Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    *RANT* Why pfsense is popular

    Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
    59 Posts 10 Posters 11.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      Harvy66
      last edited by

      Stop building castles in swamps, pfSense being the castle and the swamp being your hardware.

      I'm getting 0.008ms through pfSense. I let bittorrent run 24/7 and don't have any issues with latency. Here's my quality graph against 4.2.2.2

      2017Quality.PNG
      2017Quality.PNG_thumb

      1 Reply Last reply Reply Quote 0
      • E
        edseitzinger Banned
        last edited by

        @ivor:

        Sorry but you did not provide any context or asked for help. Ranting or venting doesn't help anyone. Most of us are gamers and latency is not an issue. If you have latency issues check your hardware, cables, ISP and so on.

        That's kind of the point of it being a RANT do you know many RANTS that are useful or helpfully? That being said…..

        All the hardware is the same minus the pfsense box and the Google Fiber box, cables everything else is the same .

        AS for the Current hardware:
        AMD A10-5800B FM2
        GIGABYTE GA-F2A88XN-WIFI FM2+/FM2 A88X with the lastest BIOS F6
        8 GB Kingston HyperX DDR3 @ 1600Mhz
        INTEL PRO/1000 VT PCIe NIC 4-PORT GIGABIT SERVER ADAPTER EXPI9404VT YT674
        60GB OCZ SSD

        ISP is Google fiber and it is a PITA being able to remove the box from the network as the WAN has to be VLAN 2 tagged and the priority bit set to 3 which is done easily in pfsense. And may infact be the issue but I doubt that as I can goto any speed test site:

        http://beta.speedtest.net
        http://speedtest.googlefiber.net/
        http://www.dslreports.com/speedtest

        and all the speed test are within 50Mbps of each other both with the GFiber box and the pfsense box. and the pings form each site range from 4-6 ms.

        My normal day to day data traffic flows with no hiccups with either box. Streaming movies (netflix, hulu, amazon) livetv (sling), youtube, pandora and that runs fine with either box. When I try to play WoW, on the GF box 78ms, nothing more nothing less. PF normal is 300-600 ms. this is with a vanilla install, and I have tried using port forwarding for the WOW server/ports doesn't not matter if they are on or off.

        Also pfsense doesn't grab the dhcpv6 info that the GF box does and this seem to be an issue that all GF users have.

        1 Reply Last reply Reply Quote 0
        • C
          chrcoluk
          last edited by

          for me pfsense lowered latency not increased it.

          Most consumer routers run of very weak atom type chips, whilst my units have more than 20X cpu power available over such units.

          I got no idea what went wrong for you, but I disagree its "pfsense to blame" as such, might be something that needs configuring to be fully compatible with your isp.

          pfSense CE 2.7.2

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            The only complaints I've seen regularly are about static ports with outbound NAT.

            1 Reply Last reply Reply Quote 0
            • E
              edseitzinger Banned
              last edited by

              @johnpoz:

              "with pfsense 300-1500 ms lag."

              If your seeing this sort of lag that you are blaming on pfsense you got something else wrong… Sorry but that is just not the case... There is nothing pfsense would be doing that would introduce such extra lag..

              Please show you work and setup that brings you to the conclusion that pfsense is the cause of your lag..

              Something as simple as http://www.azurespeed.com/ even.. Lets see those numbers with and without pfsense.

              Sorry but I have seen post where ppl have had some bad lag on a pfsense box and install untangled on the same hardware and lost all the lag. Not saying its normal, just saying that is is possible. And I would try to remove pfsense as the variable in this case but unfortunately UT does have the ability to set the 802.11q bit to 3 and confirmed by one of their engineers who has submitted a feature request ticket.

              You can read the post above to see the hardware used in my pfsense box and removed as many of the variables as I could.

              Currently using the GFiber box and my in game latency is sitting at 78ms as it always is.

              First Pic is GF the 2nd Pic is PFsense

              Right after I switch the data feed from GF to PF I reload azurespeed and WOW, wow is now at 79ms, which is awesome.

              Shutting down the wow client and then restarting wow its jumped back up to 200+ms
              after about 5 minus is came back down to 100ms, this is not normal as I have raided for hrs and it never came down form 500+ ms lag.

              I can live with 100ms, my issue is I have seen it go as high as 2500ms and as low as 35ms (last night while raiding) with no real explanation.

              PfsenseLAT.jpg
              PfsenseLAT.jpg_thumb
              GFiberLAT.jpg
              GFiberLAT.jpg_thumb

              1 Reply Last reply Reply Quote 0
              • E
                edseitzinger Banned
                last edited by

                @chrcoluk:

                for me pfsense lowered latency not increased it.

