Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Netgate 3100 RuleError:There were errors loading the rules: /tmp/rules.debug:18: cannot load

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 4 Posters 931 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      GunerX
      last edited by GunerX

      RuleError:There were errors loading the rules: /tmp/rules.debug:18: cannot load "/etc/bogonsv6": Invalid argument - The line in question reads [18]: table <bogonsv6> persist file "/etc/bogonsv6"

      I have already googled around about this error, and found many people saying its an old "update glitch". In order to fix it you need to increase the default Firewall Maximum Table Entries to 400,000. Well thats what my default value already was. And it even says in the description for that entry that "this devices default value is 400000". So I tried deleting the value completely so that it would be blank, which according to the description, would result in using the Default value, which SHOULD be 400000. But when I delete the entry, save, and reload, the default value is now 200,000. And the description has also changed itself to say that the "default value for this device is 200000". So after playing with it, the description just sets itself to w/e number you put in, so theres no real way of knowing what the default value is supposed to be. I have tried 200,000, this number causes filters to not even try to load...I think?.... I have tried 400,000. I have tried 500,000 (this requires a reboot). None of these numbers is the "magic number" to make this error stop.

      For reference I purchased a Netgate SG-3100-US.

      Can anyone help me with this?

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by bmeeks

        First off, make sure your SG-3100 has the latest 2.4.5_p1 version (and not just plain vanilla 2.4.5).

        However, being on the latest release will not necessarily stop the error. From some things I recall reading in the past, this error will occur on the initial boot, but then later the rules will actually load if you make a firewall change that results in reloading of the rules.

        But the real root problem is the IPv6 Bogons table is just too stinking large. It is orders and orders of magnitude larger than the IPv4 Bogons table. If I were in your shoes, I would turn off the IPv6 Bogons table -- especially if you are not using any IPv6 in your network.

        1 Reply Last reply Reply Quote 0
        • G
          GunerX
          last edited by

          I am on 2.4.5-RELEASE-p1.

          I tried a tables entry of 1,000,000. it still was not working. so i have turned ipv6 off. even though I would really like to use ipv6.

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            While the error is similar, "Invalid argument" is a different error than the out of memory, cannot allocate memory errors. Did /etc/bogonsv6 exist?

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • G
              GunerX
              last edited by

              I have no idea. Nor do I know how to check that? Can you direct me?

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                Diagnostics > Command Prompt

                Execute this:

                ls -l /etc/bogonsv6

                Please paste the output here.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • G
                  GunerX
                  last edited by

                  -rw-r--r-- 1 root wheel 1860301 Jul 12 23:38 /etc/bogonsv6

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    Hmm. I wonder if something is wrong with that file. You could try:

                    mv /etc/bogonsv6 /root
                    sh /etc/rc.update_bogons.sh force

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • G
                      GunerX
                      last edited by

                      first command output was blank. so i ran it a second time and got this:

                      mv: /etc/bogonsv6: No such file or directory

                      second command upon "execution" the output was again blank. running the command a second time returns this:

                      wc: /tmp/bogons: open: No such file or directory
                      egrep: /tmp/bogons: No such file or directory
                      rm: /tmp/bogons: No such file or directory
                      wc: /tmp/bogonsv6: open: No such file or directory
                      egrep: /tmp/bogonsv6: No such file or directory
                      rm: /tmp/bogonsv6: No such file or directory

                      me thinks i need to just Reinstall with a fresh iso?

                      viktor_gV 1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        Always an option.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • viktor_gV
                          viktor_g Netgate @GunerX
                          last edited by

                          @GunerX Try to temporary disable "Block bogon networks":
                          Screenshot from 2020-07-20 08-18-10.png
                          and run /etc/rc.update_bogons.sh (without force) again

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.