Pfsense with HA closing sessions when apply any rule.



  • Hi all!

    Here in my enterprise, we have a pfSense configuration with two HA pfsense, using CARP, virtual IPs, IPv4 and IPv6 configured and pfBlocker.

    After i upgraded to 2.4.3-Release, everytime i apply any rule all sessions are closed ( like SSH connections receive a timeout ).

    For that reason, i`ve upgraded to 2.4.3-RELEASE-p1. And then, it stops load firewall rules (solved applying this correction: https://redmine.pfsense.org/issues/8518).

    But then, the problem with sessions (PFSYNC) continue. And now apper this two erros too:

    0_1528983810048_290f9f42-ab5d-4e96-997a-59500efa2a13-image.png

    Both firewalls have the same Installed Packages. Same versions. SYNC interfaces ping each other.

    SYNC interface Rules:

    0_1528984922566_28a33431-1c56-4cc6-8ad9-633ced722711-image.png

    System Logs when i apply a firewall rule:

    Jun 14 08:29:07	php-cgi		notify_monitor.php: Message sent to lista-seguranca.centralit@listas.icmbio.gov.br OK
    Jun 14 08:29:02	php-fpm	327	[pfBlockerNG] XMLRPC sync to [ 192.168.1.2:{port} ] completed successfully.
    Jun 14 08:29:02	php-fpm	327	/rc.start_packages: XMLRPC reload data success with https://192.168.1.2:443/xmlrpc.php (pfsense.merge_installedpackages_section).
    Jun 14 08:29:01	php-fpm	327	/rc.start_packages: Beginning XMLRPC sync data to https://192.168.1.2:443/xmlrpc.php.
    Jun 14 08:29:01	php-fpm	327	/rc.start_packages: New alert found: A communications error occurred while attempting to call XMLRPC method merge_installedpackages_section:
    Jun 14 08:29:01	php-fpm	327	/rc.start_packages: A communications error occurred while attempting to call XMLRPC method merge_installedpackages_section:
    Jun 14 08:29:00	php-fpm	70969	/rc.filter_synchronize: XMLRPC reload data success with https://192.168.1.2:443/xmlrpc.php (pfsense.restore_config_section).
    Jun 14 08:28:57	php-cgi		notify_monitor.php: Message sent to lista-seguranca.centralit@listas.icmbio.gov.br OK
    Jun 14 08:28:57	php-fpm	70969	/rc.filter_synchronize: Beginning XMLRPC sync data to https://192.168.1.2:443/xmlrpc.php.
    Jun 14 08:28:57	php-fpm	70969	/rc.filter_synchronize: New alert found: A communications error occurred while attempting to call XMLRPC method restore_config_section:
    Jun 14 08:28:57	php-fpm	70969	/rc.filter_synchronize: A communications error occurred while attempting to call XMLRPC method restore_config_section:
    Jun 14 08:28:01	php-fpm	327	/rc.start_packages: Beginning XMLRPC sync data to https://192.168.1.2:443/xmlrpc.php.
    Jun 14 08:28:01	php-fpm	327	[pfBlockerNG] XMLRPC sync is starting.
    Jun 14 08:28:01	check_reload_status		Reloading filter
    Jun 14 08:28:01	check_reload_status		Syncing firewall
    Jun 14 08:27:59	check_reload_status		Reloading filter
    Jun 14 08:27:59	php-fpm	327	/rc.start_packages: The command '/sbin/ifconfig 'bce0.521' delete '10.10.10.1'' returned exit code '1', the output was 'ifconfig: ioctl (SIOCDIFADDR): Can't assign requested address'
