Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    slow gui after upgrade from 2.6 to 2.7 on proxmox.

    Scheduled Pinned Locked Moved Virtualization
    33 Posts 2 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      OK, so how is DNS configured locally? Is pfSense resolving? Forwarding? Does it resolve to an IPv6 IP that has to time-out?

      W 1 Reply Last reply Reply Quote 0
      • W
        wifi75 @stephenw10
        last edited by

        @stephenw10 said in slow gui after upgrade from 2.6 to 2.7 on proxmox.:

        OK, so how is DNS configured locally? Is pfSense resolving? Forwarding? Does it resolve to an IPv6 IP that has to time-out?

        only ipv4 .
        DNS Forwarder disabled!

        0f0b7511-0f1d-4114-83ff-bd976594a894-image.png

        c1674b46-d196-4c80-83da-d0069ce3ec43-image.png

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Is there a delay when resolving though?

          Is Unbound (the resolver) set in resolving mode? Is DNSec enabled?

          W 1 Reply Last reply Reply Quote 0
          • W
            wifi75 @stephenw10
            last edited by

            @stephenw10
            yes:

            572a2c06-942a-4a07-9917-e6473ea4cbf3-image.png

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Ok that should be fine. It resolves to your external IP I assume? And HAProxy is listening there so it should respond.

              As a test you could add a host override on a client device dircetly so it doesn't have to resolve it. If that is then fast then it's a DNS problem. If it's still slow then it's an HAProxy issue.

              W 1 Reply Last reply Reply Quote 0
              • W
                wifi75 @stephenw10
                last edited by

                @stephenw10
                as this example ?

                bbfae1ec-c7f5-46fb-b555-877fb8100536-image.png

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  No add it to the hosts file on the test client behind pfSense directly. Doing that will mean it doesn't have to resolve against pfSense so any DNS delay would be removed.

                  W 2 Replies Last reply Reply Quote 0
                  • W
                    wifi75 @stephenw10
                    last edited by wifi75

                    @stephenw10

                    ok.When I get home I'll edit the Windows hosts file and update you.
                    Thank you so much for your support!

                    but I have to add the local IP of the server that responds to the DNS ?

                    1 Reply Last reply Reply Quote 1
                    • W
                      wifi75 @stephenw10
                      last edited by

                      @stephenw10
                      but inwindows host file I have to add the local IP of the server that responds to the DNS ?

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        No you would add, for example, firewall.mydomain.com and point that towards whatever IP it should resolve to. So probably your WAN IP or whatever HAProxy is listening on.

                        W 1 Reply Last reply Reply Quote 0
                        • W
                          wifi75 @stephenw10
                          last edited by

                          @stephenw10
                          ok but I have wan Dynamic Ip...

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            It only has to work once in order to test. I assume the IP doesn't change that quickly.

                            W 1 Reply Last reply Reply Quote 0
                            • W
                              wifi75 @stephenw10
                              last edited by

                              @stephenw10 I tried with the host file, it's still slow

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                Ok, so it's almost certainly an HAProxy issue. Is that logging anything? Hard to know what might have changed between 2.6 and 2.7 but the haproxy package was updated.

                                W 1 Reply Last reply Reply Quote 0
                                • W
                                  wifi75 @stephenw10
                                  last edited by

                                  @stephenw10
                                  for my metero server, in Ha proxy I added the following security headers, could these be?

                                  00255083-ce0e-45b1-81a4-080576d7340a-image.png

                                  1 Reply Last reply Reply Quote 0
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    I don't use HAProxy, I couldn't really say how that might affect it. But anythijng that applied to I would expect to equally affect traffic from external IPs and it is not. The only significant difference there is the source IP used which I guess some of those might see. But I wouldn't expect a delay, it would just reject it instantly.
                                    Just how 'slow' is it from internal clients?

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.