<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[pfSense freezes after 19-23 hours uptime]]></title><description><![CDATA[<p dir="auto">Hi</p>
<p dir="auto">I just bought a new box to give pfSense a try. Installation went smooth and configuration was fast (thanks for the good documentation!).  Then the problems started.</p>
<p dir="auto"><strong>SYMPTOMS</strong><br />
The box froze after having had an uptime of 19-23h. Problems were:</p>
<ul>
<li>no interface could be reached anymore</li>
<li>keyboard inputs were not responded to</li>
<li>no error visible on the screen</li>
</ul>
<p dir="auto">A cold reset helped and anything came up again. Once in a while I got a kernel panic instead of a freeze (crash dumps still available if desired) with the advantage, that the box then rebooted itself.</p>
<p dir="auto"><strong>TESTS</strong><br />
I tried different things:</p>
<ul>
<li>troubleshooting the Intel I211 NIC's as described <a href="https://docs.netgate.com/pfsense/en/latest/hardware/tuning-and-troubleshooting-network-cards.html" target="_blank" rel="noopener noreferrer nofollow ugc">here</a></li>
<li>tried both 2.4.4-p3 and 2.4.5</li>
<li>disabled all additional packages. While pfBlockerNG is <strong>not</strong> the problem it could provoke the error sooner, when played around and often reloaded/updated the IP's</li>
</ul>
<p dir="auto">Error stayed the same.</p>
<p dir="auto"><strong>SOLUTION</strong><br />
Then I stumbled upon <a href="https://forum.netgate.com/topic/139433/resolved-pfsense-hangs-when-wan-is-unstable-or-lost">this post</a>. Problems are similar altough my connections did not automagically came back. But then I did the following and for now it seems to have resolved the problem:</p>
<ul>
<li>"System - Routing - Edit Gateway" and activated both "<strong>Disable Gateway Monitoring</strong>" and "<strong>Disable Gateway Monitoring Action</strong>" (I do only have one gateway)</li>
<li>"Interface - WAN" set "<strong>IPv6 Configuration Type = None</strong>" (my ISP does not provide IPv6 functionality)</li>
</ul>
<p dir="auto"><strong>QUESTION</strong><br />
My question is: why that? Can that be a driver problem with the Intel NIC (I have two 2-port I211 cards). I can't see the slightest error in the logs or syslog server before the system freezes. Was just wondering if somebody maybe had a good idea or could have a look at it.</p>
]]></description><link>https://forum.netgate.com/topic/152889/pfsense-freezes-after-19-23-hours-uptime</link><generator>RSS for Node</generator><lastBuildDate>Tue, 14 Apr 2026 16:02:01 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/152889.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 24 Apr 2020 08:18:11 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to pfSense freezes after 19-23 hours uptime on Fri, 24 Apr 2020 10:26:17 GMT]]></title><description><![CDATA[<p dir="auto">You welcome and Cool_Corona didn't accidentally ask the bogons, ;-)</p>
]]></description><link>https://forum.netgate.com/post/907738</link><guid isPermaLink="true">https://forum.netgate.com/post/907738</guid><dc:creator><![CDATA[DaddyGo]]></dc:creator><pubDate>Fri, 24 Apr 2020 10:26:17 GMT</pubDate></item><item><title><![CDATA[Reply to pfSense freezes after 19-23 hours uptime on Fri, 24 Apr 2020 10:21:47 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/cool_corona">@<bdi>Cool_Corona</bdi></a></p>
<blockquote>
<p dir="auto">Are you running bogons block on the interfaces??</p>
</blockquote>
<p dir="auto">On WAN and DMZ yes, but not on LAN.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/daddygo">@<bdi>DaddyGo</bdi></a></p>
<blockquote>
<p dir="auto">I would not postpone its setup (FC and EEE), I will go further ..... I always start with these settings as they form the basis of the system</p>
</blockquote>
<p dir="auto">Understood and will do but hey - I am on my first installation and need to get  the vibes first ;) But it's noted down for beginning of next week!</p>
<blockquote>
<p dir="auto">I strongly recommend using pfBlockerNG-devel</p>
</blockquote>
<p dir="auto">Okay, will dig into that too.</p>
<p dir="auto">Thanks for the hints guys!</p>
