• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

pfSense Plus 21.02-p1 Now Available

Scheduled Pinned Locked Moved Messages from the pfSense Team
26 Posts 13 Posters 6.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    dennis_s
    last edited by Feb 25, 2021, 5:05 PM

    pfSense Plus version 21.02-p1 is now available. This minor release addresses a bug that causes stability and performance issues on Netgate SG-3100 security gateway appliances.

    We also have published a more in-depth blog that details what exactly was happening.

    R C T 3 Replies Last reply Feb 25, 2021, 9:13 PM Reply Quote 12
    • R
      rsherwood_va @dennis_s
      last edited by Feb 25, 2021, 9:13 PM

      @dennis_s Thanks for posting the blog post. Interesting and helpful.

      M 1 Reply Last reply Feb 25, 2021, 9:58 PM Reply Quote 1
      • M
        mcury Rebel Alliance @rsherwood_va
        last edited by Feb 25, 2021, 9:58 PM

        Hi,

        I'm facing the same problem with this version..
        Downloaded the image, so it's a clean install.

        This happens with pfblockerNG, same configuration as before, just ran the wizard.
        Can you please check and advise?

        26c17745-a392-423f-87e3-ac2a795998e5-image.png

        dead on arrival, nowhere to be found.

        M 1 Reply Last reply Feb 25, 2021, 10:11 PM Reply Quote 0
        • M
          mcury Rebel Alliance @mcury
          last edited by Feb 25, 2021, 10:11 PM

          Opened a TAC ticket, attached my full xml config, and described the actions taken to trigger the problem.
          TAC: 76936

          dead on arrival, nowhere to be found.

          K 1 Reply Last reply Feb 25, 2021, 10:23 PM Reply Quote 0
          • K
            kphillips Administrator Netgate @mcury
            last edited by Feb 25, 2021, 10:23 PM

            @mcury I'm assuming you're referring to the Segmentation fault error? If so you likely have an issue with the package. I see your ticket and we will reply to it whenever we're able to do so.

            M 1 Reply Last reply Feb 25, 2021, 10:25 PM Reply Quote 0
            • M
              mcury Rebel Alliance @kphillips
              last edited by Feb 25, 2021, 10:25 PM

              @kphillips said in pfSense Plus 21.02-p1 Now Available:

              I'm assuming you're referring to the Segmentation fault error?

              Hello kphillips, hope you are doing fine.
              Yes it is, same error as we spoke previously.

              Kindly check and advise if I can help you with more information, thanks.

              dead on arrival, nowhere to be found.

              1 Reply Last reply Reply Quote 0
              • S
                stephenw10 Netgate Administrator
                last edited by Feb 25, 2021, 10:48 PM

                Just to confirm you were seeing that in 21.02 also?

                The p1 release addresses only https://redmine.pfsense.org/issues/11444.
                If we had included any additional fixes or updates it would have required a lot more testing and delayed the fix release significantly. That particular issue was impacting SG-3100 severely.

                What you're seeing here does not appear to be that.

                Steve

                M 1 Reply Last reply Feb 25, 2021, 11:37 PM Reply Quote 0
                • M
                  mcury Rebel Alliance @stephenw10
                  last edited by Feb 25, 2021, 11:37 PM

                  @stephenw10 said in pfSense Plus 21.02-p1 Now Available:

                  Just to confirm you were seeing that in 21.02 also?

                  The p1 release addresses only https://redmine.pfsense.org/issues/11444.
                  If we had included any additional fixes or updates it would have required a lot more testing and delayed the fix release significantly. That particular issue was impacting SG-3100 severely.

                  What you're seeing here does not appear to be that.

                  Steve

                  Hello stephenw10,
                  Yes, I was seeing this same behavior in 21.02.

                  It happens only with pfblockerNG-devel 3.0.0_10 installed.
                  Didn't test with pfblockerNG 2.1.4_24.

                  This happens during a reboot, after installing and configuring this package.
                  Without it, I can't see any problems.

                  dead on arrival, nowhere to be found.

                  M 1 Reply Last reply Feb 25, 2021, 11:49 PM Reply Quote 0
                  • M
                    mcury Rebel Alliance @mcury
                    last edited by Feb 25, 2021, 11:49 PM

                    inside this link: https://redmine.pfsense.org/issues/11444

                    Check the file OS-Message Buffer.txt

                    dead on arrival, nowhere to be found.

                    1 Reply Last reply Reply Quote 0
                    • C
                      costanzo @dennis_s
                      last edited by Feb 26, 2021, 12:29 AM

                      @dennis_s I am experiencing random reboots with my SG-1100 since upgrading to 21.02. I applied the p1 update; however, still seeing random reboots. They seem to occur once or twice in a day, with no pattern.

                      I created a ticket, #INC-76956, and attached the file created from the status page.

                      Any idea what might be going on or have any suggestions that might help?

