Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense brake completely enable DHCP

    Scheduled Pinned Locked Moved DHCP and DNS
    25 Posts 4 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mullcom
      last edited by

      Hello.

      I am wondering how i can bring my Pfsense backup again. I have try so many ways now and can't get the loan Port to start sending package out from its own.

      Story

      I have fresh install Pfsense and when i enable DHCP it brake down. Can't get Webb UI to respond and when i ping Pfsense IP i don't get any respond back.

      When i go to Pfsense with monitor i press 8 and ping My IP and i get respons back but when i ping outside from this network ports "rc1" i get : invikid command as respond. Really strange behavior! I have try to get this fixed as to do.

      Get rc1 interface new IP address
      Restart (Pfsense, switch, second router)
      Shutdown the other DHCP.
      Shutdown rc1 port and start it.

      But nothing working. The only thing that is are to reinstall the system. But i think this is a bit extream to do. Must be a somting else i cam do to resetting the port so it can start to send package external again?

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        What are your LAN configuration details and DHCP server config? Screenshots would be helpful.

        M 1 Reply Last reply Reply Quote 1
        • M
          mullcom
          last edited by mullcom

          It's not so much to tell.
          I don't find any upload for IMG.

          My Lan is static on 192.168.10.1

          When i try to enable DHCP i select between 100 - 150 in same network.

          After i enable it then i can't reach web UI or ping up from my computer but when i go to CLI Interface to check if system has Frozen i can see it has not and system is up and i can ping 192.168.10.1 but no other ip in network.

          1 Reply Last reply Reply Quote 0
          • M
            mullcom @KOM
            last edited by

            @KOM said in Pfsense brake completely enable DHCP:

            What are your LAN configuration details and DHCP server config? Screenshots would be helpful.

            not so many option i have checked

            GertjanG 1 Reply Last reply Reply Quote 0
            • KOMK
              KOM
              last edited by

              When you reply, on the far right of the Edit bar is an icon titled Upload Image, right between Emoji and Upload File. Use that to post screenshots here.

              1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan @mullcom
                last edited by

                @mullcom said in Pfsense brake completely enable DHCP:

                @KOM said in Pfsense brake completely enable DHCP:

                What are your LAN configuration details and DHCP server config? Screenshots would be helpful.

                not so many option i have checked

                Probably one to much : image number 4 : Static ARP.

                Only the machines listed below will be able to communicate with the firewall on this interface.
                

                Do you understand what this implies ? Did you really add all the MAC's ?

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                M 1 Reply Last reply Reply Quote 0
                • M
                  mullcom @Gertjan
                  last edited by mullcom

                  @Gertjan said in Pfsense brake completely enable DHCP:

                  @mullcom said in Pfsense brake completely enable DHCP:

                  @KOM said in Pfsense brake completely enable DHCP:

                  What are your LAN configuration details and DHCP server config? Screenshots would be helpful.

                  not so many option i have checked

                  Probably one to much : image number 4 : Static ARP.

                  Only the machines listed below will be able to communicate with the firewall on this interface.
                  

                  Do you understand what this implies ? Did you really add all the MAC's ?

                  I should read about this. But this should not make the web UI and nic-port brake totally?

                  I have done some backup new so I can go back to a working state if it's brake again. So I can test if this setting cursing this behavior.

                  GertjanG 1 Reply Last reply Reply Quote 0
                  • M
                    mullcom
                    last edited by mullcom

                    Update.

                    I have look around in Pfsense and find out that ntp servis is not working as it should! I have try to fix that but I get same issue and clock is not updating. This can be a direct issue with DHCP I think. So I need to solve this first.

                    Why so many failing points in this system at a clean installation?Screenshot_20190812-191722_Chrome Canary.jpg

                    1 Reply Last reply Reply Quote 0
                    • KOMK
                      KOM
                      last edited by

                      @mullcom said in Pfsense brake completely enable DHCP:

                      Why so many failing points in this system at a clean installation?

                      Impossible to answer since we have no idea what you have done or how you have configured anything. I did ask for screenshots of your network details but you never got around to providing them.

                      1 Reply Last reply Reply Quote 0
                      • GertjanG
                        Gertjan @mullcom
                        last edited by

                        @mullcom said in Pfsense brake completely enable DHCP:

                        @Gertjan said in Pfsense brake completely enable DHCP:

                        @mullcom said in Pfsense brake completely enable DHCP:

                        @KOM said in Pfsense brake completely enable DHCP:

                        What are your LAN configuration details and DHCP server config? Screenshots would be helpful.

                        not so many option i have checked

                        Probably one to much : image number 4 : Static ARP.

                        Only the machines listed below will be able to communicate with the firewall on this interface.
                        

                        Do you understand what this implies ? Did you really add all the MAC's ?

                        I should read about this. But this should not make the web UI and nic-port brake totally?

                        I have done some backup new so I can go back to a working state if it's brake again. So I can test if this setting cursing this behavior.

                        NTP ?
                        Here is mine :

                        c1d1b017-b4a0-488a-b17b-8c2608a2bd9a-image.png

                        Status :

                        b140b962-fc32-4c84-a91d-3769de182971-image.png

                        time is set close to a 0.00 001 second.

