• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Problem with inter VLAN Connections

Scheduled Pinned Locked Moved L2/Switching/VLANs
14 Posts 2 Posters 884 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    sysadminfromhell
    last edited by Nov 13, 2023, 10:17 AM

    Hello everyone,

    I switched my Intel X550-T2 to an X710-T4L since this change my inter vlan communication or vlan communication in general is instable.
    ssh connections, or tcp connection in general, gets reset sometimes.
    In a packet trace it looks like the dst pc reset the connection but on the other side the connection stays open until the service says timeout.
    So this isnt the case, the pfsense somehow resets the connection but doesnt see it?

    Sometimes in a call /ms teams) or some sort the audio/video stutters also since this change.

    Is there any way to troubleshoot that?

    Ah in the vlan the connections are stable, so if I open a ssh or a tcp connection, to the pfsense for example, nothing happens.
    Any help is appreciated.

    Setup:

    ixl2 - LAN 192.168.178.1/24 - into MikroTik Switch 10G FC off
    ixl3 - VMNET 172.16.24.1/24 - into MikroTik Switch 10G FC off
    ixl3.100 - GUESTWLAN 172.16.23.1/24
    ixl3.30 - LAB 192.168.30.1/24
    Access Point located in ixl3.100 and ixl2 - into MikoTik Switch 1G FC auto

    Kind regards,

    1 Reply Last reply Reply Quote 0
    • S
      sysadminfromhell
      last edited by Nov 13, 2023, 12:10 PM

      OKAy, I found the problem: the state - somehow - gets exceeded very fast so that the TCP:A flag is not allowed anymore.
      I Try to reboot at first and then try to figure out to make the states waiting times a bit higher. All is default but this is weird.

      1 Reply Last reply Reply Quote 0
      • S
        sysadminfromhell
        last edited by Nov 14, 2023, 10:26 AM

        Okay I really do need the help of the community here:
        I really cant find any issue with my routing or why the state gets stale so fast.

        Here i Tried to find the issue:

        First I can open an ssh connection, but after 20 Seconds the Flag doesnt get accepted anymore even the Rule is build to accept any TCP Flag
        8016a33a-1ff6-40ab-aad9-2ac0d4dab9eb-image.png
        b551f22c-c599-49d8-ab5d-bdbdf571af36-image.png
        I really cant find an issue with the routing or some sort of, maybe its a flag configuration but the optimazation options are the same as before: Normal
        dfe7205c-ffdf-4d61-92dc-d3da97879c56-image.png
        same as the State Timeouts:
        8eea8bc1-6f82-4b5e-ac22-e7bcf55a24a2-image.png
        Nothing fits with this 20 Seconds, the packet capture shows that its not 20 Seconds but 10 but even that makes no sense.

        P 1 Reply Last reply Nov 14, 2023, 10:52 AM Reply Quote 0
        • P
          Popolou @sysadminfromhell
          last edited by Nov 14, 2023, 10:52 AM

          @sysadminfromhell Are you running any part of it through a VM instance?

          S 1 Reply Last reply Nov 14, 2023, 10:56 AM Reply Quote 0
          • S
            sysadminfromhell @Popolou
            last edited by Nov 14, 2023, 10:56 AM

            @Popolou no the pfsense is Baremetal but I found that the driver which currently get shipped with pfsense should be broken with the x710. The card is not very populated right now because its hard to get it cheap but I guess this should be the case here maybe. I try ti get more information about it to find a way to troubleshoot that.
            https://forum.netgate.com/topic/162333/intel-x710-issues/36

            P 1 Reply Last reply Nov 14, 2023, 11:01 AM Reply Quote 0
            • P
              Popolou @sysadminfromhell
              last edited by Nov 14, 2023, 11:01 AM

              @sysadminfromhell Under System -> Advanced -> Networking towards the bottom under Network Interfaces, can i ask what do you have ticked/unticked?

              S 1 Reply Last reply Nov 14, 2023, 11:04 AM Reply Quote 0
              • S
                sysadminfromhell @Popolou
                last edited by Nov 14, 2023, 11:04 AM

                @Popolou as before with the x550:
                e5526d6b-7957-4f12-9641-5b22e5e1f4af-image.png

                P 1 Reply Last reply Nov 14, 2023, 11:11 AM Reply Quote 0
                • P
                  Popolou @sysadminfromhell
                  last edited by Nov 14, 2023, 11:11 AM

                  @sysadminfromhell Those seem correct. I had very similar issues (posted about it) and noticed some of the same symptoms. Needed to remove all hardware offloading to restore functionality. Have you disabled the checksum offloading and tested? I've had mixed results with this on an x710 too.

                  S 3 Replies Last reply Nov 14, 2023, 11:21 AM Reply Quote 0
                  • S
                    sysadminfromhell @Popolou
                    last edited by Nov 14, 2023, 11:21 AM

                    @Popolou I did not check that, but I can test it and see if this works. I Keep you updated

                    1 Reply Last reply Reply Quote 0
                    • S
                      sysadminfromhell @Popolou
                      last edited by Nov 14, 2023, 12:22 PM

                      @Popolou unfurtanatly its the same problem:
                      f6a1aa65-a727-43e7-b926-7183b8ad2ecc-image.png

                      I now try to enable all the offload and see if this fixes it.
                      If not, maybe I need and developer to look at it or give me a hint to troubleshoot it more. Maybe I need the new drivers?

                      S 1 Reply Last reply Nov 14, 2023, 12:30 PM Reply Quote 0
                      • S
                        sysadminfromhell @sysadminfromhell
                        last edited by Nov 14, 2023, 12:30 PM

                        @sysadminfromhell Even here the same issue:

                        ad5c42dc-55a7-4a8c-b8c2-69fdb3300d43-image.png
                        2cd2b99c-8eb8-469d-84a0-cb372bf6ad86-image.png

                        S 1 Reply Last reply Nov 14, 2023, 1:35 PM Reply Quote 0
                        • S
                          sysadminfromhell @sysadminfromhell
                          last edited by Nov 14, 2023, 1:35 PM

                          I will buy a new x550 and replace it once again if not someone has a Idea (driver update or some sort of trick). I just need to inform netgate before because if I change my network card the ndi changes too.

                          1 Reply Last reply Reply Quote 0
                          • S
                            sysadminfromhell @Popolou
                            last edited by Nov 14, 2023, 5:05 PM

                            @Popolou So I pciked up a x550 locally to replace the broken one and the x710 which appearently doesnt work properly and see there: "almost" no problems. I guess somehow the IPSec is broken and the S2S connection to my lab doesnt work properly.

                            P 1 Reply Last reply Nov 20, 2023, 11:06 AM Reply Quote 0
                            • P
                              Popolou @sysadminfromhell
                              last edited by Nov 20, 2023, 11:06 AM

                              @sysadminfromhell I suppose it's possible it could have been a cheap/fake x710 giving you the problems. I'd have probably looked at the firewall rules or checked if there was any rate limiting in place but it sounds like the replacement nic has put you right.

                              1 Reply Last reply Reply Quote 0
                              2 out of 14
                              • First post
                                2/14
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                This community forum collects and processes your personal information.
                                consent.not_received