Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Random disconnect

    Scheduled Pinned Locked Moved General pfSense Questions
    12 Posts 3 Posters 935 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      michmoor LAYER 8 Rebel Alliance @bmeeks
      last edited by

      @bmeeks said in Random disconnect:

      The fact you saw gateway monitoring alerts in your pfSense logs indicates that something happened between your firewall and the rest of the world. That loss of connectivity would result in the "restart all packages" command getting issued automatically by pfSense.

      Interesting. Is there a way to check if my WAN interface went down? Some kind of status that says "up for x amount of time"?

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      M bmeeksB 2 Replies Last reply Reply Quote 0
      • M
        michmoor LAYER 8 Rebel Alliance @michmoor
        last edited by

        @bmeeks

        Yep...Interface status change.

        Nov 13 01:16:20 GAFW kernel: ix3: link state changed to DOWN
        Nov 13 01:16:20 GAFW check_reload_status[2674]: Linkup starting ix3
        Nov 13 01:16:30 GAFW check_reload_status[2674]: Linkup starting ix3
        Nov 13 01:16:30 GAFW kernel: ix3: link state changed to UP

        Is there a place to see this in the GUI ?

        Firewall: NetGate,Palo Alto-VM,Juniper SRX
        Routing: Juniper, Arista, Cisco
        Switching: Juniper, Arista, Cisco
        Wireless: Unifi, Aruba IAP
        JNCIP,CCNP Enterprise

        bmeeksB 1 Reply Last reply Reply Quote 0
        • bmeeksB
          bmeeks @michmoor
          last edited by

          @michmoor said in Random disconnect:

          Is there a way to check if my WAN interface went down? Some kind of status that says "up for x amount of time"?

          The only way I know of is to check the system log. The gateway alarms will be logged there. You can also seem them with details under the Gateways tab of the STATUS > SYSTEM LOGS page.

          1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks @michmoor
            last edited by

            @michmoor said in Random disconnect:

            Is there a place to see this in the GUI ?

            There is a GUI page with several tabs to view system logs. So "yeah", there is a way to see this in the GUI the way I would interpret it.

            M 1 Reply Last reply Reply Quote 0
            • M
              michmoor LAYER 8 Rebel Alliance @bmeeks
              last edited by

              @bmeeks
              I see it now.

              e404dd19-f4e4-43fe-8ce7-94a887cf4d82-image.png

              Thanks Bill. Also i didnt know about the packages tied to interface status part so thats really good to know.

              Firewall: NetGate,Palo Alto-VM,Juniper SRX
              Routing: Juniper, Arista, Cisco
              Switching: Juniper, Arista, Cisco
              Wireless: Unifi, Aruba IAP
              JNCIP,CCNP Enterprise

              bmeeksB 1 Reply Last reply Reply Quote 0
              • bmeeksB
                bmeeks @michmoor
                last edited by bmeeks

                @michmoor said in Random disconnect:

                i didnt know about the packages tied to interface status

                Think about it logically -- many services (packages) need to know about active interfaces and what their status and IP settings are. So, there has to be a mechanism to let packages know something has changed with interfaces. pfSense uses a sort of big hammer here -- simply restart all the packages when an interface changes. That causes them to behave like an initial boot-up and they all read the information they need/require again and configure themselves accordingly.

                1 Reply Last reply Reply Quote 1
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Yup there could be more finesse there. But most pfSense installs rarely see an interface link status change so not often a big issue.

                  M 1 Reply Last reply Reply Quote 0
                  • bmeeksB
                    bmeeks
                    last edited by

                    You can also see a series of "restarting packages" commands over time if your dpinger-monitored interface is down for an extended period. The interface will be cycled, but if dpinger still sees no connectivity to the monitored IP, then it will restart the interface again. This will continue until the interface's connectivity to the monitor IP is restored, or you tell dpinger and pfSense to always consider the gateway as "up".

                    1 Reply Last reply Reply Quote 0
                    • M
                      michmoor LAYER 8 Rebel Alliance @stephenw10
                      last edited by

                      @stephenw10 @bmeeks
                      Is that with ANY interface state change or only when an interface is a wan-type?

                      A flapping interface is not uncommon. So if i have a DMZ leg that is flapping does that mean my LAN -> WAN flows will be impacted? Essentially 2x interfaces that have nothing to do with DMZ will see an outage?

                      Firewall: NetGate,Palo Alto-VM,Juniper SRX
                      Routing: Juniper, Arista, Cisco
                      Switching: Juniper, Arista, Cisco
                      Wireless: Unifi, Aruba IAP
                      JNCIP,CCNP Enterprise

                      bmeeksB 1 Reply Last reply Reply Quote 0
                      • bmeeksB
                        bmeeks @michmoor
                        last edited by bmeeks

                        @michmoor said in Random disconnect:

                        @stephenw10 @bmeeks
                        Is that with ANY interface state change or only when an interface is a wan-type?

                        A flapping interface is not uncommon. So if i have a DMZ leg that is flapping does that mean my LAN -> WAN flows will be impacted? Essentially 2x interfaces that have nothing to do with DMZ will see an outage?

                        I believe it is either a physical link status change or the execution of ifconfig up or ifconfig down that triggers the restart all packages command. And I think dpinger will trigger that ifconfig up/down command when it fails to reach the monitored IP within the configured time window. I have never examined all the PHP and shell script code for this in pfSense to find every possible trigger.

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.