Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WAN interface stops working every few days.

    Scheduled Pinned Locked Moved General pfSense Questions
    54 Posts 8 Posters 7.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      No, an outbound NAT rule will not be doing anything.

      Traffic shaping is far more likely. Assuming it's anything config related.

      Steve

      1 Reply Last reply Reply Quote 0
      • G
        gawainxx
        last edited by gawainxx

        Ok, I reloaded everything, with the exception that I imported the VPN config, certs and firewall rules because those would have been a royal PITA to rebuild.

        Problem still persists.

        There have been several times in the past few weeks where I suddenly got very high latency and packet loss but it resolved itself after a couple of minutes.

        Somehow using my main workstation for the first time in a day seems like it could be attributing to the issue, it seems like the behavior occurs 5-10 minutes after I've powered that system on...? I can't think of why a single system could cause the WAN interface of pfsense to behave like this though?

        I'm getting towards the end of my list of ideas and could desperately use some solutions.

        I've just connected my centurylink C3000z in bridge mode and placed pfsense behind that, seeing if perhaps letting the centurylink "modem" handle the VLAN tagging makes some difference?

        Here is a copy of my config, I have scrubbed anything cert or credential related from it.
        1599534090821-config_scrubbed.xml

        I'm getting down towards my last options which would be to purchase another desktop for the explicit purpose of temporarily running it as the pfsense sever to test if it's somehow a host issue or using my spare ASUS router (This would cause me a lot of headaches as I would have to reconfigure my entire home network, stripping out vlans and resubnetting all of my vms, devices.)

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          The TTL exceeded message you are seeing from upstream when it happens still makes it look like some upstream routing problem to me.

          If you are able to use the ISP router in there as a test though that would rule out an obscure pfSense issue.

          Steve

          G 1 Reply Last reply Reply Quote 0
          • Cool_CoronaC
            Cool_Corona
            last edited by

            What version of pfsense??

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              It's 2.4.5p1. Because, yeah, this sure looks like #10414 in 2.4.5. ๐Ÿ˜‰

              G 1 Reply Last reply Reply Quote 0
              • G
                gawainxx @stephenw10
                last edited by

                @stephenw10 said in WAN interface stops working every few days.:

                The TTL exceeded message you are seeing from upstream when it happens still makes it look like some upstream routing problem to me.

                If you are able to use the ISP router in there as a test though that would rule out an obscure pfSense issue.

                Steve

                I'm not using the ISP router for routing or dhcp atm, just handling the vlan tagged traffic to see if it has any influence...
                I may have to suffer and try running a double NAT for a week or two though to see if the behaviour persists when ISP router handles traffic.

                1 Reply Last reply Reply Quote 0
                • G
                  gawainxx @stephenw10
                  last edited by

                  @stephenw10 said in WAN interface stops working every few days.:

                  It's 2.4.5p1. Because, yeah, this sure looks like #10414 in 2.4.5. ๐Ÿ˜‰

                  Interesting, I'll need to take a close look at that thread later. The webui does definately take several seconds to load when I initially try to access it while the gateway issues are occuring

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    If you are somehow hitting that still you would see high latency to the firewall itself from a LAN side client everytime you ran Status > Filter reload.

                    Steve

                    G 1 Reply Last reply Reply Quote 0
                    • G
                      gawainxx @stephenw10
                      last edited by

                      @stephenw10

                      hmm, manually doing a filter reload caused the ping to firewall to jump from 1 to 100ms for a single ping but nothing noteworthy aside from that.

                      I am however still using the ISP "Modem" (Truly a router) to handle the VLAN tagging, which i set up last night.

                      hugoeyngH 1 Reply Last reply Reply Quote 0
                      • hugoeyngH
                        hugoeyng @gawainxx
                        last edited by

                        @gawainxx I already faced this kind of trouble.
                        The latency starts growing until th Wan interface stops working.
                        A (not) solution was to turn monitoring IP to of.

                        Then I changed my ISP and both, the trouble and the ISP, desappeared.

                        I love pfSense!

                        Hugo Eyng
                        Datamais Sistemas

                        G 2 Replies Last reply Reply Quote 0
                        • G
                          gawainxx @hugoeyng
                          last edited by

                          @hugoeyng said in WAN interface stops working every few days.:

                          @gawainxx I already faced this kind of trouble.
                          The latency starts growing until th Wan interface stops working.
                          A (not) solution was to turn monitoring IP to of.

                          Then I changed my ISP and both, the trouble and the ISP, desappeared.

                          To verify, you changed the monitoring function/action off?
                          I'll add that to my to-do list.
                          Unfortunately the speed with my ISP is awesome and the pricing is reliable, unlike Comcast. I'd rather not go to Comcast if I can help it as it's tiresome to negotiate pricing once every year.

