CP not work correctly
-
After update to last from 26.04 v2 CP not work correctly
# ipfw pipe list 20002: 2.050 Kbit/s 0 ms burst 0 q151074 100 sl. 0 flows (1 buckets) sched 85538 weight 0 lmax 0 pri 0 droptail sched 85538 type FIFO flags 0x0 0 buckets 1 active 0 ip 0.0.0.0/0 0.0.0.0/0 30 5170 15 2136 0 20003: 5.120 Kbit/s 0 ms burst 0 q151075 100 sl. 0 flows (1 buckets) sched 85539 weight 0 lmax 0 pri 0 droptail sched 85539 type FIFO flags 0x0 0 buckets 1 active 0 ip 0.0.0.0/0 0.0.0.0/0 3 3126 1 98 0 # ipfw pipe list 20002: 2.050 Kbit/s 0 ms burst 0 q151074 100 sl. 0 flows (1 buckets) sched 85538 weight 0 lmax 0 pri 0 droptail sched 85538 type FIFO flags 0x0 0 buckets 1 active 0 ip 0.0.0.0/0 0.0.0.0/0 33 5432 12 1878 0 20003: 5.120 Kbit/s 0 ms burst 0 q151075 100 sl. 0 flows (1 buckets) sched 85539 weight 0 lmax 0 pri 0 droptail sched 85539 type FIFO flags 0x0 0 buckets 1 active 0 ip 0.0.0.0/0 0.0.0.0/0 8 3568 4 344 0 # ipfw table 1 list 192.168.10.253/32 mac 00:15:c5:20:27:78 20002 # ipfw table 2 list 192.168.10.253/32 mac 00:15:c5:20:27:78 20003
-
Nothing changed on the builder or in the code between the 26th to today that would have affected CP. Are you sure nothing else changed?
-
Nothing changed on the builder or in the code between the 26th to today that would have affected CP. Are you sure nothing else changed?
I update from release 4.4.2011.There no problem at all.We use external radius.
uname -a FreeBSD 8.1-RELEASE-p2 #1: Mon Apr 4 06:03:23 EDT 2011 sullrich@FreeBSD_8.0_pfSense_2.0-snaps.pfsense.org:/usr/obj.pfSense/usr/pfSensesrc/src/sys/pfSense_SMP.8 i386 20012: 2.048 Mbit/s 0 ms burst 0 q151084 100 sl. 0 flows (1 buckets) sched 85548 weight 0 lmax 0 pri 0 droptail sched 85548 type FIFO flags 0x0 0 buckets 1 active 0 ip 0.0.0.0/0 0.0.0.0/0 11 726 0 0 0 20013: 5.120 Mbit/s 0 ms burst 0 q151085 100 sl. 0 flows (1 buckets) sched 85549 weight 0 lmax 0 pri 0 droptail sched 85549 type FIFO flags 0x0 0 buckets 1 active 0 ip 0.0.0.0/0 0.0.0.0/0 2 1652 0 0 0 Login OK: [user/1111] (from client pfsense port 12 cli 00:15:f2:a7:45:4d) +- entering group post-auth {...} Exec-Program output: WISPr-Bandwidth-Max-Up=2048,WISPr-Bandwidth-Max-Down=5120, Exec-Program-Wait: value-pairs: WISPr-Bandwidth-Max-Up=2048,WISPr-Bandwidth-Max-Down=5120 Exec-Program: returned: 0 ++[exec] returns noop Sending Access-Accept of id 21 to 192.168.0.254 port 57887 WISPr-Bandwidth-Max-Up = 2048 WISPr-Bandwidth-Max-Down = 5120 Finished request 9. Going to the next request
This is release with problem with radius bandw. parameters