                Most consumer routers run of very weak atom type chips, whilst my units have more than 20X cpu power available over such units.

                I got no idea what went wrong for you, but I disagree its "pfsense to blame" as such, might be something that needs configuring to be fully compatible with your isp.

                I really can't run a consumer router other then in bridged mode and then I might as well just have a switch and a wifi woth POE along with either the GFiber box or pfsense.

                1 Reply Last reply Reply Quote 0
                • E
                  edseitzinger Banned
                  last edited by

                  @Harvy66:

                  Stop building castles in swamps, pfSense being the castle and the swamp being your hardware.

                  I'm getting 0.008ms through pfSense. I let bittorrent run 24/7 and don't have any issues with latency. Here's my quality graph against 4.2.2.2

                  Yeah i doubt my hardware is the swamp you can read the specs above. Are you using a beta version of PFsense cuz it shows my is the latest version:

                  2.4.2-RELEASE-p1 (amd64)
                  built on Tue Dec 12 13:45:26 CST 2017
                  FreeBSD 11.1-RELEASE-p6

                  Can provide me the info to get those graph and chart I do not see them in the dashboard widgets.

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    If you have gateway monitoring on WAN (the default setting), the system is automatically keeping track of two pings per second in Status > Monitoring.

                    From there select settings, change the left axis to Quality / WANGW (or the local equivalent).

                    A good place to start with Options: 8 hours, Resolution: 1 minute.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • E
                      edseitzinger Banned
                      last edited by

                      @Derelict:

                      If you have gateway monitoring on WAN (the default setting), the system is automatically keeping track of two pings per second in Status > Monitoring.

                      From there select settings, change the left axis to Quality / WANGW (or the local equivalent).

                      A good place to start with Options: 8 hours, Resolution: 1 minute.

                      Thank you for the help on setting that up, also playing wow now to see if that could help capture any packet drops or issues :D ;D

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        I do not see any difference between your tests with your GF and pfsense..  And that azure test.. Where are those 300-1500 numbers your talking about?

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • E
                          edseitzinger Banned
                          last edited by

                          @johnpoz:

                          I do not see any difference between your tests with your GF and pfsense..  And that azure test.. Where are those 300-1500 numbers your talking about?

                          In World of Warcraft. Like I said my normal day to day traffic is rock solid.

                          ![Pfsense ping.jpg](/public/imported_attachments/1/Pfsense ping.jpg)
                          ![Pfsense ping.jpg_thumb](/public/imported_attachments/1/Pfsense ping.jpg_thumb)

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            And how exactly do you think pfsense can tell the difference between these packets.. And slow down the wow ones?  PFM?  Because pfsense/netgate hate wow players? ;)

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                            1 Reply Last reply Reply Quote 0
                            • E
                              edseitzinger Banned
                              last edited by

                              @johnpoz:

                              And how exactly do you think pfsense can tell the difference between these packets.. And slow down the wow ones?  PFM?  Because pfsense/netgate hate wow players? ;)

                              Well its obvious they do, seriously ….... Hence why it was a RANT, its doesn't make sense. General networking would suggest that there were a a large % of dropped packets while gaming, which I have not seen. Maybe I did something wrong, but its is pretty much a vanilla install and the 3rd clean install, after trying port forwarding and traffic shaping.

                              I did game a bit last nite and upon logging it it jumped to 300+ms lag. Leaving the game running I moved the cables to the GFiber box, relogged into wow of a few mins add lag was as always 78ms, then switched the cables back to pfsense and relogged and then they stayed at 78ms for the rest of the nite, thoughts?

                              1 Reply Last reply Reply Quote 0
                              • C
                                chrcoluk
                                last edited by

                                @edseitzinger:

                                @johnpoz:

                                And how exactly do you think pfsense can tell the difference between these packets.. And slow down the wow ones?  PFM?  Because pfsense/netgate hate wow players? ;)

                                Well its obvious they do, seriously ….... Hence why it was a RANT, its doesn't make sense. General networking would suggest that there were a a large % of dropped packets while gaming, which I have not seen. Maybe I did something wrong, but its is pretty much a vanilla install and the 3rd clean install, after trying port forwarding and traffic shaping.

                                I did game a bit last nite and upon logging it it jumped to 300+ms lag. Leaving the game running I moved the cables to the GFiber box, relogged into wow of a few mins add lag was as always 78ms, then switched the cables back to pfsense and relogged and then they stayed at 78ms for the rest of the nite, thoughts?

                                My thoughts are its a compatibility issue, it might be a specific vlan id or something needs setting to get the right performance from the ISP.