                          hugoeyngH 1 Reply Last reply Reply Quote 0
                          • K
                            kuradeel
                            last edited by

                            One more thing to check, is it possible that your machine is overheating? Specifically the network card? I've had a situation where the network card was malfunctioning and a reboot of the machine would not fix it. I physically had to shut the entire machine down (remove power) in order to fix the problem. I think it stems from the network card in particular overheating. If you have something blocking the airflow or the processors on the network card do not have heatsinks, then perhaps it's that. I had issues with a Broadcom card just generally so I switched to Intel and haven't looked back, except for when I have an overheating issue. Sounds like you have the issue at or around noon? Go on eBay and get something like the INTEL EXPI9404PTL PRO/1000 PT Quad Port PCIe card for like $30. Intel makes the best gigabit cards in my opinion.

                            G 1 Reply Last reply Reply Quote 0
                            • G
                              gawainxx @kuradeel
                              last edited by gawainxx

                              @kuradeel
                              I doubt it, the r210 ii has excellent airflow and mobo, proc temps are all green.

                              This has happened with onboard as well as 3 different PCIe NICs 2x broadcom, 1x Intel all different chips

                              1 Reply Last reply Reply Quote 0
                              • G
                                gawainxx @hugoeyng
                                last edited by

                                @hugoeyng said in WAN interface stops working every few days.:

                                @gawainxx I already faced this kind of trouble.
                                The latency starts growing until th Wan interface stops working.
                                A (not) solution was to turn monitoring IP to of.

                                Then I changed my ISP and both, the trouble and the ISP, desappeared.

                                Did already established connections continue to work without issue?

                                IE if I'm using splashtop and connected controlling a remote desktop I'm able to continue using it with no speed delay, however I'd be unable to reconnect once I disconnect.

                                hugoeyngH 1 Reply Last reply Reply Quote 0
                                • hugoeyngH
                                  hugoeyng @gawainxx
                                  last edited by

                                  @gawainxx System/Routing/Gateways
                                  Edit the Gateway and disable monitoring.

                                  e546fcfc-04c9-4b93-b63a-1b1b91045ceb-image.png

                                  Remembering that it is not a solution but a way to get it working.

                                  I love pfSense!

                                  Hugo Eyng
                                  Datamais Sistemas

                                  G 1 Reply Last reply Reply Quote 0
                                  • hugoeyngH
                                    hugoeyng @gawainxx
                                    last edited by

                                    @gawainxx I am not able to answer this question.

                                    I love pfSense!

                                    Hugo Eyng
                                    Datamais Sistemas

                                    1 Reply Last reply Reply Quote 0
                                    • G
                                      gawainxx @hugoeyng
                                      last edited by

                                      @hugoeyng said in WAN interface stops working every few days.:

                                      @gawainxx System/Routing/Gateways
                                      Edit the Gateway and disable monitoring.

                                      e546fcfc-04c9-4b93-b63a-1b1b91045ceb-image.png

                                      Remembering that it is not a solution but a way to get it working.

                                      Crapped out again, going to give this a try to see if it makes a difference.

                                      G 1 Reply Last reply Reply Quote 0
                                      • G
                                        gawainxx @gawainxx
                                        last edited by

                                        Nope, Issue occured again 1 hour later....

                                        Guess I'm going to throw the ISP's provided "Modem" (router) in as my main internet and double nat for a bit so that I can rule out whether it's something weird with PPPOE in pfsense, it'll also give me an escalation path as I'd be using the ISP's hardware.....

                                        Port forwarding configuration with this config is going to suck though.

                                        A 1 Reply Last reply Reply Quote 0
                                        • A
                                          akuma1x @gawainxx
                                          last edited by

                                          @gawainxx Lots of ISP modems have a "DMZ" feature. You could use this, if available, since it will pass ALL (or most) ports right into the pfsense WAN port. Once there, you can deal with the pfsense box doing the port forwarding, like it was at the edge of your network.

                                          Jeff

                                          G 1 Reply Last reply Reply Quote 0
                                          • G
                                            gawainxx @akuma1x
                                            last edited by

                                            @akuma1x said in WAN interface stops working every few days.:

                                            @gawainxx Lots of ISP modems have a "DMZ" feature. You could use this, if available, since it will pass ALL (or most) ports right into the pfsense WAN port. Once there, you can deal with the pfsense box doing the port forwarding, like it was at the edge of your network.

                                            Jeff

                                            Thanks, I'm working with this right now. This should help me rule out pfsense because i can directly interface with the modem if needed and this provices a path for escalating with the ISP.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.