    Jun 14 08:27:59	php-fpm	86843	/rc.filter_synchronize: XMLRPC reload data success with https://192.168.1.2:443/xmlrpc.php (pfsense.restore_config_section).
    Jun 14 08:27:59	nrpe	40186	Allowing connections from: 10.197.32.238
    Jun 14 08:27:59	nrpe	40186	Listening for connections on port 0
    Jun 14 08:27:59	nrpe	40186	Warning: Daemon is configured to accept command arguments from clients!
    Jun 14 08:27:59	nrpe	40186	Server listening on 10.197.21.3 port 5666.
    Jun 14 08:27:59	nrpe	40186	Starting up daemon
    Jun 14 08:27:59	php-fpm	327	[pfBlockerNG] Starting cron process.
    Jun 14 08:27:59	nrpe	60867	Daemon shutdown
    Jun 14 08:27:59	nrpe	60867	Cannot remove pidfile '/var/run/nrpe2.pid' - check your privileges.
    Jun 14 08:27:59	nrpe	60867	Caught SIGTERM - shutting down...
    Jun 14 08:27:59	php-fpm	327	/rc.start_packages: Restarting/Starting all packages.
    Jun 14 08:27:58	check_reload_status		Starting packages
    Jun 14 08:27:58	check_reload_status		Reloading filter
    Jun 14 08:27:56	php-fpm	70969	/rc.filter_synchronize: Beginning XMLRPC sync data to https://192.168.1.2:443/xmlrpc.php.
    Jun 14 08:27:56	php-fpm	70969	/rc.filter_synchronize: XMLRPC versioncheck: 18.0 -- 18.0
    Jun 14 08:27:56	php-fpm	70969	/rc.filter_synchronize: XMLRPC reload data success with https://192.168.1.2:443/xmlrpc.php (pfsense.host_firmware_version).
    Jun 14 08:27:56	php-fpm	70969	/rc.filter_synchronize: Beginning XMLRPC sync data to https://192.168.1.2:443/xmlrpc.php.
    Jun 14 08:27:56	php-fpm	86843	/rc.filter_synchronize: Beginning XMLRPC sync data to https://192.168.1.2:443/xmlrpc.php.
    Jun 14 08:27:56	php-fpm	86843	/rc.filter_synchronize: XMLRPC versioncheck: 18.0 -- 18.0
    Jun 14 08:27:56	php-fpm	86843	/rc.filter_synchronize: XMLRPC reload data success with https://192.168.1.2:443/xmlrpc.php (pfsense.host_firmware_version).
    Jun 14 08:27:56	pkg-static		pfSense-pkg-System_Patches-1.1.7 installed
    Jun 14 08:27:56	php-fpm	86843	/rc.filter_synchronize: Beginning XMLRPC sync data to https://192.168.1.2:443/xmlrpc.php.
    Jun 14 08:27:56	php		/etc/rc.packages: Successfully installed package: System Patches.
    Jun 14 08:27:55	check_reload_status		Syncing firewall
    Jun 14 08:27:55	check_reload_status		Syncing firewall
    Jun 14 08:27:54	php		/etc/rc.packages: Beginning package installation for System Patches .
    Jun 14 08:27:45	php-fpm	79998	/rc.filter_synchronize: XMLRPC reload data success with https://192.168.1.2:443/xmlrpc.php (pfsense.restore_config_section).
    Jun 14 08:27:42	php-fpm	79998	/rc.filter_synchronize: Beginning XMLRPC sync data to https://192.168.1.2:443/xmlrpc.php.
    Jun 14 08:27:42	php-fpm	79998	/rc.filter_synchronize: XMLRPC versioncheck: 18.0 -- 18.0
    Jun 14 08:27:42	php-fpm	79998	/rc.filter_synchronize: XMLRPC reload data success with https://192.168.1.2:443/xmlrpc.php (pfsense.host_firmware_version).
    Jun 14 08:27:42	php-fpm	79998	/rc.filter_synchronize: Beginning XMLRPC sync data to https://192.168.1.2:443/xmlrpc.php.
    Jun 14 08:27:41	check_reload_status		Syncing firewall
    

    If anyone can help me to solve this problem, Thanks!!