                                e.g.in the UK on openreach VDSL, there is multiple vlan's used to classify traffic priority, some are only supposed to be used for IPTV customers and can have unpredictable results on other types of network usage, I expect your google supplied box is preconfigured correctly and you need to research and get the information to get it all setup right on pfsense.

                                pfSense CE 2.7.2

                                1 Reply Last reply Reply Quote 0
                                • E
                                  edseitzinger Banned
                                  last edited by

                                  @chrcoluk:

                                  @edseitzinger:

                                  @johnpoz:

                                  And how exactly do you think pfsense can tell the difference between these packets.. And slow down the wow ones?  PFM?  Because pfsense/netgate hate wow players? ;)

                                  Well its obvious they do, seriously ….... Hence why it was a RANT, its doesn't make sense. General networking would suggest that there were a a large % of dropped packets while gaming, which I have not seen. Maybe I did something wrong, but its is pretty much a vanilla install and the 3rd clean install, after trying port forwarding and traffic shaping.

                                  I did game a bit last nite and upon logging it it jumped to 300+ms lag. Leaving the game running I moved the cables to the GFiber box, relogged into wow of a few mins add lag was as always 78ms, then switched the cables back to pfsense and relogged and then they stayed at 78ms for the rest of the nite, thoughts?

                                  My thoughts are its a compatibility issue, it might be a specific vlan id or something needs setting to get the right performance from the ISP.

                                  e.g.in the UK on openreach VDSL, there is multiple vlan's used to classify traffic priority, some are only supposed to be used for IPTV customers and can have unpredictable results on other types of network usage, I expect your google supplied box is preconfigured correctly and you need to research and get the information to get it all setup right on pfsense.

                                  I'm not ruling that out, but I have done the research, this projects is a good 6-8 mos in planning and readin google, level1techs and pfsense forums. What I have gleened from the data is that WAN has to be configured  for VLAN 2 with the 802.11q bit priority set to 3, to get the internet traffic flowing and it does I hit my normal speed test at 900Mbps on all the major speed test sites so I know its configured for internet data, versus IPTV and VOIP.

                                  1 Reply Last reply Reply Quote 0
                                  • C
                                    chrcoluk
                                    last edited by

                                    other ideas (without commands sorry as I been up all night).best to try these step by step one at a time, and retest in each step.

                                    Disable energy efficient ethernet.
                                    Disable (at least temporarily checksum offloading on the NIC).
                                    Reduce network queues to 1, this to make sure no packet ordering issues causing problems or driver bugs.
                                    Disable TSO/RSO if enabled.
                                    Disable interrupt moderation on NIC if enabled.
                                    If powerd is enabled set to the performance mode or disable it.

                                    Its unlikely to be a widescale pfsense issue, there would be many complaints if it was, its either a bug that only kicks in a specific scenario which you hitting or a compatibility issue whether it be hardware or isp config.

                                    WOW has a known issue where if nagle is enabled (Delayed acks) it will show high lag because it uses tcp not udp for the game packets.  But pfsense as the router doesnt control nagle for client LAN devices, however just in case you can disable nagle on pfsense side via this shell command.

                                    'sysctl net.inet.tcp.delayed_ack=0'

                                    pfSense CE 2.7.2

                                    1 Reply Last reply Reply Quote 0
                                    • johnpozJ
                                      johnpoz LAYER 8 Global Moderator
                                      last edited by

                                      What does http://us-looking-glass.battle.net/ show from realm your on to the your IP?

                                      Lets see a sniff of this problem.

                                      So put pfsense behind your GF device in a double nat.. Do you have the problem then vs replacement and the vlan tagging your doing..

                                      Lets see your looking glass traces with your GF and Pfsense and then your untangle - the one thing that would be most likely changing would be your IP.. Are you on the same netblock when you swap out devices.. Your routing could be completely different based upon network your on with google..

                                      if your saying untangle does not have the problem - lets see sniff on untangle wan with it working good, and then sniff on pfsense wan with it bad..

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                      1 Reply Last reply Reply Quote 0
                                      • E
                                        edseitzinger Banned
                                        last edited by

                                        @johnpoz:

                                        What does http://us-looking-glass.battle.net/ show from realm your on to the your IP?

                                        Lets see a sniff of this problem.

                                        So put pfsense behind your GF device in a double nat.. Do you have the problem then vs replacement and the vlan tagging your doing..

                                        Lets see your looking glass traces with your GF and Pfsense and then your untangle - the one thing that would be most likely changing would be your IP.. Are you on the same netblock when you swap out devices.. Your routing could be completely different based upon network your on with google..

                                        if your saying untangle does not have the problem - lets see sniff on untangle wan with it working good, and then sniff on pfsense wan with it bad..

