Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Auto Backup Error: Unable to resolve acb.netgate.com

    Scheduled Pinned Locked Moved General pfSense Questions
    20 Posts 4 Posters 848 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      digimd
      last edited by

      I have been facing this error related to failure to autobackup my config. I have seen this message even when pfblocker is turned off but less often. Where is the problem? Thanks.

      An error occurred while uploading the encrypted Netgate pfSense Plus configuration to https://acb.netgate.com/save ( Unable to resolve acb.netgate.com ) @ 2024-11-03 13:06:03
      
      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @digimd
        last edited by

        @digimd Does Diagnostics/DNS Lookup succeed?

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        D 1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Is it after rebooting? Like during boot?

          D 1 Reply Last reply Reply Quote 0
          • D
            digimd @SteveITS
            last edited by

            @SteveITS Yes, it does without issues.

            1 Reply Last reply Reply Quote 0
            • D
              digimd @stephenw10
              last edited by

              @stephenw10 said in Auto Backup Error: Unable to resolve acb.netgate.com:

              Is it after rebooting? Like during boot?

              I do not think so. I almost never rebooted this pfsense machine except for updates.

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Does it fail every time? Like if you make a manual backup or try to view the available backups for the device?

                D 1 Reply Last reply Reply Quote 0
                • D
                  digimd @stephenw10
                  last edited by

                  @stephenw10
                  I believe it is hit or miss. Manual backup works. The only resolution I find for this is to disable pfblockerNG, then these random errors would disappear.

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Hmm, anything in the pfBlocker logs?

                    Are you just using Unbound for local DNS?

                    D 1 Reply Last reply Reply Quote 0
                    • D
                      digimd @stephenw10
                      last edited by

                      @stephenw10 said in Auto Backup Error: Unable to resolve acb.netgate.com:

                      Hmm, anything in the pfBlocker logs?

                      I see in the error logs "validation failed" for some DNSBL types

                      Are you just using Unbound for local DNS?

                      Yes

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        What about in the dnsbl.log file? That's where I might expect to see it.

                        Otherwise do you see Unbound restarting a lot? It could be failing to resolve at that point and that could coincide with acb trying to send a config update.

                        D 1 Reply Last reply Reply Quote 0
                        • D
                          digimd @stephenw10
                          last edited by

                          @stephenw10
                          I checked both and I don't see errors.

                          GertjanG 1 Reply Last reply Reply Quote 0
                          • GertjanG
                            Gertjan @digimd
                            last edited by

                            @digimd

                            Can you execute

                            17afa4e6-4a85-4d67-9fb4-b007b8c12510-image.png

                            and list the last 20 lines or so ? (if any).

                            No "help me" PM's please. Use the forum, the community will thank you.
                            Edit : and where are the logs ??

                            D 1 Reply Last reply Reply Quote 0
                            • D
                              digimd @Gertjan
                              last edited by

                              @Gertjan

                              Nov  5 11:25:03 pfsense unbound[1948]: [1948:0] info: start of service (unbound 1.19.3).
                              Nov  5 11:30:38 pfsense unbound[93372]: [93372:0] info: start of service (unbound 1.19.3).
                              Nov  5 11:40:25 pfsense unbound[1249]: [1249:0] info: start of service (unbound 1.19.3).
                              Nov  5 12:32:38 pfsense unbound[91078]: [91078:0] info: start of service (unbound 1.19.3).
                              Nov  5 12:33:03 pfsense unbound[39185]: [39185:0] info: start of service (unbound 1.19.3).
                              Nov  5 12:33:25 pfsense unbound[14094]: [14094:0] info: start of service (unbound 1.19.3).
                              Nov  5 12:33:48 pfsense unbound[47038]: [47038:0] info: start of service (unbound 1.19.3).
                              Nov  5 12:34:11 pfsense unbound[15742]: [15742:0] info: start of service (unbound 1.19.3).
                              Nov  5 12:34:32 pfsense unbound[30305]: [30305:0] info: start of service (unbound 1.19.3).
                              Nov  6 11:09:39 pfsense unbound[65438]: [65438:0] info: start of service (unbound 1.19.3).
                              Nov  6 11:11:31 pfsense unbound[99829]: [99829:0] info: start of service (unbound 1.19.3).
                              Nov  6 19:15:48 pfsense unbound[23707]: [23707:0] info: start of service (unbound 1.19.3).
                              Nov  6 22:30:28 pfsense unbound[39026]: [39026:0] info: start of service (unbound 1.19.3).
                              
