Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    diag_traceroute

    Scheduled Pinned Locked Moved General pfSense Questions
    18 Posts 4 Posters 1.6k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • yon 0Y Offline
      yon 0
      last edited by

      how i add more run time for traceroute?

      diag_traceroute.php
      504 Gateway Time-out
      nginx

      1 Reply Last reply Reply Quote 0
      • stephenw10S Online
        stephenw10 Netgate Administrator
        last edited by

        If you're hitting that using the webgui utility there is probably no route.
        But you should run traceroute from the CLI instead if you need to see extreme timespans.

        Steve

        1 Reply Last reply Reply Quote 0
        • yon 0Y Offline
          yon 0
          last edited by

          when checked Reverse Address Lookup, will happen this issuse.

          1 Reply Last reply Reply Quote 0
          • stephenw10S Online
            stephenw10 Netgate Administrator
            last edited by

            Ok, so something in your route is taking so long to respond the php process times out.

            If you need to do that run it from the CLI.

            Steve

            1 Reply Last reply Reply Quote 0
            • jimpJ Offline
              jimp Rebel Alliance Developer Netgate
              last edited by

              Also consider using the mtr package instead of traceroute.

              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • yon 0Y Offline
                yon 0
                last edited by

                MTR has no the Source Address option.

                1 Reply Last reply Reply Quote 0
                • jimpJ Offline
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  The program itself supports it at the console (-a x.x.x.x) it's just not in the GUI yet.

                  Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • RicoR Offline
                    Rico LAYER 8 Rebel Alliance
                    last edited by

                    Hmmmm when using mtr -a <SOURCE IP WAN2> <TARGET> from command line
                    I still see my 'WAN' Interface as Source when checking Diagnostics > States
                    Any idea?

                    -Rico

                    1 Reply Last reply Reply Quote 0
                    • RicoR Offline
                      Rico LAYER 8 Rebel Alliance
                      last edited by

                      Sorry for not being clear: The mtr path looks like the correct one, it is really sourcing my WAN2.
                      Just curious the states show WAN Interface...

                      -Rico

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S Online
                        stephenw10 Netgate Administrator
                        last edited by

                        The state already existed?

                        You have a specific route to the target via WAN1?

                        You would not normally have outbound NAT for WAN2 from WAN1 so it would fail.

                        Does a pcap show it actually leaving WAN2?

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • RicoR Offline
                          Rico LAYER 8 Rebel Alliance
                          last edited by

                          Hi Steve, thanks for your reply.

                          @stephenw10 said in diag_traceroute:

                          The state already existed?

                          No existing state before my MTR testing, I can reproduce this with any target anyway.

                          @stephenw10 said in diag_traceroute:

                          You have a specific route to the target via WAN1?

                          No, the target can be any random Internet host.
                          System > Routing > Static Routes
                          is empty.

                          @stephenw10 said in diag_traceroute:

                          You would not normally have outbound NAT for WAN2 from WAN1 so it would fail.

                          I'm on Automatic outbound NAT with this pfSense installation.

                          @stephenw10 said in diag_traceroute:

                          Does a pcap show it actually leaving WAN2?

                          Yes, pcap show the MTR traffic leaving WAN2.

                          -Rico

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S Online
                            stephenw10 Netgate Administrator
                            last edited by

                            Hmm, OK so in fact the state table is just showing it on the wrong interface? The traffic is actually leaving correctly...

                            Does it also show incorrect in pfctl -ss?

                            Steve

                            1 Reply Last reply Reply Quote 0
                            • RicoR Offline
                              Rico LAYER 8 Rebel Alliance
                              last edited by

                              Yes it shows wrong in pfctl -ss (igb0 (WAN)).
                              Hmmm maybe because my Default gateway IPv4 is a Gateway group with WANGW Tier 1 and WAN2GW Tier 2?
                              The system is in production with a lot of traffic, I can't poke around there and play with the Gateways atm.

                              -Rico

                              1 Reply Last reply Reply Quote 0
                              • RicoR Offline
                                Rico LAYER 8 Rebel Alliance
                                last edited by

                                I just tried in my home lab with the same weird behavior.
                                It has nothing to do with the gateway group, same happens with Default gateway IPv4 set to automatic or WANGW.
                                When switching Default gateway IPv4 to WAN2GW the state shows correct of course, but the problem is just vice versa when sourcing MTR from the WAN IP, it's showing WAN2 in states.

                                -Rico

                                1 Reply Last reply Reply Quote 0
                                • stephenw10S Online
                                  stephenw10 Netgate Administrator
                                  last edited by

                                  Hmm, if you put a floating outbound block rule on WAN1 for the target IP does it actually block it?

                                  1 Reply Last reply Reply Quote 0
                                  • RicoR Offline
                                    Rico LAYER 8 Rebel Alliance
                                    last edited by

                                    Yeah it's blocked then and MTR showing mtr: Unexpected mtr-packet error

                                    -Rico

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S Online
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      Hmm, so pf is actually seeing that traffic on WAN1 even though it's leaving WAN2?

                                      Not sure how that could happen...

                                      What hardware are you testing that on? What are the WAN interfaces there?

                                      Steve

                                      1 Reply Last reply Reply Quote 0
                                      • RicoR Offline
                                        Rico LAYER 8 Rebel Alliance
                                        last edited by

                                        The system in production I've seen this first is SG-5100 with WAN igb0 and WAN2 ix1.
                                        My lab testing is VMware.

                                        -Rico

                                        1 Reply Last reply Reply Quote 0
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.