Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense on ESXi | Best Practices

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    pfsense 2.4.4networkingnetwork problemswitchesxi 6.7
    23 Posts 4 Posters 3.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • mohkhalifaM
      mohkhalifa
      last edited by

      I tried without pfSense directly connected to WAN VLAN, everything working fine without any problem which means it's pfSense problem 100%

      1 Reply Last reply Reply Quote 0
      • kiokomanK
        kiokoman LAYER 8
        last edited by kiokoman

        esxcli network nic tso set --enable=0 -n vmnic0
        esxcli network nic cso set --enable=0 -n vmnic0
        ?
        i'm pretty sure it's not a pfsense problem
        try to use another physical network interface card to connect the virtual switch to the physical switch to eliminate physical problems.
        Immagine.jpg

        esxi version? ESXi 6.0 is known to have host loses network connectivity randomly
        check /var/log/vmkernel.log file, if there is evidence of transmit timeouts

        also check if this article can help you
        https://kb.vmware.com/s/article/1004109

        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
        Please do not use chat/PM to ask for help
        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

        mohkhalifaM 1 Reply Last reply Reply Quote 0
        • mohkhalifaM
          mohkhalifa @kiokoman
          last edited by

          Thanks @kiokoman for you help, really appropriated. But why when I directly connected the WAN without pfSense everything goes fine ? also I tried to change the adapter type from e1000 to VMNET3 and the same problem !!

          1 Reply Last reply Reply Quote 0
          • RicoR
            Rico LAYER 8 Rebel Alliance
            last edited by

            Again: Latest VMware Tools installed?

            -Rico

            mohkhalifaM 2 Replies Last reply Reply Quote 0
            • mohkhalifaM
              mohkhalifa @Rico
              last edited by

              @Rico yes sure

              1 Reply Last reply Reply Quote 0
              • mohkhalifaM
                mohkhalifa @Rico
                last edited by

                @Rico Open-VM-Tools v10.1.0_2,1

                1 Reply Last reply Reply Quote 0
                • kiokomanK
                  kiokoman LAYER 8
                  last edited by

                  did you set traffic shaping or load balancing on the vswitch ?

                  ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                  Please do not use chat/PM to ask for help
                  we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                  Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                  mohkhalifaM 1 Reply Last reply Reply Quote 0
                  • mohkhalifaM
                    mohkhalifa @kiokoman
                    last edited by

                    @kiokoman NO

                    1 Reply Last reply Reply Quote 0
                    • kiokomanK
                      kiokoman LAYER 8
                      last edited by kiokoman

                      i'm tring to mess as much as i can with my vm but i'm unable to reproduce it
                      can you do a test with pfsense 2.5.0-devel ?
                      also i found this about the vmx driver
                      https://www.freebsd.org/cgi/man.cgi?query=vmx&sektion=4
                      ethernet0.virtualDev="vmxnet3" i have it inside the virtual machine configuration and
                      The hw.pci.honor_msi_blacklist tunable must be disabled to enable MSI-X support.
                      i have it set on my
                      /boot/loader.conf.local

                      hw.pci.honor_msi_blacklist="0"
                      

                      also i found this but idk if it's still relevant
                      https://forum.netgate.com/topic/88082/esxi-5-5-packet-loss/12

                      ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                      Please do not use chat/PM to ask for help
                      we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                      Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                      1 Reply Last reply Reply Quote 0
                      • B
                        bbrendon
                        last edited by

                        I have a bunch of pfsense instances running in ESXi. No issues. All 2.4.4-p3 and 2.4.5-RC.

                        1 Reply Last reply Reply Quote 0
                        • RicoR
                          Rico LAYER 8 Rebel Alliance
                          last edited by

                          Yeah I don't think this problem is pfSense related.
                          Can you spin up two more VMs for testing? One with vanilla FreeBSD 11.2 and another with Linux or Windows. Check if the timeouts happen in one or both test VMs.

                          -Rico

                          1 Reply Last reply Reply Quote 0
                          • mohkhalifaM
                            mohkhalifa
                            last edited by

                            problem SOLVED after "Disabling hardware checksum offload"

                            B 1 Reply Last reply Reply Quote 0
                            • kiokomanK
                              kiokoman LAYER 8
                              last edited by kiokoman

                              🤦 🤦
                              i told you 4 days ago to disable cso "esxcli network nic cso set --enable=0 -n vmnic0"
                              but i forgot to tell you to disable it from the pfsense gui

                              ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                              Please do not use chat/PM to ask for help
                              we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                              Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                              mohkhalifaM 1 Reply Last reply Reply Quote 0
                              • mohkhalifaM
                                mohkhalifa @kiokoman
                                last edited by

                                @kiokoman 😱 😱 😱

                                1 Reply Last reply Reply Quote 0
                                • B
                                  bbrendon @mohkhalifa
                                  last edited by

                                  @mohkhalifa said in pfSense on ESXi | Best Practices:

                                  problem SOLVED after "Disabling hardware checksum offload"

                                  Awesome. I poked around on a few of mine and didn't find any with that enabled. Mostly Dell hardware here. Good find.

                                  1 Reply Last reply Reply Quote 1
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.