                                        I was going to try untangled but I can't set the priority bit so had to bypass that set of testing….

                                        Here is the Looking Glass out put and it doesn't look good....

                                        PING:
                                        PING MYEXTIP (MYEXTIP) 56(84) bytes of data.

                                        --- MYEXTIP ping statistics ---
                                        4 packets transmitted, 0 received, 100% packet loss, time 3001ms

                                        23/12/2017 15:25:10 UTC

                                        PING:
                                        PING MYEXTIP (MYEXTIP) 56(84) bytes of data.

                                        --- MYEXTIP ping statistics ---
                                        4 packets transmitted, 0 received, 100% packet loss, time 3002ms

                                        23/12/2017 15:25:10 UTC

                                        TRACEROUTE:
                                        traceroute to MYEXTIP (MYEXTIP), 15 hops max, 60 byte packets
                                        1  24.105.30.2 (24.105.30.2)  0.562 ms  1.036 ms  1.056 ms
                                        2  * * *
                                        3  137.221.66.2 (137.221.66.2)  1.382 ms  1.441 ms  1.505 ms
                                        4  137.221.68.66 (137.221.68.66)  1.315 ms  1.344 ms  1.387 ms
                                        5  137.221.68.32 (137.221.68.32)  0.838 ms  1.052 ms  1.066 ms
                                        6  * * *
                                        7  * * *
                                        8  * * *
                                        9  * * *
                                        10  * * *
                                        11  * * *
                                        12  * * *
                                        13  * * *
                                        14  * * *
                                        15  * * *

                                        23/12/2017 15:25:10 UTC

                                        TRACEROUTE:
                                        traceroute to MYEXTIP (MYEXTIP), 15 hops max, 60 byte packets
                                        1  24.105.30.2 (24.105.30.2)  1.408 ms  1.414 ms  1.429 ms
                                        2  * * *
                                        3  137.221.66.2 (137.221.66.2)  1.288 ms  1.345 ms  2.723 ms
                                        4  137.221.68.66 (137.221.68.66)  1.308 ms  1.331 ms  1.356 ms
                                        5  137.221.68.32 (137.221.68.32)  0.869 ms  0.906 ms  1.060 ms
                                        6  * * *
                                        7  * * *
                                        8  * * *
                                        9  * * *
                                        10  * * *
                                        11  * * *
                                        12  * * *
                                        13  * * *
                                        14  * * *
                                        15  * * *

                                        23/12/2017 15:25:10 UTC

                                        TRACEROUTE:
                                        traceroute to MYEXTIP (MYEXTIP), 15 hops max, 60 byte packets
                                        1  Blizzard (Blizzard)  0.739 ms  0.757 ms  0.803 ms
                                        2  * * *
                                        3  137.221.66.8 (137.221.66.8)  2.093 ms  2.147 ms  2.226 ms
                                        4  137.221.69.70 (137.221.69.70)  2.042 ms  2.064 ms  2.090 ms
                                        5  137.221.69.34 (137.221.69.34)  1.720 ms  1.810 ms  1.820 ms
                                        6  * * *
                                        7  * * *
                                        8  * * *
                                        9  192-119-18-202.mci.googlefiber.net (192.119.18.202)  31.579 ms  31.618 ms  31.682 ms
                                        10  192-119-18-184.mci.googlefiber.net (192.119.18.184)  32.038 ms  32.012 ms  32.041 ms
                                        11  ae7.ar02.mci102.googlefiber.net (192.119.17.69)  32.005 ms  31.962 ms  31.975 ms
                                        12  23-255-225-17.mci.googlefiber.net (23.255.225.17)  32.105 ms  32.099 ms  31.998 ms
                                        13  23-255-225-19.mci.googlefiber.net (23.255.225.19)  32.483 ms  32.531 ms  32.534 ms
                                        14  * * *
                                        15  * * *

                                        23/12/2017 15:25:15 UTC

                                        PING:
                                        PING MYEXTIP (MYEXTIP) 56(84) bytes of data.