                      Thanks in advance

                      1 Reply Last reply Reply Quote 0
                      • S
                        stephenw10 Netgate Administrator
                        last edited by Feb 26, 2021, 1:43 AM

                        It's unlikely that was related to the update unfortunately. The p1 point release would not have done anything for that, it addressed only: https://redmine.pfsense.org/issues/11444

                        We should be able to resolve that on the ticket for you.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • T
                          Traveller @dennis_s
                          last edited by Feb 26, 2021, 4:43 AM

                          @dennis_s Thanks for the links, and to Netgate for the extended blog on the details.

                          That was amazing work considering the time frame and everything else that was going on.

                          I'm an internals guy, and I thought there might be a deadlock involved when I saw the workaround.

                          Also, good on the team to provide a real fix rather than a patch that would reduce performance and increase technical debt.

                          1 Reply Last reply Reply Quote 1
                          • R
                            Ramosel
                            last edited by Feb 26, 2021, 3:33 PM

                            I read through the blog. 48hr find/fix is quite an accomplishment. Good job.
                            Leaves me with a couple of questions that have zero urgency tied to them.

                            What is different in the SG-3100 hardware that made it susceptible to this lock condition?

                            If you are NOT running SG-3100 hardware, is there any merit/value in doing the -p1 update?

                            Rick

                            ? 1 Reply Last reply Feb 26, 2021, 4:03 PM Reply Quote 0
                            • ?
                              A Former User @Ramosel
                              last edited by Feb 26, 2021, 4:03 PM

                              @ramosel It's the processors architecture that is unique to the 3100. As to updating on other devices it can be assumed they tested that. Given the forum is not overrun with complaints I would conclude it's fine to upgrade.

                              R 1 Reply Last reply Feb 26, 2021, 4:42 PM Reply Quote 0
                              • R
                                Ramosel @A Former User
                                last edited by Feb 26, 2021, 4:42 PM

                                @jwj Agreed, but I wasn't asking if it was safe or "fine"... I was asking if there was any merit/value in updating if one wasn't running an SG-3100.

                                ? 1 Reply Last reply Feb 26, 2021, 4:49 PM Reply Quote 0
                                • ?
                                  A Former User @Ramosel
                                  last edited by Feb 26, 2021, 4:49 PM

                                  @ramosel It fixes the one issue that was specific to the 3100. It doesn't address any other issues (as per Netgate), so the value on other devices would be zero. The harm also appears to be zero. If you are staring at an 'update available' notice or flashing led I'd update just to make that go away.

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    stephenw10 Netgate Administrator
                                    last edited by stephenw10 Feb 27, 2021, 4:18 PM Feb 27, 2021, 4:18 PM

                                    Yeah, there no need to update if a reboot is inconvenient for example. On other architectures 21.02p1 is effectively unchanged. But it is safe to do so.

                                    Steve

                                    R J 2 Replies Last reply Feb 27, 2021, 4:33 PM Reply Quote 1
                                    • R
                                      Ramosel @stephenw10
                                      last edited by Feb 27, 2021, 4:33 PM

                                      @stephenw10 Awesome... thank you.

                                      1 Reply Last reply Reply Quote 0
                                      • J
                                        johnpoz LAYER 8 Global Moderator @stephenw10
                                        last edited by johnpoz Feb 27, 2021, 4:53 PM Feb 27, 2021, 4:48 PM

                                        @stephenw10 said in pfSense Plus 21.02-p1 Now Available:

                                        if a reboot is inconvenient for example

                                        Exactly... I am prob just going to wait til the zfs correction for
                                        https://redmine.pfsense.org/issues/11483

                                        Is implemented, I would assume 21.0X or if a p2 comes out..

                                        Reboots are always "inconvenient" ;)

                                        The 3100s I have are stuck running what they are running until such time that I can get to office(es) or someone is onsite as smart hands, etc. While it would be nice to get them current - just not worth "any" risk of something going wrong.. Since offices don't have any staff there currently.

                                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                                        If you get confused: Listen to the Music Play
                                        Please don't Chat/PM me for help, unless mod related
                                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                                        1 Reply Last reply Reply Quote 0
                                        • P
                                          pfBo
                                          last edited by Feb 27, 2021, 4:59 PM

                                          Hi,

                                          After upgrading my SG-3100 I'm seeing issues with fq_codel. I have limiters configured and it has been running fine before upgrading to 21.02-p1.

                                          The firewall stops passing traffic when limiters are enabled and connecting to console all I see is these error messages over and over again:

                                          fq_codel_new_sched cannot allocate memory for fq_codel configuration parameters
                                          si_new new_sched error

                                          My limiters and rules are configures as follows:

                                          2021-02-27 17_55_48-Window.png

                                          2021-02-27 17_56_02-Window.png

                                          2021-02-27 17_56_15-Window.png

                                          Please let me know if I can provide and more details, logs or anything else that can help me (and you) resolve this issue.

                                          Best regards,

                                          Bo

                                          1 Reply Last reply Reply Quote 0
                                          20 out of 26
                                          • First post
                                            20/26
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received