]]></description><link>https://forum.netgate.com/post/907737</link><guid isPermaLink="true">https://forum.netgate.com/post/907737</guid><dc:creator><![CDATA[emak]]></dc:creator><pubDate>Fri, 24 Apr 2020 10:21:47 GMT</pubDate></item><item><title><![CDATA[Reply to pfSense freezes after 19-23 hours uptime on Fri, 24 Apr 2020 10:16:09 GMT]]></title><description><![CDATA[<p dir="auto">Flow control and EEE are the default settings, so you can get rid of a lot of trouble in the beginning</p>
<p dir="auto">I strongly recommend using pfBlockerNG-devel, read BBcan177's recommendations.</p>
<p dir="auto">I would not postpone its setup (FC and EEE), I will go further ..... I always start with these settings as they form the basis of the system<br />
I'm past the 50th installation :-)</p>
]]></description><link>https://forum.netgate.com/post/907732</link><guid isPermaLink="true">https://forum.netgate.com/post/907732</guid><dc:creator><![CDATA[DaddyGo]]></dc:creator><pubDate>Fri, 24 Apr 2020 10:16:09 GMT</pubDate></item><item><title><![CDATA[Reply to pfSense freezes after 19-23 hours uptime on Fri, 24 Apr 2020 10:15:10 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/emak">@<bdi>emak</bdi></a></p>
<p dir="auto">Are you running bogons block on the interfaces??</p>
]]></description><link>https://forum.netgate.com/post/907731</link><guid isPermaLink="true">https://forum.netgate.com/post/907731</guid><dc:creator><![CDATA[Cool_Corona]]></dc:creator><pubDate>Fri, 24 Apr 2020 10:15:10 GMT</pubDate></item><item><title><![CDATA[Reply to pfSense freezes after 19-23 hours uptime on Fri, 24 Apr 2020 10:08:48 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">-try rebooting via SSH rather than cold boot</p>
</blockquote>
<p dir="auto">Well no interface is working. No SSH, no ping nothing on WAN/DMZ/LAN...</p>
<blockquote>
<p dir="auto">-Many user-poorly configured resource-intensive processes, such as Suricata / Snort / pfblockerNG, can also cause extreme WAN-side parameters, which also indicate a crash-like state.</p>
</blockquote>
<p dir="auto">Well I uninstalled close to all packages (apart acme, arpwatch and Status_Traffic_Totals). Still the problem persisted. Now I have pfBlockerNG re-installed and with around 400k IP's it should be well within the limits of my memory and parameter settings. But I had it to hourly update and read on another post that they had troubles with it - so I adjusted it to daily (still got the freezes though).</p>
<p dir="auto">Thanks for the tips about Flow Control and EEE - will do that probably starting next week. I would like to see first though, that the box can run stable without big changes. Then I go ahead with the recommendations :)</p>
]]></description><link>https://forum.netgate.com/post/907730</link><guid isPermaLink="true">https://forum.netgate.com/post/907730</guid><dc:creator><![CDATA[emak]]></dc:creator><pubDate>Fri, 24 Apr 2020 10:08:48 GMT</pubDate></item><item><title><![CDATA[Reply to pfSense freezes after 19-23 hours uptime on Fri, 24 Apr 2020 09:55:51 GMT]]></title><description><![CDATA[<p dir="auto">-try rebooting via SSH rather than cold boot<br />
-Many user-poorly configured resource-intensive processes, such as Suricata / Snort / pfblockerNG, can also cause extreme WAN-side parameters, which also indicate a crash-like state.<br />
-PfSense is a bit of a different philosophy, but if you try it, you'll love it :-).<br />
-EEE = energy efficiency ethernet, (it doesn’t make much sense on a busy NGFW)<br />
use these:</p>
<h1><a class="anchor-offset" name="these-ae-tunables-to-improve-network-performance-on-intel-igb-driver-nics"></a>These ae tunables to improve network performance on Intel igb driver NICs</h1>
<h1><a class="anchor-offset" name="flow-control-fc-0-disabled-1-rx-pause-2-tx-pause-3-full-fc"></a>Flow Control (FC) 0=Disabled 1=Rx Pause 2=Tx Pause 3=Full FC</h1>
<h1><a class="anchor-offset" name="this-tunable-must-be-set-according-to-your-configuration.-very-important"></a>This tunable must be set according to your configuration. VERY IMPORTANT!</h1>
<h1><a class="anchor-offset" name="set-fc-to-0-lt-x-gt-on-all-interfaces"></a>Set FC to 0 (&lt;x&gt;) on all interfaces</h1>
<p dir="auto">hw.igb.&lt;x&gt;.fc=0 #Also put this in System Tunables hw.igb.&lt;x&gt;.fc: value=0</p>