                        Your status list : it found a list with IP address, but none is reachable;

                        You have severe upstream connection problem.

                        pfSense is as any other router : Out f the box, set up WAN (if it is DHCPclient, nothing to do, because this is default) : it connects and it's ready to go.
                        Any bad experiencing from this point : tell us your setup, and we tell you what's wrong.

                        Btw : use a 'normal' device to set it up. Phone-only seems not a good idea to me.

                        edit : ntp using IPv6 .... oh, well, why not :

                        53a72b26-71d1-44a8-af54-e747b89f3faf-image.png

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        M 1 Reply Last reply Reply Quote 0
                        • M
                          mullcom @Gertjan
                          last edited by mullcom

                          @Gertjan said in Pfsense brake completely enable DHCP:

                          @mullcom said in Pfsense brake completely enable DHCP:

                          @Gertjan said in Pfsense brake completely enable DHCP:

                          @mullcom said in Pfsense brake completely enable DHCP:

                          @KOM said in Pfsense brake completely enable DHCP:

                          What are your LAN configuration details and DHCP server config? Screenshots would be helpful.

                          not so many option i have checked

                          Probably one to much : image number 4 : Static ARP.

                          Only the machines listed below will be able to communicate with the firewall on this interface.
                          

                          Do you understand what this implies ? Did you really add all the MAC's ?

                          I should read about this. But this should not make the web UI and nic-port brake totally?

                          I have done some backup new so I can go back to a working state if it's brake again. So I can test if this setting cursing this behavior.

                          NTP ?
                          Here is mine :

                          c1d1b017-b4a0-488a-b17b-8c2608a2bd9a-image.png

                          Status :

                          b140b962-fc32-4c84-a91d-3769de182971-image.png

                          time is set close to a 0.00 001 second.

                          Your status list : it found a list with IP address, but none is reachable;

                          You have severe upstream connection problem.

                          pfSense is as any other router : Out f the box, set up WAN (if it is DHCPclient, nothing to do, because this is default) : it connects and it's ready to go.
                          Any bad experiencing from this point : tell us your setup, and we tell you what's wrong.

                          Btw : use a 'normal' device to set it up. Phone-only seems not a good idea to me.

                          edit : ntp using IPv6 .... oh, well, why not :

                          53a72b26-71d1-44a8-af54-e747b89f3faf-image.png

                          Thx. I upload my settings. I have try so many ways now but right now I have this.

                          Still problem. :(
                          Screenshot_20190813-134824_Chrome Canary.jpg
                          Screenshot_20190813-135128_Chrome Canary.jpg Screenshot_20190813-134932_Chrome Canary.jpg Screenshot_20190813-134857_Chrome Canary.jpgScreenshot_20190813-140156_Chrome Canary.jpg

                          1 Reply Last reply Reply Quote 0
                          • M
                            mullcom
                            last edited by mullcom

                            Seams I geting better result but it still saying unreachable.
                            Screenshot_20190813-174636_Chrome Canary.jpgScreenshot_20190813-175004_Chrome Canary.jpg

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              If you can talk to them then your reach should be 377..

                              And your offsets are so large not going to adjust anyway.. Set the time on the pfsense box to be somewhere close to start with.

                              Your connectivity is just broken from those jitter values..

                              ntp.png

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              M 1 Reply Last reply Reply Quote 0
                              • M
                                mullcom @johnpoz
                                last edited by

                                @johnpoz Screenshot_20190813-183937_Chrome Canary.jpg

                                I try to sett time manually. But same problem and offset time is still big. 😭

                                1 Reply Last reply Reply Quote 0
                                • GertjanG
                                  Gertjan
                                  last edited by

                                  Is is possible to remove all your firewall and NAT rules - and put in place the default pass all rule on LAN ?

                                  No "help me" PM's please. Use the forum, the community will thank you.
                                  Edit : and where are the logs ??

                                  1 Reply Last reply Reply Quote 0
                                  • johnpozJ
                                    johnpoz LAYER 8 Global Moderator
                                    last edited by johnpoz

                                    @mullcom said in Pfsense brake completely enable DHCP:

                                    I try to sett time manually. But same problem and offset time is still big

                                    Well your not really talking to them... So the reach will go up as you get back answers.. it tells you how many out of the last 8 queries you got answers for... Normal is 377.. 7 means HORRIBLE!!! You could do the math to match up which ones got an answer..

                                    7 would mean only the last 3 have gotten an answer
                                    00000111

                                    377
                                    11111111
                                    would mean you got answers for the last 8 queries.

                                    What are your reaches now? When they are 377 and stay there you have a stable connection to the ntp servers.

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                                    1 Reply Last reply Reply Quote 0
                                    • M
                                      mullcom
                                      last edited by

                                      This is a bit crazy...

                                      No one in the list.

                                      Screenshot_20190813-192808_Chrome Canary.jpg

                                      johnpozJ 1 Reply Last reply Reply Quote 0
                                      • M
                                        mullcom
                                        last edited by mullcom

                                        Finally. I delit pool and only use time.windows.com like all windows OS do.

