magic script to restart racoon if it's stopped (cron inside) ?

        edit : error message
        Sep 17 08:33:49 pfsense kernel: pid 2238 (racoon), uid 0: exited on signal 11 (core dumped)

        Edit 2: new crash
        System log message : Sep 17 19:07:56 kernel: pid 10333 (racoon), uid 0: exited on signal 11 (core dumped)
        Ipsec error message : Sep 17 19:07:56 racoon: [xxx]: [yyy.yyy.yyy.yyy] ERROR: phase1 negotiation failed.

        Edit 3 : no crash since I disabled badly configured tunnel … will keep you informed and check with V2 Release this week.

        So a badly configured tunnel seems to kill racoon ... Will this help ?

        1 Reply Last reply Reply Quote 0
        • D
          dhatz
          last edited by

          You might also want to open a ticket with the ipsec-tools developers:
          http://sourceforge.net/projects/ipsec-tools/

          1 Reply Last reply Reply Quote 0
          • P
            podilarius
            last edited by

            @TheBlast:

            So a badly configured tunnel seems to kill racoon … Will this help ?

            What was badly configured? I have noticed that all that had the problem are showing core dumps. Could be bad memory or bad memory management by raccoon. Are there any other packages being used?

            1 Reply Last reply Reply Quote 0
            • T
              TheBlast
              last edited by

              Hi,
              when I said "badly" it was just a way to say that one side was using an ID and not the other side.
              Anyway I disabled all the "misconfigured" tunnels but I still get the same problem, even with version 2.0 Release.
              Racoon stops once or twice a day. Fortunately some kind of cron restarts it from time to time but looks like a bug.
              Where can I find the core dump and who will be interested in debugging it ?

              1 Reply Last reply Reply Quote 0
              • T
                TheBlast
                last edited by

                The problem remains the same : once or twice a day racoon crashes. Fortunately some king of script restarts it after a while. Is the a way to stop this ?

                1 Reply Last reply Reply Quote 0
                • S
                  stemond
                  last edited by

                  @theblast: Can you post your script restart ?

                  thank you!

                  1 Reply Last reply Reply Quote 0
                  • T
                    TheBlast
                    last edited by

                    Hi,
                    no because I don't know which script it is ! I just wanted to point out that a script does the job.

                    1 Reply Last reply Reply Quote 0
                    • P
                      podilarius
                      last edited by

                      Are you running snort or any other packages? What type of hardware do you have? Single/Multiple Core CPU and how much memory?

                      1 Reply Last reply Reply Quote 0
                      • T
                        TheBlast
                        last edited by

                        Hi,
                        Only VPN Client export package is installed.
                        The hardware :

                        • abit motherboard (2011) / Core I3 intel processor
                        • Ram 2 Go
                        • Network : Lan is intel PCI Express Gigabit adapter, others are DLINK DFE 530 Tx 100 mb
                        1 Reply Last reply Reply Quote 0
                        • P
                          podilarius
                          last edited by

                          Except for the DLink, it sounds ideal. Have you run memtest on the machine to make sure memory is good?

                          1 Reply Last reply Reply Quote 0
                          • T
                            TheBlast
                            last edited by

                            @podilarius:

                            Except for the DLink, it sounds ideal. Have you run memtest on the machine to make sure memory is good?

                            Hi Podilarius,

                            • maybe the d-link is not an ideal choice - I agree
                            • No, I did not check the memory, nor the hard drive. It really sounds like a bug to me but I'll do the test one of those days.
                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.