(pipe show is different from release 4.4.2011):name -a FreeBSD 8.1-RELEASE-p3 #1: Mon Apr 25 20:44:39 EDT 2011 sullrich@FreeBSD_8.0_pfSense_2.0-snaps.pfsense.org:/usr/obj.pfSense/usr/pfSensesrc/src/sys/pfSense.8 i386 [2.0-RC1][root@xxxyyy.homeunix.org]/var/log(15): ipfw show 65291 0 0 allow pfsync from any to any 65292 0 0 allow carp from any to any 65301 8 296 allow ip from any to any layer2 mac-type 0x0806 65302 0 0 allow ip from any to any layer2 mac-type 0x888e 65303 0 0 allow ip from any to any layer2 mac-type 0x88c7 65304 0 0 allow ip from any to any layer2 mac-type 0x8863 65305 0 0 allow ip from any to any layer2 mac-type 0x8864 65306 0 0 allow ip from any to any layer2 mac-type 0x888e 65307 0 0 deny ip from any to any layer2 not mac-type 0x0800 65310 349 29338 allow ip from any to { 255.255.255.255 or 192.168.0.254 } in 65311 764 147306 allow ip from { 255.255.255.255 or 192.168.0.254 } to any out 65312 0 0 allow icmp from { 255.255.255.255 or 192.168.0.254 } to any out icmptypes 0 65313 0 0 allow icmp from any to { 255.255.255.255 or 192.168.0.254 } in icmptypes 8 65314 0 0 allow ip from table(3) to any in 65315 0 0 allow ip from any to table(4) out 65316 0 0 pipe tablearg ip from table(5) to any in 65317 0 0 pipe tablearg ip from any to table(6) out 65318 0 0 allow ip from any to table(7) in 65319 0 0 allow ip from table(8) to any out 65320 0 0 pipe tablearg ip from any to table(9) in 65321 0 0 pipe tablearg ip from table(10) to any out 65322 2418 144231 pipe tablearg ip from table(1) to any in 65323 897 70184 pipe tablearg ip from any to table(2) out 65531 815 83726 fwd 127.0.0.1,8000 tcp from any to any in 65532 727 65756 allow tcp from any to any out 65533 6 614 deny ip from any to any 65534 0 0 allow ip from any to any layer2 65535 312 31665 allow ip from any to any Login OK: [user/1111] (from client pfsense port 10 cli 00:15:f2:a7:45:4d) +- entering group post-auth {...} Exec-Program output: WISPr-Bandwidth-Max-Up=2048,WISPr-Bandwidth-Max-Down=5120, Exec-Program-Wait: value-pairs: WISPr-Bandwidth-Max-Up=2048,WISPr-Bandwidth-Max-Down=5120 Exec-Program: returned: 0 ++[exec] returns noop Sending Access-Accept of id 246 to 192.168.0.254 port 12556 WISPr-Bandwidth-Max-Up = 2048 WISPr-Bandwidth-Max-Down = 5120 [2.0-RC1][root@xxxyyy.homeunix.org]/var/log(16): ipfw pipe show 20010: 2.050 Kbit/s 0 ms burst 0 q151082 100 sl. 0 flows (1 buckets) sched 85546 weight 0 lmax 0 pri 0 droptail sched 85546 type FIFO flags 0x0 0 buckets 1 active 0 ip 0.0.0.0/0 0.0.0.0/0 2515 186655 99 7266 1806 20011: 5.120 Kbit/s 0 ms burst 0 q151083 100 sl. 0 flows (1 buckets) sched 85547 weight 0 lmax 0 pri 0 droptail sched 85547 type FIFO flags 0x0 0 buckets 1 active 0 ip 0.0.0.0/0 0.0.0.0/0 1 54 0 0 0
-
If you were coming from an older snapshot then you might be seeing this:
https://rcs.pfsense.org/projects/pfsense/repos/mainline/commits/2d4003aab1d969ed9ba3e52f2fe3ec083e4bef8c
We were not calculating the bandwidth received from RADIUS according to the standard. You'll probably have to fix your bandwidth values in your RADIUS server.