                                        I get that to pop-up.
                                        Screenshot_20190813-194551_Chrome Canary.jpg

                                        2.4.4-RELEASE][admin@pfSense.localdomain]/root: ntpdate -d time.windows.com
                                        13 Aug 19:42:45 ntpdate[62579]: ntpdate 4.2.8p13@1.3847-o Fri May 10 20:05:40 UTC 2019 (1)
                                        transmit(40.74.70.63)
                                        receive(40.74.70.63)
                                        transmit(40.74.70.63)
                                        receive(40.74.70.63)
                                        transmit(40.74.70.63)
                                        receive(40.74.70.63)
                                        transmit(40.74.70.63)
                                        receive(40.74.70.63)

                                        server 40.74.70.63, port 123
                                        stratum 2, precision -23, leap 00, trust 000
                                        refid [132.163.96.2], root delay 0.192383, root dispersion 0.014725
                                        reference time: e0fd7778.aa4bf9d3 Tue, Aug 13 2019 19:52:56.665
                                        originate timestamp: e0fd7795.26345eac Tue, Aug 13 2019 19:53:25.149
                                        transmit timestamp: e0fd751b.ae457a08 Tue, Aug 13 2019 19:42:51.680
                                        filter delay: 0.09448 0.09479 0.09439 0.09439
                                        ---- ---- ---- ----
                                        filter offset: 615.057016 621.197134 627.284268 633.434036
                                        ---- ---- ---- ----
                                        delay 0.09439, dispersion 6.89256, offset 627.284268

                                        13 Aug 19:42:51 ntpdate[62579]: step time server 40.74.70.63 offset 627.284268 sec
                                        [2.4.4-RELEASE][admin@pfSense.localdomain]/root:

                                        1 Reply Last reply Reply Quote 0
                                        • johnpozJ
                                          johnpoz LAYER 8 Global Moderator @mullcom
                                          last edited by

                                          well if you can not resolve - then no nobody would be in the list..

                                          Not sure why you are worried about ntp.. Does the wan get an IP from your isp - is it public or rfc1918.. What does the quality graph show? Can pfsense ping say 8.8.8.8 from the diag, ping tool?

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                                          M 1 Reply Last reply Reply Quote 0
                                          • M
                                            mullcom @johnpoz
                                            last edited by mullcom

                                            @johnpoz

                                            I am glad you all help me with this.

                                            Pfsense deliver NTP as a funktion so. I think that should work when it come with the box. Time is important. If not correct time with your hardware to getting trubbel in the end with other. Like when you deliver active directory for one example. It seams DHCP is also in need of time. But the thing is that I want it to work and function correctly before I move on. Not like to have failing funktionalitet in the network. Btw I feel some responses loss in web GUI when time is not Correct. Sometime it frozen for a minute.

                                            With that sad.

                                            I call my ISP to get a IP adress that's are derectly to the internet. If I didn't do that I don't get a fake ip that's not directly to internet and gets some limitations.

                                            I did some more testing in ssh when I update time manually.

                                            [2.4.4-RELEASE][admin@pfSense.localdomain]/root: date 1342
                                            date: can't reach time daemon, time set locally
                                            Wed Aug 14 13:42:00 +02 2019
                                            [2.4.4-RELEASE][admin@pfSense.localdomain]/root:
                                            

                                            Can't reach time deamon it say

                                            [2.4.4-RELEASE][admin@pfSense.localdomain]/root: time
                                            0.006u 0.018s 29:48.45 0.0%     7908+1780k 4+0io 0pf+0w
                                            [2.4.4-RELEASE][admin@pfSense.localdomain]/root:
                                            

                                            Have no idea why it say like this.

                                            I have sett correct location and that is Sweden Stockholm in web GUI. And when I ping 8.8.8.8

                                            [2.4.4-RELEASE][admin@pfSense.localdomain]/root: ping 8.8.8.8
                                            PING 8.8.8.8 (8.8.8.8): 56 data bytes
                                            64 bytes from 8.8.8.8: icmp_seq=0 ttl=54 time=4.960 ms
                                            64 bytes from 8.8.8.8: icmp_seq=1 ttl=54 time=4.950 ms
                                            64 bytes from 8.8.8.8: icmp_seq=2 ttl=54 time=4.946 ms
                                            64 bytes from 8.8.8.8: icmp_seq=3 ttl=54 time=4.948 ms
                                            64 bytes from 8.8.8.8: icmp_seq=4 ttl=54 time=4.947 ms
                                            

                                            And i get back all NTP servers in the list now. And that are 377 now. Start Frome 7 and get higher more I waited. But still saying unreachable 😭
                                            Screenshot_20190814-134900_Chrome Canary.jpg

                                            I did remove all NAT rules and open up WAN for everything to see if it working better.

                                            LAN is already open as defoult.
                                            Screenshot_20190814-135449_Chrome Canary.jpg

                                            Screenshot_20190814-135432_Chrome Canary.jpg Screenshot_20190814-135343_Chrome Canary.jpg

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.