23.05.1 update on aws instance, still fails
-
Hope someone reads this since you ignored my first posting
Made a clone via AMI, then updated from console menu
blah blah
[117/117] Fetching php82-pear-Auth_RADIUS-1.1.0_4.pkg: .. done
Checking integrity...Child process pid=89349 terminated abnormally: Killed
Amazon Web Services - Netgate Device ID: xxxxxxxxxxxtail -80 system.log.0
Jun 30 06:17:47 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:47 ac3prod-pfvpn01 check_reload_status[372]: Linkup starting xn0 Jun 30 06:17:47 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:48 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:48 ac3prod-pfvpn01 sshd[12737]: Server listening on :: port 22. Jun 30 06:17:48 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:48 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:48 ac3prod-pfvpn01 sshd[12737]: Server listening on 0.0.0.0 port 22. Jun 30 06:17:48 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:48 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:48 ac3prod-pfvpn01 sshguard[13359]: Now monitoring attacks. Jun 30 06:17:48 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 check_reload_status[372]: rc.newwanip starting xn0 Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 php-cgi[389]: rc.bootup: Resyncing OpenVPN instances. Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 kernel: Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 kernel: tun1: changing name to 'ovpns1' Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 kernel: ovpns1: link state changed to UP Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 check_reload_status[372]: rc.newwanip starting ovpns1 Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:56 ac3prod-pfvpn01 kernel: pflog0: promiscuous mode enabled Jun 30 06:17:56 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:57 ac3prod-pfvpn01 kernel: .done. Jun 30 06:17:57 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:57 ac3prod-pfvpn01 php-cgi[389]: rc.bootup: Default gateway setting Interface WAN_DHCP Gateway as default. Jun 30 06:17:57 ac3prod-pfvpn01 syslogd: sendto: Network is unreachable Jun 30 06:17:57 ac3prod-pfvpn01 php-cgi[389]: rc.bootup: Gateway, NONE AVAILABLE Jun 30 06:17:57 ac3prod-pfvpn01 php-fpm[343]: /rc.newwanip: rc.newwanip: Info: starting on xn0. Jun 30 06:17:57 ac3prod-pfvpn01 kernel: done. Jun 30 06:17:57 ac3prod-pfvpn01 php-fpm[343]: /rc.newwanip: rc.newwanip: on (IP address: 172.18.0.203) (interface: WAN[wan]) (real interface: xn0). Jun 30 06:17:57 ac3prod-pfvpn01 php-fpm[342]: /rc.newwanip: rc.newwanip: Info: starting on ovpns1. Jun 30 06:17:57 ac3prod-pfvpn01 php-fpm[342]: /rc.newwanip: rc.newwanip: on (IP address: 192.168.167.1) (interface: []) (real interface: ovpns1). Jun 30 06:18:15 ac3prod-pfvpn01 php-cgi[389]: rc.bootup: sync unbound done. Jun 30 06:18:15 ac3prod-pfvpn01 kernel: done. Jun 30 06:18:16 ac3prod-pfvpn01 kernel: done. Jun 30 06:18:46 ac3prod-pfvpn01 kernel: done. Jun 30 06:18:46 ac3prod-pfvpn01 kernel: done. Jun 30 06:18:46 ac3prod-pfvpn01 php-cgi[389]: rc.bootup: NTPD is starting up. Jun 30 06:18:47 ac3prod-pfvpn01 kernel: done. Jun 30 06:18:47 ac3prod-pfvpn01 check_reload_status[372]: Updating all dyndns Jun 30 06:18:48 ac3prod-pfvpn01 php-cgi[389]: rc.bootup: The command '/usr/local/sbin/strongswanrc