                              GertjanG 1 Reply Last reply Reply Quote 0
                              • GertjanG
                                Gertjan @digimd
                                last edited by Gertjan

                                @digimd

                                It's restarting "all the time". Not a problem, but every time it restarts, you - and pfSense - loose DNS for a moment.
                                Restarting unbound takes some time.
                                You use pfBlockerng : restarting takes even more time.

                                Do you use "ISC DHP", and if so, you have this option checked (under Services > DNS Resolver > General Settings) ?

                                e820c95f-5315-4573-b75d-ab8f47366243-image.png

                                If so, uncheck it. save and Apply.

                                You can set pfBlockerng settings so DNSBL are reloaded less frequent, thus less DNS resolver restarts.

                                No "help me" PM's please. Use the forum, the community will thank you.
                                Edit : and where are the logs ??

                                D 1 Reply Last reply Reply Quote 0
                                • D
                                  digimd @Gertjan
                                  last edited by digimd

                                  @Gertjan
                                  Yes, I figured ;(

                                  I still use the ISC DHCP. The other (newer) was crashing to my eye without even checking the logs. I don't have that option checked, but only for static mappings (the option just below). I will turn off pfblocker until I am able to troubleshoot the unbound issues. I have "Resolver Live Sync" option checked so it should not have to reload. Cron setting (under General menu) is set to hourly.

                                  GertjanG 1 Reply Last reply Reply Quote 0
                                  • GertjanG
                                    Gertjan @digimd
                                    last edited by Gertjan

                                    @digimd said in Auto Backup Error: Unable to resolve acb.netgate.com:

                                    I still use the ISC DHCP. The other (newer) was crashing to my eye without even checking the logs. I don't have that option checked, but only for static mappings (the option just below)

                                    Ok !
                                    I was just checking. "DHCP Registration" when checked, restarts unbound(resolver) on every DHCP event. And, as already stated, unbound restating == temporary DNS outage.

                                    @digimd said in Auto Backup Error: Unable to resolve acb.netgate.com:

                                    I have "Resolver Live Sync" option checked so it should not have to reload.

                                    I'm not so sure about that.
                                    I read "Resolver Live Sync" as "restart unbound" to have it taken in effect new DNSBL info.

                                    "Resolver Live Sync" only is available if you use the old "Unbound mode".
                                    The newer Python mode is waaaay faster (with more options etc ^^).

                                    2dff4902-289b-46df-b445-66df380085f7-image.png

                                    It's worth trying Python mode.
                                    Select it, save, and do a Firewallpf > BlockerNG > Update reload all.

                                    @digimd said in Auto Backup Error: Unable to resolve acb.netgate.com:

                                    Cron setting (under General menu) is set to hourly.

                                    That's a choice.

                                    Mine is set to :

                                    881b3d35-1b1e-4e8a-a7f6-f7c2342d634d-image.png

                                    so one a day.
                                    As that's fine for me ©
                                    see here : it's the unbound cache size, which shows ... the cache size 😊 and the frequency of unbound restarting.

                                    No "help me" PM's please. Use the forum, the community will thank you.
                                    Edit : and where are the logs ??

                                    D 1 Reply Last reply Reply Quote 0
                                    • D
                                      digimd @Gertjan
                                      last edited by

                                      @Gertjan
                                      Awesome! I switched to Python mode. I must have used some outdated tutorial. I changed the Message Cache Size from 4mg to 20 mg (is this enough?) to test this intesreting point you brought up; thank you. FYI, I don't have DHCP Registration checked, so I am fine there.

                                      GertjanG 1 Reply Last reply Reply Quote 0
                                      • GertjanG
                                        Gertjan @digimd
                                        last edited by Gertjan

                                        @digimd

                                        Wait a day or so, then re execute

                                        cat /var/log/resolver/log | grep 'start'
                                        

                                        as I've shown above, and see that unbound restarts (way) less times a day.

                                        No "help me" PM's please. Use the forum, the community will thank you.
                                        Edit : and where are the logs ??

                                        D 1 Reply Last reply Reply Quote 1
                                        • D
                                          digimd @Gertjan
                                          last edited by

                                          This post is deleted!
                                          1 Reply Last reply Reply Quote 0
                                          • stephenw10S
                                            stephenw10 Netgate Administrator
                                            last edited by

                                            You could also try adding a host override for acb.netgate.com as a test. I wouldn't leave it like that because the IP might change at some point in the future. But it's been the same until now!

                                            1 Reply Last reply Reply Quote 1
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.