Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2.3.1 Hard Lock Up

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    13 Posts 7 Posters 3.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RonpfSR
      RonpfS
      last edited by

      You have to disable pfBlockerNG and DNSBL before restoring a config
      Unbound will not start until you remove the "server:include: /var/unbound/pfb_dnsbl.conf" from Services/DNS Resolver/General Settings/Custom Options

      or change the config file
      <unbound><custom_options>c2VydmVyOmluY2x1ZGU6IC92YXIvdW5ib3VuZC9wZmJfZG5zYmwuY29uZg==</custom_options>

      to</unbound>

      2.4.5-RELEASE-p1 (amd64)
      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

      1 Reply Last reply Reply Quote 0
      • A
        ak
        last edited by

        No crash dumps on restart - just dirty filesystem.

        I didn't get a chance to check syslog as it locks up soon after.

        Thanks for the Unbound - thats exactly what I did (see other thread in same forum). The gets going - it doesn't seem to be PfBlockerNG as next reboot it looks up. Hopefully have time for a trial with a process of elimination.

        I tried to mount the installation USB in linux so I can copy a version of the backup XML but linux cannot read the filesystem. Any ideas how to mount the installation USB? This will speed up the reinstall and restart times.

        1 Reply Last reply Reply Quote 0
        • w0wW
          w0w
          last edited by

          Looks like hardware issue, for example faulty RAM or whatever else.

          1 Reply Last reply Reply Quote 0
          • H
            Harvy66
            last edited by

            Hard locks typically mean faulty hardware
            Black screen then reboot typically means overheat or faulty hardware
            Kernel fault typically means corrupt data, faulty hardware, or buggy drivers/kernel(very much less so kernel)

            1 Reply Last reply Reply Quote 0
            • A
              ak
              last edited by

              Found the issue now. Its not hardware.

              Setup:
              PfSense with a LAN and a WAN.
              LAN plugged into a Ubiquiti Switch. On the switch I have a couple of dumb switches to the rest of the house, and one Ubiquiti AP Pro.

              The Ubiquiti has a default Network configured for my internal network with address of 192.168.1.0/24 (it looks like you have to set up a 'corporate' network). I then setup an additional network VLAN with 192.168.10.0/24 as a GUEST network with VLAN tag 90.

              Switch is configured to allow LAN to the dumb switches and ALL for the AP and PfSense. PfSense has the LAN to my 192.168.1.0/24 and a VLAN to match the Ubiquiti setup. The AP has two SSID to match the LAN and the VLAN.

              Now whenever I try and attach a client to the GUEST network the PfSense box locks up  - I have a keyboard plugged in and it is unresponsive. I cannot ping the box from the cable network either.

              Any ideas why a GUEST VLAN fails and locks up? There is nothing I can see in the logs just before a hard restart. Nothing in /var/crash apart from a file called minfree with the value 2048.

              Attached is a quick hand sketch of the network topology. This is the first time I have used VLANs so not sure if I am doing anything wrong,

              network-corrected.jpg
              network-corrected.jpg_thumb

              1 Reply Last reply Reply Quote 0
              • P
                phil.davis
                last edited by

                The subnets must not overlap (or be the same):
                LAN 192.168.1.0/24 - the system should not have let you use the bottom IP address of the subnet (.0) - the LAN interface IP should be in the range 1 to 254

                VLAN 192.168.1.10/24 - the subnet is 192.168.1.0 through 255 - the same as 192.168.1.0/24 - you must not do that.

                Certainly the routing will get confused. But the box itself should not "lock up" - i.e. the menu should still work from the console.

                As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                1 Reply Last reply Reply Quote 0
                • A
                  ak
                  last edited by

                  My Bad - in my haste in sketching I wrote the wrong thing (corrected image now uploaded).

                  LAN: 192.168.1.0/24
                  VLAN: 192.168.10.0/24

                  1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan
                    last edited by

                    This:
                    @ak:

                    Found the issue now. Its not hardware.

                    isn't proved by this :
                    @ak:

                    Setup:
                    PfSense with a LAN and a WAN.
                    LAN plugged into a Ubiquiti Switch. On the switch I have a couple of dumb switches to the rest of the house, and one Ubiquiti AP Pro.

                    The Ubiquiti has a default Network configured for my internal network with address of 192.168.1.0/24 (it looks like you have to set up a 'corporate' network). I then setup an additional network VLAN with 192.168.10.0/24 as a GUEST network with VLAN tag 90.

                    Switch is configured to allow LAN to the dumb switches and ALL for the AP and PfSense. PfSense has the LAN to my 192.168.1.0/24 and a VLAN to match the Ubiquiti setup. The AP has two SSID to match the LAN and the VLAN.

                    Now whenever I try and attach a client to the GUEST network the PfSense box locks up  - I have a keyboard plugged in and it is unresponsive. I cannot ping the box from the cable network either.

                    Any ideas why a GUEST VLAN fails and locks up? There is nothing I can see in the logs just before a hard restart. Nothing in /var/crash apart from a file called minfree with the value 2048.

                    Attached is a quick hand sketch of the network topology. This is the first time I have used VLANs so not sure if I am doing anything wrong,

                    Even a messy setup can't not 'dirty' your hard drive.
                    Drives get dirty when sectors a badly written - or when important file structures are filled up with non-sense.

                    I tend to say : you DO HAVE hardware problems.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    1 Reply Last reply Reply Quote 0
                    • A
                      ak
                      last edited by

                      All I got to go on are the observations.

                      HDD is dirty because when it hard locks, I get no response on the network or the plugged in keyboard. Forcing a hard reboot to get going. On startup, the screen shows that the HDD was not safely unmounted and so 'dirty' - it then runs a disk check and mentions how many inodes its recovered/lost/or marked. (can't remember the terminology).

                      The cause being the VLAN is due to again my cause and effect observations. As soon as I try and connect a wireless client to the GUEST network (that has a VLAN configured), the machine locks up. To be honest I cannot guarantee this as I only have had time to attempt this twice. Will need to try a couple more times to prove this.

                      I have been running successfully for the pass 24 hours and it has been fine - however, this is without the GUEST network available on the AP (I have turned this on as we need internet connectivity.

                      1 Reply Last reply Reply Quote 0
                      • w0wW
                        w0w
                        last edited by

                        Why just not let memtest run over night, just to be sure?
                        http://www.memtest86.com/
                        VLAN connection may be placed in bad bit memory address and this causes system to lock up immediately or soon after.
                        Many others have VLAN configured without any issue.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.