                                        --- MYEXTIP ping statistics ---
                                        4 packets transmitted, 0 received, 100% packet loss, time 2998ms

                                        23/12/2017 15:25:16 UTC

                                        TRACEROUTE:
                                        traceroute to MYEXTIP (MYEXTIP), 15 hops max, 60 byte packets
                                        1  Blizzard (Blizzard)  0.953 ms  0.990 ms  1.068 ms
                                        2  * * *
                                        3  137.221.66.8 (137.221.66.8)  1.935 ms  2.028 ms  2.073 ms
                                        4  137.221.69.70 (137.221.69.70)  1.863 ms  1.971 ms  1.992 ms
                                        5  137.221.69.34 (137.221.69.34)  1.717 ms  1.729 ms  1.733 ms
                                        6  * * *
                                        7  * * *
                                        8  * * *
                                        9  192-119-18-202.mci.googlefiber.net (192.119.18.202)  31.793 ms  31.835 ms  31.935 ms
                                        10  192-119-18-184.mci.googlefiber.net (192.119.18.184)  33.210 ms  32.071 ms  32.099 ms
                                        11  ae7.ar02.mci102.googlefiber.net (192.119.17.69)  32.061 ms  31.990 ms  31.974 ms
                                        12  23-255-225-17.mci.googlefiber.net (23.255.225.17)  32.255 ms  32.265 ms  32.005 ms
                                        13  23-255-225-19.mci.googlefiber.net (23.255.225.19)  32.461 ms  32.673 ms  32.565 ms
                                        14  * * *
                                        15  * * *

                                        23/12/2017 15:25:20 UTC

                                        MTR:
                                        Start: Sat Dec 23 15:25:10 2017
                                        HOST: Blizzard Loss%  Snt  Last  Avg  Best  Wrst StDev
                                          1.|-- 24.105.30.2                0.0%    10    0.6  0.7  0.5  0.8  0.0
                                          2.|-- ???                        100.0    10    0.0  0.0  0.0  0.0  0.0
                                          3.|-- 137.221.66.2                0.0%    10    1.3  1.4  1.3  1.5  0.0
                                          4.|-- 137.221.68.66              0.0%    10    1.2  1.3  1.2  1.3  0.0
                                          5.|-- 137.221.68.32              0.0%    10    1.0  2.8  0.9  11.5  3.9
                                          6.|-- ???                        100.0    10    0.0  0.0  0.0  0.0  0.0

                                        23/12/2017 15:25:10 UTC

                                        MTR:
                                        Start: Sat Dec 23 15:25:10 2017
                                        HOST: Blizzard Loss%  Snt  Last  Avg  Best  Wrst StDev
                                          1.|-- 24.105.30.2                0.0%    10    0.6  0.7  0.5  1.3  0.0
                                          2.|-- ???                        100.0    10    0.0  0.0  0.0  0.0  0.0
                                          3.|-- 137.221.66.2                0.0%    10    1.4  1.3  1.2  1.4  0.0
                                          4.|-- 137.221.68.66              0.0%    10    1.1  1.3  1.1  1.4  0.0
                                          5.|-- 137.221.68.32              0.0%    10    1.0  4.5  1.0  35.6  10.9
                                          6.|-- ???                        100.0    10    0.0  0.0  0.0  0.0  0.0

                                        23/12/2017 15:25:10 UTC

                                        PING:
                                        PING MYEXTIP (MYEXTIP) 56(84) bytes of data.

                                        --- MYEXTIP ping statistics ---
                                        4 packets transmitted, 0 received, 100% packet loss, time 2999ms

                                        23/12/2017 15:25:21 UTC

                                        MTR:
                                        Start: Sat Dec 23 15:25:15 2017
                                        HOST: Blizzard        Loss%  Snt  Last  Avg  Best  Wrst StDev
                                          1.|-- Blizzard                      0.0%    10    2.4  2.7  0.5  7.9  2.8
                                          2.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                          3.|-- 137.221.66.8                        0.0%    10    2.1  2.1  2.1  2.2  0.0
                                          4.|-- 137.221.69.70                      0.0%    10    2.0  2.6  1.9  7.2  1.5
                                          5.|-- 137.221.69.34                      0.0%    10  41.3  6.6  1.7  41.3  12.4
                                          6.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                          7.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                          8.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                          9.|-- 192-119-18-202.mci.googlefiber.net  0.0%    10  31.5  31.6  31.5  31.7  0.0
                                        10.|-- 192-119-18-184.mci.googlefiber.net  0.0%    10  32.3  32.2  32.0  33.0  0.0
                                        11.|-- ae7.ar02.mci102.googlefiber.net    0.0%    10  32.0  32.1  32.0  32.1  0.0
                                        12.|-- 23-255-225-17.mci.googlefiber.net  0.0%    10  32.1  32.1  32.0  32.2  0.0
                                        13.|-- 23-255-225-19.mci.googlefiber.net  0.0%    10  32.6  32.5  32.5  32.6  0.0
                                        14.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0