<p dir="auto">and</p>
<p dir="auto">Disable Energy Efficiency - set for each igb port in your system<br />
This setting can cause Link flap errors if not disabled<br />
Set for every igb interface in the system as per these examples<br />
dev.igb.0.eee_disabled: value=1<br />
dev.igb.1.eee_disabled: value=1<br />
dev.igb.2.eee_disabled: value=1<br />
dev.igb.3.eee_disabled: value=1</p>
<p dir="auto">These are mostly needed for IPS, but I think they only make your system better.</p>
]]></description><link>https://forum.netgate.com/post/907724</link><guid isPermaLink="true">https://forum.netgate.com/post/907724</guid><dc:creator><![CDATA[DaddyGo]]></dc:creator><pubDate>Fri, 24 Apr 2020 09:55:51 GMT</pubDate></item><item><title><![CDATA[Reply to pfSense freezes after 19-23 hours uptime on Fri, 24 Apr 2020 09:43:20 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for the fast response!</p>
<blockquote>
<p dir="auto">In this case, it may take up to 5 - 10 minutes for the GUI to be available.</p>
</blockquote>
<p dir="auto">I have a broadband monitor from both WAN and LAN to the gateway. This shows downtimes for up to 40 min until I cold started the box (was never more patient than that during testing). So if it should come back then it takes waaaay to long.</p>
<blockquote>
<p dir="auto">Intel i211-based NICs are relatively problem-free in the pfsense system, even with basic settings.</p>
</blockquote>
<p dir="auto">Glad to hear :)</p>
<blockquote>
<p dir="auto">On the WAN side, look for the problem, why your connection may be lost or why the WAN gateway parameters are deteriorating.<br />
I suggest that, also turn off EEE and flow control on this interface.</p>
</blockquote>
<p dir="auto">I've had a different firewall before and did not experience downtimes. So it should not be a problem from the provider side? Will try disabling flow control if I ran into a problem again (and then get this post updated). But that would be for all ports and not only the troublesome, right? And what do you mean by EEE though?</p>
<blockquote>
<p dir="auto">The gateway monitor should be well configured for the external gateway IP, if it responds to the ping or for external trusted IP e.g. DNS server 8.8.8.8 / 9.9.9.9/ 1.1.1.1 or similar.</p>
</blockquote>
<p dir="auto">Sure, I have it set to loadbalanced servers from my work - so I do know if we encounter troubles but it for sure is better to set it to a service with even more reliable uptime.</p>
]]></description><link>https://forum.netgate.com/post/907716</link><guid isPermaLink="true">https://forum.netgate.com/post/907716</guid><dc:creator><![CDATA[emak]]></dc:creator><pubDate>Fri, 24 Apr 2020 09:43:20 GMT</pubDate></item><item><title><![CDATA[Reply to pfSense freezes after 19-23 hours uptime on Fri, 24 Apr 2020 09:20:06 GMT]]></title><description><![CDATA[<p dir="auto">Pfsense checks a lot of things from the internet, so if there is no internet access then the GUI becomes very slow.<br />
Many colleagues he/she when experiences this even - they think the system has crashed, but this is not always the case, in fact.<br />
In this case, it may take up to 5 - 10 minutes for the GUI to be available.<br />
This is not expected by many and they do a cold boot immediately, which is not a very good idea and the many - many cold start requires minimum at least a ZFS file system installation.</p>
<p dir="auto">Intel i211-based NICs are relatively problem-free in the pfsense system, even with basic settings.</p>
<p dir="auto">On the WAN side, look for the problem, why your connection may be lost or why the WAN gateway parameters are deteriorating.<br />
I suggest that, also turn off EEE and flow control on this interface.</p>
<p dir="auto">The gateway monitor should be well configured for the external gateway IP, if it responds to the ping or for external trusted IP e.g. DNS server 8.8.8.8 / 9.9.9.9/ 1.1.1.1 or similar.</p>
<p dir="auto">I hope this can help</p>
]]></description><link>https://forum.netgate.com/post/907710</link><guid isPermaLink="true">https://forum.netgate.com/post/907710</guid><dc:creator><![CDATA[DaddyGo]]></dc:creator><pubDate>Fri, 24 Apr 2020 09:20:06 GMT</pubDate></item></channel></rss>