Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2.5 with many tunnels - Apply Changes fails

    Scheduled Pinned Locked Moved IPsec
    21 Posts 2 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • vergilisV
      vergilis
      last edited by

      It was stuck on this screen for about 4 minutes.

      bootup-ipsec-issue.png

      Please let me know if you need anything else.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        That g_vfs_done line implies it's having problems communicating with its storage.

        You may have some other problem in your hypervisor/guest config which is causing it to perform slower than it should, leading to your timerout.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • vergilisV
          vergilis
          last edited by

          Only post 2.5 upgrade and only for IpSec tunnels?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            Yes, it's common for hypervisors to need adjustments when moving from one FreeBSD version to another, depending on your settings.

            It may not be related to IPsec at all, just that it's something that is time consuming and provokes the general slowness.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • vergilisV
              vergilis
              last edited by

              Thank you.

              What is your recommendation to correct this?

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                That depends on your hypervisor and guest settings, I don't have any general recommendations there other than to check what your hypervisor recommends for use with FreeBSD 12.2 (or at least 12.x).

                Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • vergilisV
                  vergilis
                  last edited by

                  This is an AWS instance with your approved image and size. This is a c5n.large.

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    Then I suggest you redeploy it instead of upgrading in-place to see if the problem happens that way.

                    Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • vergilisV
                      vergilis
                      last edited by

                      When I load the XML file into a new instance, your software produces the same timeout issue and the XML never loads.

                      Any other ideas?

                      1 Reply Last reply Reply Quote 0
                      • vergilisV
                        vergilis
                        last edited by

                        Also, after a few attempts it loaded. It continues to hang in the same spot during boot up, and actually does not boot up at all. I don't think that its hardware or disk related.

                        Please let me know how you would like to proceed.

                        1 Reply Last reply Reply Quote 0
                        • jimpJ
                          jimp Rebel Alliance Developer Netgate
                          last edited by

                          Is there any way you can try at least loading the IPsec portion of that configuration in a non-AWS system?

                          It's difficult to tell if it's related to IPsec or if there is a general problem with AWS.

                          The only other potentially-related report I've seen is a report of a kernel panic on AWS with someone that has even more IPsec tunnels than you, but as far as I'm aware they were not experiencing any slowness or boot delays.

                          Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                          Need help fast? Netgate Global Support!

                          Do not Chat/PM for help!

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.