Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense on ESXi | Best Practices

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    pfsense 2.4.4networkingnetwork problemswitchesxi 6.7
    23 Posts 4 Posters 3.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • kiokomanK
      kiokoman LAYER 8
      last edited by

      imho probably your ISP, ping your isp gateway and see if you have the same problem, if it work without problem do a traceroute and ping every single hop until you find what is timing out, after that call your ISP
      also check if all your cable are in good condition

      ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
      Please do not use chat/PM to ask for help
      we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
      Don't forget to Upvote with the 👍 button for any post you find to be helpful.

      1 Reply Last reply Reply Quote 0
      • mohkhalifaM
        mohkhalifa
        last edited by

        I tried without pfSense directly connected to WAN VLAN, everything working fine without any problem which means it's pfSense problem 100%

        1 Reply Last reply Reply Quote 0
        • kiokomanK
          kiokoman LAYER 8
          last edited by kiokoman

          esxcli network nic tso set --enable=0 -n vmnic0
          esxcli network nic cso set --enable=0 -n vmnic0
          ?
          i'm pretty sure it's not a pfsense problem
          try to use another physical network interface card to connect the virtual switch to the physical switch to eliminate physical problems.
          Immagine.jpg

          esxi version? ESXi 6.0 is known to have host loses network connectivity randomly
          check /var/log/vmkernel.log file, if there is evidence of transmit timeouts

          also check if this article can help you
          https://kb.vmware.com/s/article/1004109

          ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
          Please do not use chat/PM to ask for help
          we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
          Don't forget to Upvote with the 👍 button for any post you find to be helpful.

          mohkhalifaM 1 Reply Last reply Reply Quote 0
          • mohkhalifaM
            mohkhalifa @kiokoman
            last edited by

            Thanks @kiokoman for you help, really appropriated. But why when I directly connected the WAN without pfSense everything goes fine ? also I tried to change the adapter type from e1000 to VMNET3 and the same problem !!

            1 Reply Last reply Reply Quote 0
            • RicoR
              Rico LAYER 8 Rebel Alliance
              last edited by

              Again: Latest VMware Tools installed?

              -Rico

              mohkhalifaM 2 Replies Last reply Reply Quote 0
              • mohkhalifaM
                mohkhalifa @Rico
                last edited by

                @Rico yes sure

                1 Reply Last reply Reply Quote 0
                • mohkhalifaM
                  mohkhalifa @Rico
                  last edited by

                  @Rico Open-VM-Tools v10.1.0_2,1

                  1 Reply Last reply Reply Quote 0
                  • kiokomanK
                    kiokoman LAYER 8
                    last edited by

                    did you set traffic shaping or load balancing on the vswitch ?

                    ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                    Please do not use chat/PM to ask for help
                    we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                    Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                    mohkhalifaM 1 Reply Last reply Reply Quote 0
                    • mohkhalifaM
                      mohkhalifa @kiokoman
                      last edited by

                      @kiokoman NO

                      1 Reply Last reply Reply Quote 0
                      • kiokomanK
                        kiokoman LAYER 8
                        last edited by kiokoman

                        i'm tring to mess as much as i can with my vm but i'm unable to reproduce it
                        can you do a test with pfsense 2.5.0-devel ?
                        also i found this about the vmx driver
                        https://www.freebsd.org/cgi/man.cgi?query=vmx&sektion=4
                        ethernet0.virtualDev="vmxnet3" i have it inside the virtual machine configuration and
                        The hw.pci.honor_msi_blacklist tunable must be disabled to enable MSI-X support.
                        i have it set on my
                        /boot/loader.conf.local

                        hw.pci.honor_msi_blacklist="0"
                        

                        also i found this but idk if it's still relevant
                        https://forum.netgate.com/topic/88082/esxi-5-5-packet-loss/12

                        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                        Please do not use chat/PM to ask for help
                        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                        1 Reply Last reply Reply Quote 0
                        • B
                          bbrendon
                          last edited by

                          I have a bunch of pfsense instances running in ESXi. No issues. All 2.4.4-p3 and 2.4.5-RC.

                          1 Reply Last reply Reply Quote 0
                          • RicoR
                            Rico LAYER 8 Rebel Alliance
                            last edited by

                            Yeah I don't think this problem is pfSense related.
                            Can you spin up two more VMs for testing? One with vanilla FreeBSD 11.2 and another with Linux or Windows. Check if the timeouts happen in one or both test VMs.

                            -Rico

                            1 Reply Last reply Reply Quote 0
                            • mohkhalifaM
                              mohkhalifa
                              last edited by

                              problem SOLVED after "Disabling hardware checksum offload"

                              B 1 Reply Last reply Reply Quote 0
                              • kiokomanK
                                kiokoman LAYER 8
                                last edited by kiokoman

                                🤦 🤦
                                i told you 4 days ago to disable cso "esxcli network nic cso set --enable=0 -n vmnic0"
                                but i forgot to tell you to disable it from the pfsense gui

                                ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                                Please do not use chat/PM to ask for help
                                we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                                Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                                mohkhalifaM 1 Reply Last reply Reply Quote 0
                                • mohkhalifaM
                                  mohkhalifa @kiokoman
                                  last edited by

                                  @kiokoman 😱 😱 😱

                                  1 Reply Last reply Reply Quote 0
                                  • B
                                    bbrendon @mohkhalifa
                                    last edited by

                                    @mohkhalifa said in pfSense on ESXi | Best Practices:

                                    problem SOLVED after "Disabling hardware checksum offload"

                                    Awesome. I poked around on a few of mine and didn't find any with that enabled. Mostly Dell hardware here. Good find.

                                    1 Reply Last reply Reply Quote 1
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.