stop' returned exit code '1', the output was 'strongswan not running? (check /var/run/daemon-charon.pid).' Jun 30 06:18:48 ac3prod-pfvpn01 kernel: .done. Jun 30 06:18:52 ac3prod-pfvpn01 php-cgi[389]: rc.bootup: Creating rrd update script Jun 30 06:18:52 ac3prod-pfvpn01 kernel: done. Jun 30 06:18:52 ac3prod-pfvpn01 syslogd: exiting on signal 15 Jun 30 06:18:52 ac3prod-pfvpn01 syslogd: kernel boot file is /boot/kernel/kernel Jun 30 06:18:53 ac3prod-pfvpn01 kernel: done. Jun 30 06:18:53 ac3prod-pfvpn01 php-fpm[342]: /rc.start_packages: Restarting/Starting all packages. Jun 30 06:18:53 ac3prod-pfvpn01 root[74820]: Bootup complete Jun 30 06:18:54 ac3prod-pfvpn01 radiusd[69873]: Debugger not attached Jun 30 06:18:54 ac3prod-pfvpn01 radiusd[69873]: tls: In order to use TLS 1.0 and/or TLS 1.1, you likely need to set: cipher_list = "DEFAULT@SECLEVEL=1" Jun 30 06:18:54 ac3prod-pfvpn01 radiusd[69873]: Loaded virtual server <default> Jun 30 06:18:54 ac3prod-pfvpn01 radiusd[69873]: Loaded virtual server default Jun 30 06:18:54 ac3prod-pfvpn01 radiusd[69873]: Ignoring "sql" (see raddb/mods-available/README.rst) Jun 30 06:18:54 ac3prod-pfvpn01 radiusd[69873]: Ignoring "ldap" (see raddb/mods-available/README.rst) Jun 30 06:18:54 ac3prod-pfvpn01 radiusd[69873]: # Skipping contents of 'if' as it is always 'false' -- /usr/local/etc/raddb/sites-enabled/inner-tunnel-ttls:63 Jun 30 06:18:54 ac3prod-pfvpn01 radiusd[69873]: Loaded virtual server inner-tunnel-ttls Jun 30 06:18:54 ac3prod-pfvpn01 radiusd[69873]: # Skipping contents of 'if' as it is always 'false' -- /usr/local/etc/raddb/sites-enabled/inner-tunnel-peap:63 Jun 30 06:18:54 ac3prod-pfvpn01 radiusd[69873]: Loaded virtual server inner-tunnel-peap Jun 30 06:18:54 ac3prod-pfvpn01 radiusd[69873]: Ready to process requests Jun 30 06:18:55 ac3prod-pfvpn01 login[92071]: login on ttyu0 as root Jun 30 06:18:55 ac3prod-pfvpn01 login[90487]: login on ttyv0 as root Jun 30 06:18:55 ac3prod-pfvpn01 sshguard[92715]: Now monitoring attacks. Jun 30 06:19:00 ac3prod-pfvpn01 newsyslog[19020]: logfile turned over due to size>500K cat system.log Jun 30 06:19:00 ac3prod-pfvpn01 newsyslog[19020]: logfile turned over due to size>500K Jun 30 06:19:00 ac3prod-pfvpn01 sshguard[92715]: Exiting on signal. Jun 30 06:19:00 ac3prod-pfvpn01 sshguard[19638]: Now monitoring attacks. Jun 30 06:20:25 ac3prod-pfvpn01 sshd[66828]: Accepted publickey for admin from xxxxxxxx port 38367 ssh2: RSA zzzzzzzzzz Jun 30 06:20:45 ac3prod-pfvpn01 pkg-static[28646]: pfSense-repoc-20230605 installed Jun 30 06:20:45 ac3prod-pfvpn01 pkg-static[28646]: pfSense-upgrade upgraded: 1.0_59 -> 1.0_68 Jun 30 06:22:08 ac3prod-pfvpn01 kernel: pid 89349 (pkg-static), jid 0, uid 0, was killed: failed to reclaim memory Jun 30 06:22:12 ac3prod-pfvpn01 kernel: pid 85909 (radiusd), jid 0, uid 0, was killed: failed to reclaim memory
-
I figured out what was wrong, I was running a nano instance and that doesn't seem to work too well with radius package installed. I upgraded the instance to small and things seems to work now.
-
Ah, the actual instance size?
Do you know if it was exhausting the memory?
-
@stephenw10 it was a t2.nano (maybe t3.nano) , and I changed to .small and that resolved my issues
I assume it was memory related, but never saw any warning or anything.