                                        23/12/2017 15:25:15 UTC

                                        MTR:
                                        Start: Sat Dec 23 15:25:16 2017
                                        HOST: Blizzard        Loss%  Snt  Last  Avg  Best  Wrst StDev
                                          1.|-- Blizzard                      0.0%    10    0.8  0.6  0.6  0.8  0.0
                                          2.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                          3.|-- 137.221.66.8                        0.0%    10    2.1  2.0  1.9  2.2  0.0
                                          4.|-- 137.221.69.70                      0.0%    10    1.9  2.6  1.9  7.5  1.7
                                          5.|-- 137.221.69.34                      0.0%    10    9.8  3.6  1.7  9.8  3.2
                                          6.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                          7.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                          8.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                          9.|-- 192-119-18-202.mci.googlefiber.net  0.0%    10  31.6  31.9  31.5  33.5  0.6
                                        10.|-- 192-119-18-184.mci.googlefiber.net  0.0%    10  32.2  32.5  32.1  33.9  0.5
                                        11.|-- ae7.ar02.mci102.googlefiber.net    0.0%    10  32.1  32.1  32.0  32.2  0.0
                                        12.|-- 23-255-225-17.mci.googlefiber.net  0.0%    10  32.1  32.1  32.1  32.2  0.0
                                        13.|-- 23-255-225-19.mci.googlefiber.net  0.0%    10  32.5  32.5  32.5  32.5  0.0
                                        14.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0

                                        23/12/2017 15:25:16 UTC

                                        1 Reply Last reply Reply Quote 0
                                        • DerelictD
                                          Derelict LAYER 8 Netgate
                                          last edited by

                                          So what is the perceived issue there?

                                          If you want your WAN port to respond to pings you have to enable a firewall rule on WAN passing ICMP source any dest WAN address.

                                          All unsolicited inbound traffic is blocked by default. Even pings.

                                          Chattanooga, Tennessee, USA
                                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                          1 Reply Last reply Reply Quote 0
                                          • E
                                            edseitzinger Banned
                                            last edited by

                                            @Derelict:

                                            So what is the perceived issue there?

                                            If you want your WAN port to respond to pings you have to enable a firewall rule on WAN passing ICMP source any dest WAN address.

                                            All unsolicited inbound traffic is blocked by default. Even pings.

                                            Ok I had forgotten about that…..

                                            Why do the first couple pings/tracert bottom out and the last few complete as normal????

                                            PING:
                                            PING MYEXTIP (MYEXTIP) 56(84) bytes of data.

                                            --- MYEXTIP ping statistics ---
                                            4 packets transmitted, 0 received, 100% packet loss, time 2999ms

                                            23/12/2017 20:06:53 UTC

                                            PING:
                                            PING MYEXTIP (MYEXTIP) 56(84) bytes of data.

                                            --- MYEXTIP ping statistics ---
                                            4 packets transmitted, 0 received, 100% packet loss, time 3000ms

                                            23/12/2017 20:06:53 UTC

                                            TRACEROUTE:
                                            traceroute to MYEXTIP (MYEXTIP), 15 hops max, 60 byte packets
                                            1  24.105.30.2 (24.105.30.2)  1.277 ms  1.879 ms  1.896 ms
                                            2  * * *
                                            3  137.221.66.2 (137.221.66.2)  1.372 ms  1.432 ms  1.502 ms
                                            4  137.221.68.66 (137.221.68.66)  1.236 ms  1.259 ms  1.288 ms
                                            5  137.221.68.32 (137.221.68.32)  0.955 ms  0.974 ms  0.978 ms
                                            6  * * *
                                            7  * * *
                                            8  * * *
                                            9  * * *
                                            10  * * *
                                            11  * * *
                                            12  * * *
                                            13  * * *
                                            14  * * *
                                            15  * * *

                                            23/12/2017 20:06:53 UTC

                                            TRACEROUTE:
                                            traceroute to MYEXTIP (MYEXTIP), 15 hops max, 60 byte packets
                                            1  24.105.30.2 (24.105.30.2)  1.390 ms  1.501 ms  1.520 ms
                                            2  * * *
                                            3  137.221.66.2 (137.221.66.2)  1.234 ms  1.299 ms  1.365 ms
                                            4  137.221.68.66 (137.221.68.66)  1.104 ms  1.200 ms  1.305 ms
                                            5  137.221.68.32 (137.221.68.32)  1.022 ms  1.049 ms  1.058 ms
                                            6  * * *
                                            7  * * *
                                            8  * * *
                                            9  * * *
                                            10  * * *
                                            11  * * *
                                            12  * * *
                                            13  * * *
                                            14  * * *
                                            15  * * *

