Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    TCP connections being closed with no traffic

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    8 Posts 3 Posters 858 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      stbellcom
      last edited by

      We am having issues with a site that is running a 6100 with Dual WAN intermittently unable to access webpages.

      As a example running curl to acb.netgate.com we will get:

      [23.05-RELEASE][admin@NETG.home.arpa]/root: curl https://acb.netgate.com
      curl: (7) Failed to connect to acb.netgate.com port 443 after 7 ms: Couldn't connect to server
      

      TCP capture at the time will print the following:

      11:21:23.571651 IP 100.67.70.132.19567 > 208.123.73.212.https: Flags [S], seq 4028739374, win 65228, options [mss 1452,nop,wscale 7,sackOK,TS val 3134883270 ecr 0], length 0
      

      We can try again and it will work then block again at random. Also it doesn't matter which site its effecting any site.

      What we have tried, is disabling the Dual WAN to a single connection and removing load balancing and the problem continues. We have also simplified the firewall rules to the base and checking the logs shows the packet left the Netgate without a issue.

      Does anyone have suggestions as to what could be going wrong or a suggestion to test if its the Netgate blocking the request or something further upstream ?

      Thanks

      V stephenw10S 2 Replies Last reply Reply Quote 0
      • V
        viragomann @stbellcom
        last edited by

        @stbellcom said in TCP connections being closed with no traffic:

        As a example running curl to acb.netgate.com we will get:

        [23.05-RELEASE][admin@NETG.home.arpa]/root: curl https://acb.netgate.com
        curl: (7) Failed to connect to acb.netgate.com port 443 after 7 ms: Couldn't connect to server

        Is this form pfSense itself or from a device behind it?

        Is this pfSense in an HA setup?

        Are you running squid?

        State public IPs for the gateway monitoring and check then the gateway log if there are dropouts.

        S 1 Reply Last reply Reply Quote 1
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          That's a TCP connection failing to open. There is no reply traffic at all if you only see the single TCP:SYN packet in a pcap.

          Do existing connections also get dropped or is it just new connections that fail?

          S 1 Reply Last reply Reply Quote 1
          • S
            stbellcom @viragomann
            last edited by

            @viragomann

            The tests above were done from the pfSense.

            We aren't running in HA configuration.

            Squid is not installed.

            Monitoring IP for the gateways are currently 1.1.1.1 & 8.8.8.8 and there are no logs that the gateway have dropped out.

            When this is happening you can still trace out of each pppoe interface without a issue.

            1 Reply Last reply Reply Quote 0
            • S
              stbellcom @stephenw10
              last edited by

              @stephenw10

              existing connections stay active, its just new connections that fail. After a few retries you might get a connection.

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator @stbellcom
                last edited by

                @stbellcom said in TCP connections being closed with no traffic:

                11:21:23.571651 IP 100.67.70.132.19567 > 208.123.73.212

                Is that the real IP? You're behind CGN?

                Perhaps there is a state limit upstrean you're hitting? Check the number of states when it fails. Or look at the states in the Monitoring graphs, is it hitting some limit?

                Steve

                S 1 Reply Last reply Reply Quote 0
                • S
                  stbellcom @stephenw10
                  last edited by

                  @stephenw10

                  We are behind CGN which I suspect could be causing all sorts of issues. Will be contacting the ISP today to get the connections off it.

                  S 1 Reply Last reply Reply Quote 1
                  • S
                    stbellcom @stbellcom
                    last edited by

                    Getting off CGNAT solved the issue, connection is solid now.

                    1 Reply Last reply Reply Quote 1
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.