Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Gateway offline, Packetloss

    Scheduled Pinned Locked Moved General pfSense Questions
    90 Posts 6 Posters 23.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      It's possible the gateway is blocking because of the monitoring pings. I wouldn't expect that to immediately restart though. Also you tried setting the monitor IP to something external, which would prevent that, and it didn't help.
      Try deleting the ARP entry and see if that restores the connection temporarily.

      A 1 Reply Last reply Reply Quote 0
      • A
        Apaar @stephenw10
        last edited by

        @stephenw10 Saying that because i tired to stop and start the gateway service and it started working but then went offline sir.
        I will try to do that, change the gateway monitor, also try to delete the ARP table.

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          I thought you had already tried setting a different monitoring IP? That was the first thing I suggested. But that can trigger blocking in some gateways so is definitely worth trying. It's also something that is different to other routers or a client connected directly.

          Steve

          A 1 Reply Last reply Reply Quote 0
          • A
            Apaar @stephenw10
            last edited by

            @stephenw10 That time it didn’t work because ISP also had something messed up i think, so they re configured it from their side yesterday. I just change the Monitoring IP to the routers local IP. And the gateway is showing ONLINE without any loss.

            A 1 Reply Last reply Reply Quote 0
            • A
              Apaar @Apaar
              last edited by

              This post is deleted!
              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                What do mean by 'the routers local IP'? By default it monitors the gateway IP which will be the ISPs gateway, the 122.x.x.1 address.
                Since that may be objecting you can either set it to something external like 8.8.8.8 or disable gateway monitoring.

                I don't actually think that's the issue since sending an ARP query would not clear that block if it were.

                Steve

                A 4 Replies Last reply Reply Quote 0
                • A
                  Apaar @stephenw10
                  last edited by

                  @stephenw10 okay i will try it again, i m sorry i got it wrong.

                  1 Reply Last reply Reply Quote 0
                  • A
                    Apaar @stephenw10
                    last edited by

                    @stephenw10 it was showing online when i by mistake made the monitor ip to routers ip. But as soon as i change the ip to 8.8.8.8 the gateway went offline.

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      Ok, so try deleting the gateway ARP entry and see if that restores connectivity temporarily.

                      1 Reply Last reply Reply Quote 0
                      • A
                        Apaar @stephenw10
                        last edited by

                        @stephenw10 Right trying… Cleared only the Gateway IP and now restarting the router.

                        1 Reply Last reply Reply Quote 0
                        • A
                          Apaar @stephenw10
                          last edited by

                          @stephenw10 Deleted the ARP Table, it restored the table and still not working. Still offline.

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            Hmm, you might check it's actually sending it.

                            If you run a packet capture on WAN and filter by ARP and the gateway IP then I expct that to see the ARP renewal sent by pfSense.
                            With the pcap running delete the entry for the gateway in the ARP table. If you refresh the page I expect it to be immediately replaced.
                            The pcap should then have the ARP request and reply shown.

                            In your previous pcap that immediately restarted traffic.

                            The only other scenario that comes to mind that present like that is if the ARP entry in pfSense is wrong for some reason. But the pcap shows it sending to the correct MAC.

                            Steve

                            A 1 Reply Last reply Reply Quote 0
                            • A
                              Apaar @stephenw10
                              last edited by

                              @stephenw10 Okay! I m confused sir, what to do?

                              A 1 Reply Last reply Reply Quote 0
                              • A
                                Apaar @Apaar
                                last edited by

                                What can i do to replace the mac address for the gateway ?

                                1 Reply Last reply Reply Quote 0
                                • stephenw10S
                                  stephenw10 Netgate Administrator
                                  last edited by

                                  The MAC for the gateway should appear in the ARP table immediately unless the gateway doesn't reply to the ARP query. It did reply though in the pcap you uploaded. Both times pfSense queried it. You shouldn't need to do anything there.

                                  A 1 Reply Last reply Reply Quote 0
                                  • A
                                    Apaar @stephenw10
                                    last edited by

                                    @stephenw10 The ARP table detected the hostname for a sec of the ISP, but then it disappeared again.

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      The hostname doesn't matter, only the MAC and IP address are important.

                                      A 1 Reply Last reply Reply Quote 0
                                      • A
                                        Apaar @stephenw10
                                        last edited by

                                        Okay but then how will this issue solve ?

                                        1 Reply Last reply Reply Quote 0
                                        • stephenw10S
                                          stephenw10 Netgate Administrator
                                          last edited by

                                          It won't. You need to make sure pfSense is actually sending the ARP query when you remove the entry fro the table. That's why you are running the pcap and filtering for ARP and the gateway IP.

                                          If your previous pcap the gateway starts to respond each time pfSense sends that query.

                                          A 1 Reply Last reply Reply Quote 0
                                          • stephenw10S
                                            stephenw10 Netgate Administrator
                                            last edited by

                                            If it does then one thing we could do it set the ARP timeout much shorter. That would be a workaround though, it shouldn't be required.

                                            sysctl net.link.ether.inet.max_age=300
                                            

                                            Steve

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.