                                            23/12/2017 20:06:53 UTC

                                            TRACEROUTE:
                                            traceroute to MYEXTIP (MYEXTIP), 15 hops max, 60 byte packets
                                            1  Blizzard (Blizzard)  0.535 ms  0.597 ms  0.706 ms
                                            2  * * *
                                            3  137.221.66.8 (137.221.66.8)  2.048 ms  2.163 ms  2.208 ms
                                            4  137.221.69.70 (137.221.69.70)  1.980 ms  2.014 ms  2.036 ms
                                            5  137.221.69.34 (137.221.69.34)  2.021 ms  2.028 ms  2.037 ms
                                            6  * * *
                                            7  * * *
                                            8  * * *
                                            9  192-119-18-202.mci.googlefiber.net (192.119.18.202)  31.584 ms  31.615 ms  31.620 ms
                                            10  192-119-18-186.mci.googlefiber.net (192.119.18.186)  32.917 ms  32.072 ms  32.102 ms
                                            11  ae7.ar02.mci102.googlefiber.net (192.119.17.69)  31.954 ms  31.887 ms  32.099 ms
                                            12  23-255-225-17.mci.googlefiber.net (23.255.225.17)  32.098 ms  32.108 ms  32.009 ms
                                            13  23-255-225-19.mci.googlefiber.net (23.255.225.19)  32.469 ms  32.482 ms  32.513 ms
                                            14  MYEXTIP (MYEXTIP)  33.482 ms  33.679 ms  33.665 ms

                                            23/12/2017 20:06:59 UTC

                                            PING:
                                            PING MYEXTIP (MYEXTIP) 56(84) bytes of data.
                                            64 bytes from MYEXTIP: icmp_seq=1 ttl=48 time=33.5 ms
                                            64 bytes from MYEXTIP: icmp_seq=2 ttl=48 time=33.6 ms
                                            64 bytes from MYEXTIP: icmp_seq=3 ttl=48 time=33.5 ms
                                            64 bytes from MYEXTIP: icmp_seq=4 ttl=48 time=33.6 ms

                                            --- MYEXTIP ping statistics ---
                                            4 packets transmitted, 4 received, 0% packet loss, time 3001ms
                                            rtt min/avg/max/mdev = 33.537/33.593/33.660/0.049 ms

                                            23/12/2017 20:06:59 UTC

                                            TRACEROUTE:
                                            traceroute to MYEXTIP (MYEXTIP), 15 hops max, 60 byte packets
                                            1  Blizzard (Blizzard)  0.746 ms  0.808 ms  0.930 ms
                                            2  * * *
                                            3  137.221.66.8 (137.221.66.8)  2.060 ms  2.141 ms  2.220 ms
                                            4  137.221.69.70 (137.221.69.70)  1.963 ms  1.989 ms  2.014 ms
                                            5  137.221.69.34 (137.221.69.34)  1.690 ms  2.297 ms  2.310 ms
                                            6  * * *
                                            7  * * *
                                            8  * * *
                                            9  192-119-18-202.mci.googlefiber.net (192.119.18.202)  31.505 ms  31.493 ms  31.482 ms
                                            10  192-119-18-186.mci.googlefiber.net (192.119.18.186)  32.280 ms  31.942 ms  31.965 ms
                                            11  ae7.ar02.mci102.googlefiber.net (192.119.17.69)  31.920 ms  31.906 ms  31.952 ms
                                            12  23-255-225-17.mci.googlefiber.net (23.255.225.17)  31.980 ms  31.952 ms  32.224 ms
                                            13  23-255-225-19.mci.googlefiber.net (23.255.225.19)  32.474 ms  32.494 ms  32.464 ms
                                            14  MYEXTIP (MYEXTIP)  33.655 ms  33.520 ms  33.520 ms

                                            23/12/2017 20:07:01 UTC

                                            PING:
                                            PING MYEXTIP (MYEXTIP) 56(84) bytes of data.
                                            64 bytes from MYEXTIP: icmp_seq=1 ttl=48 time=33.5 ms
                                            64 bytes from MYEXTIP: icmp_seq=2 ttl=48 time=33.6 ms
                                            64 bytes from MYEXTIP: icmp_seq=3 ttl=48 time=33.5 ms
                                            64 bytes from MYEXTIP: icmp_seq=4 ttl=48 time=33.7 ms

                                            --- MYEXTIP ping statistics ---
                                            4 packets transmitted, 4 received, 0% packet loss, time 2998ms
                                            rtt min/avg/max/mdev = 33.519/33.611/33.713/0.081 ms

