Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    High load Netgate 6100

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    7 Posts 4 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      Eria211
      last edited by

      I currently have 4 Netgate 6100's deployed and 1 of them has abnormally high load averages / CPU usage

      Each 6100 has a site-to-site IPsec VPN (128bit GCM and QAT is enabled) and there's about 50 - 80 Mbit travelling over that VPN at any given time

      The 3 6100's without the issue average around 0.75-1.5 load average but the 1 with the issue averages 4-5 load average and 80-95% CPU

      This appears to be causing significant instability issues for us, where the firewall goes completely unresponsive every 1 - 3 days and requires a reboot to return to normal operations

      This is a top run on the 6100 with the issue:
      b552fd9a-62d8-453f-a075-99e50a81913f-image.png

      And this is top run on one of the other 6100s without the issue:
      7d04b840-5519-4757-b970-60f8dd01923d-image.png

      The configs of all 4 are effectively identical, they only differ by the WAN settings and the 6100 with the issue uses pfblocker sync to keep the other 6100s pfblocker settings identical (so we only have to whitelist something once)

      The only other difference I can think of is that the 6100 with the issue has a 300/300 connection and a backup PPPoE connection (that no traffic flows over unless there is a WAN failure) and the other 6100s are on 1000/1000 connections but the total WAN activity on the 6100 with the issue under 150mbits and the IPsec never goes above 80mbit

      I'm at a total loss as to what the issue is to be honest, I have tried:

      • lowering the ipsec from 256bit to 128
      • I have removed all traffic shaping and limiters
      • I have factory reset and restored the config
      • I removed hn ALTQ support (this made no difference)
      • I have net.inet.ip.intr_queue_maxlen set to 3000 or I would get a positive value when running sysctl net.inet.ip.intr_queue_drops

      Could someone help me / give me some hints as to what I could try next?

      S 1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Both of those 6100s are passing 80Mbps IPSec when that top output was taken?

        Is that traffic always in one direction?

        Steve

        E 1 Reply Last reply Reply Quote 1
        • S
          SteveITS Galactic Empire @Eria211
          last edited by

          @eria211 said in High load Netgate 6100:

          pfblocker

          What version of pfBlocker? The last three -devel versions have a bug related to changes in pfSense 22.05. If that's the case there's an easy fix to change a ) to a space:
          https://redmine.pfsense.org/issues/13154

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          E 1 Reply Last reply Reply Quote 2
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Yes, good point! It's probably that.

            1 Reply Last reply Reply Quote 1
            • E
              Eria211 @stephenw10
              last edited by

              @stephenw10 yes, give or take they were 50-80mbits at the time of taking the screenshot, its a series of Truenas snapshot replications so its 5-8 datasets replicating at a maximum of 1MiB/s a piece

              The IPSec traffic is always in that direction from the low load average 6100 to the high load average 6100

              1 Reply Last reply Reply Quote 0
              • E
                Eria211 @SteveITS
                last edited by

                @steveits I am absolutely stunned, as soon as I edited the file and reloaded pfblocker the CPU dropped to 33% and the load average has gone from 5.2 down to 2.45

                Thank you for your help - I will make this change on the other 6100's 👍

                DefenderLLCD 1 Reply Last reply Reply Quote 1
                • DefenderLLCD
                  DefenderLLC @Eria211
                  last edited by

                  @eria211 said in High load Netgate 6100:

                  @steveits I am absolutely stunned, as soon as I edited the file and reloaded pfblocker the CPU dropped to 33% and the load average has gone from 5.2 down to 2.45

                  Thank you for your help - I will make this change on the other 6100's 👍

                  This will also fix the IP blocking stats and reporting as well. I finally made this same change to my 6100 yesterday.

                  1 Reply Last reply Reply Quote 1
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.