Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    22.05 and pfblocker

    Scheduled Pinned Locked Moved pfBlockerNG
    8 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      michmoor LAYER 8 Rebel Alliance
      last edited by

      Since the upgrade, i noticed that pfblockerng has been taking up quite a few CPU cycles. Performance hasnt been an issue but the cpu idleness has been noticeable. Monitoring usually has me at 98% idle and now I hover around 74.
      I noticed there is a redmine to pfblocker and 22.05 release but are other seeing the same issue?
      Since yesterday im comfortable to say that pfblocker package isnt healthy since the upgrade (have since re-installed).

      From Diagnostics > System Activity

      e9592e24-bd09-4793-8dd1-ed2c5981e6e9-image.png

      All other packages are functioning normally.

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      M 1 Reply Last reply Reply Quote 0
      • jimpJ jimp moved this topic from General pfSense Questions on
      • M
        mcury @michmoor
        last edited by

        @michmoor https://redmine.pfsense.org/issues/13156

        dead on arrival, nowhere to be found.

        M 1 Reply Last reply Reply Quote 1
        • M
          michmoor LAYER 8 Rebel Alliance @mcury
          last edited by

          @mcury Thanks for that. The hotfix in the thread didnt fix my issue, unfortunately.
          IP Block Stats logging is not working and CPU utilization is still high.
          Looks like i have to wait this out. Appreciate your help!

          Firewall: NetGate,Palo Alto-VM,Juniper SRX
          Routing: Juniper, Arista, Cisco
          Switching: Juniper, Arista, Cisco
          Wireless: Unifi, Aruba IAP
          JNCIP,CCNP Enterprise

          M 1 Reply Last reply Reply Quote 0
          • M
            mcury @michmoor
            last edited by

            @michmoor After applying the patch, you need to restart the pfblocker service.
            It fixed for me, it should fix for you too..

            dead on arrival, nowhere to be found.

            M 1 Reply Last reply Reply Quote 1
            • M
              michmoor LAYER 8 Rebel Alliance @mcury
              last edited by

              @mcury did restart the service.
              This is what my line looks like. What do you think?

              $r = explode('', $result, 2);

              Firewall: NetGate,Palo Alto-VM,Juniper SRX
              Routing: Juniper, Arista, Cisco
              Switching: Juniper, Arista, Cisco
              Wireless: Unifi, Aruba IAP
              JNCIP,CCNP Enterprise

              S M 2 Replies Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @michmoor
                last edited by

                @michmoor There have been other posts such as https://forum.netgate.com/topic/171527/3-1-0-4-high-cpu-load/2. I haven't noticed this on any of our installs/clients, though haven't looked that closely or watched them over time.

                The Redmine note has a space:
                $r = explode(' ', $result, 2);
                not
                $r = explode('', $result, 2);

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote 👍 helpful posts!

                1 Reply Last reply Reply Quote 0
                • M
                  mcury @michmoor
                  last edited by mcury

                  07c2a434-9006-4b93-bf37-0672a0c0e09c-image.png

                                         if (substr($result, 0, 1) == '@') {
                    
                                                  $r = explode(' ', $result, 2);
                  

                  As you can see in the reddit post, it fixed the CPU usage for others too:
                  https://www.reddit.com/r/pfBlockerNG/comments/v7zp72/ip_block_logging_not_working_in_2205_plus_release/

                  dead on arrival, nowhere to be found.

                  M 1 Reply Last reply Reply Quote 0
                  • S SteveITS referenced this topic on
                  • S SteveITS referenced this topic on
                  • M
                    michmoor LAYER 8 Rebel Alliance @mcury
                    last edited by

                    @mcury Confirmed, it was the spacing issue. Fix has resolved my issue.
                    Truly appreciate you guys. @mcury @SteveITS Thanks for your help !

                    Firewall: NetGate,Palo Alto-VM,Juniper SRX
                    Routing: Juniper, Arista, Cisco
                    Switching: Juniper, Arista, Cisco
                    Wireless: Unifi, Aruba IAP
                    JNCIP,CCNP Enterprise

                    1 Reply Last reply Reply Quote 0
                    • M mcury referenced this topic on
                    • M mcury referenced this topic on
                    • M mcury referenced this topic on
                    • M mcury referenced this topic on
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.