Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Running out of memory on SG-1100 on pfblockerng updates

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    13 Posts 5 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      Enabling SWAP on the SG-1100 would not be at all straight forward if it's in fact possible.
      But it would be a bad idea anyway. The eMMC would likely be horribly slow for use as SWAP and it would massively increase the write cycles.

      In general if you see pfSense using SWAP on systems that have it enabled it's usually a sign that something is misconfigured anyway.

      Steve

      N 1 Reply Last reply Reply Quote 1
      • N
        nheath @stephenw10
        last edited by

        @stephenw10 That is what I was curious about.

        The data point about unbound being stopped during the update may be the actual issue as it takes the SG-1110 a long time to parse.

        1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan
          last edited by

          Exact.

          The size of this list :

          808ab347-0350-4aae-b54c-b422ed38d333-image.png

          should be reasonable.
          That is, a "8 core 3Ghz 32 Gbytes RAM" system could handle more as a SG 1100. Up to you to decide when you reach the point of saturation.
          Normally, pfBlockerNG-devel shouldn't restart unbound to often :

          /var/log: grep 'Restart' resolver.log
          .....
          Oct 16 16:01:02 pfsense unbound: [68926:0] notice: Restart of unbound 1.10.1.
          
          

          = 7 days for me.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          N 1 Reply Last reply Reply Quote 0
          • N
            nheath @Gertjan
            last edited by

            @Gertjan I was under the impression that it reloads unbound on the cron schedule (though I thought I have mine set for 3am but it seems to do it at midnight still) and the update schedule for each list (weekly, daily).

            1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan
              last edited by

              Check who is actually restarting Unbound ;)

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 1
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Unbound loads a test file before it restarts to be sure it is valid and that requires holding double the config in RAM at that point. That's why it sometimes fails to update but RAM usage looks OK once it's running.
                pfBlocker updates the lists on the Cron schedule but will not restart Unbound if there has been no change to them.

                Steve

                DaddyGoD 1 Reply Last reply Reply Quote 0
                • DaddyGoD
                  DaddyGo @stephenw10
                  last edited by

                  @stephenw10 said in Running out of memory on SG-1100 on pfblockerng updates:

                  pfBlocker updates the lists on the Cron schedule but will not restart Unbound if there has been no change to them.

                  Hi Steve,

                  yes this is true, but honestly -when there is no change (a tiny) in the lists...?

                  I have to say, that out of the 100 update forced by cron the UNBOUND restarts 90 times...

                  Cats bury it so they can't see it!
                  (You know what I mean if you have a cat)

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by stephenw10

                    For most lists that's true, they are usually quite dynamic. But certainly not all. It just depends what lists you're using. And remember that's only the lists for DNS-BL not the IP lists.

                    Steve

                    DaddyGoD 1 Reply Last reply Reply Quote 0
                    • DaddyGoD
                      DaddyGo @stephenw10
                      last edited by

                      @stephenw10 said in Running out of memory on SG-1100 on pfblockerng updates:

                      But certainly not all.

                      Yes, yes I agree, but

                      I will only present the facts which we observed....
                      My opinion is, use a list that is well maintained, so your/his/her "update frequency" should be at least a couple of days or a week

                      otherwise the lists, which are old or unmaintained, do not serve their purpose and not to mention the many FPs they can cause....

                      Cats bury it so they can't see it!
                      (You know what I mean if you have a cat)

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        I agree. But if you have pfBlocker set to update lists every hour I would not expect it to restart Unbound every time.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.