                                            23/12/2017 20:07:03 UTC

                                            MTR:
                                            Start: Sat Dec 23 20:06:53 2017
                                            HOST: Blizzard Loss%  Snt  Last  Avg  Best  Wrst StDev
                                              1.|-- 24.105.30.2                0.0%    10  10.1  1.8  0.4  10.1  3.0
                                              2.|-- ???                        100.0    10    0.0  0.0  0.0  0.0  0.0
                                              3.|-- 137.221.66.2                0.0%    10    1.2  1.3  1.1  1.4  0.0
                                              4.|-- 137.221.68.66              0.0%    10    1.4  1.3  1.2  1.4  0.0
                                              5.|-- 137.221.68.32              0.0%    10    1.0  4.9  0.9  29.9  9.4
                                              6.|-- ???                        100.0    10    0.0  0.0  0.0  0.0  0.0

                                            23/12/2017 20:06:53 UTC

                                            MTR:
                                            Start: Sat Dec 23 20:06:53 2017
                                            HOST: Blizzard Loss%  Snt  Last  Avg  Best  Wrst StDev
                                              1.|-- 24.105.30.2                0.0%    10    0.8  0.8  0.5  1.8  0.0
                                              2.|-- ???                        100.0    10    0.0  0.0  0.0  0.0  0.0
                                              3.|-- 137.221.66.2                0.0%    10    1.1  1.3  1.1  1.4  0.0
                                              4.|-- 137.221.68.66              0.0%    10    1.4  1.6  1.2  4.1  0.7
                                              5.|-- 137.221.68.32              0.0%    10    1.0  1.4  0.9  5.4  1.3
                                              6.|-- ???                        100.0    10    0.0  0.0  0.0  0.0  0.0

                                            23/12/2017 20:06:53 UTC

                                            MTR:
                                            Start: Sat Dec 23 20:06:59 2017
                                            HOST: Blizzard        Loss%  Snt  Last  Avg  Best  Wrst StDev
                                              1.|-- Blizzard                      0.0%    10    0.5  0.6  0.4  0.8  0.0
                                              2.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                              3.|-- 137.221.66.8                        0.0%    10    2.0  2.0  1.9  2.2  0.0
                                              4.|-- 137.221.69.70                      0.0%    10    2.0  1.9  1.9  2.1  0.0
                                              5.|-- 137.221.69.34                      0.0%    10    1.7  2.9  1.7  12.8  3.4
                                              6.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                              7.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                              8.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                              9.|-- 192-119-18-202.mci.googlefiber.net  0.0%    10  31.6  31.6  31.5  31.7  0.0
                                            10.|-- 192-119-18-186.mci.googlefiber.net  0.0%    10  32.1  32.1  31.9  32.7  0.0
                                            11.|-- ae7.ar02.mci102.googlefiber.net    0.0%    10  32.0  32.0  31.9  32.3  0.0
                                            12.|-- 23-255-225-17.mci.googlefiber.net  0.0%    10  32.0  32.1  32.0  32.2  0.0
                                            13.|-- 23-255-225-19.mci.googlefiber.net  0.0%    10  32.4  32.5  32.4  32.5  0.0
                                            14.|-- MYEXTIP                        0.0%    10  33.7  33.6  33.0  33.8  0.0

                                            23/12/2017 20:06:58 UTC

                                            MTR:
                                            Start: Sat Dec 23 20:07:00 2017
                                            HOST: Blizzard        Loss%  Snt  Last  Avg  Best  Wrst StDev
                                              1.|-- Blizzard                      0.0%    10    0.5  0.6  0.4  0.7  0.0
                                              2.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                              3.|-- 137.221.66.8                        0.0%    10    2.1  2.1  2.0  2.2  0.0
                                              4.|-- 137.221.69.70                      0.0%    10    2.0  2.0  1.9  2.2  0.0
                                              5.|-- 137.221.69.34                      0.0%    10    1.9  1.8  1.7  2.0  0.0
                                              6.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                              7.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                              8.|-- ???                                100.0    10    0.0  0.0  0.0  0.0  0.0
                                              9.|-- 192-119-18-202.mci.googlefiber.net  0.0%    10  31.6  31.6  31.5  31.6  0.0
                                            10.|-- 192-119-18-186.mci.googlefiber.net  0.0%    10  32.0  32.1  32.0  32.3  0.0
                                            11.|-- ae7.ar02.mci102.googlefiber.net    0.0%    10  32.0  32.0  32.0  32.1  0.0
                                            12.|-- 23-255-225-17.mci.googlefiber.net  0.0%    10  32.1  32.1  32.0  32.7  0.0
                                            13.|-- 23-255-225-19.mci.googlefiber.net  0.0%    10  32.5  32.5  32.4  32.5  0.0
                                            14.|-- MYEXTIP                        0.0%    10  33.8  33.6  33.5  33.8  0.0

                                            23/12/2017 20:07:00 UTC

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.