Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Subnet collapses periodically since 24.11-RELEASE

    Scheduled Pinned Locked Moved DHCP and DNS
    38 Posts 5 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      vf1954 @w0w
      last edited by

      @w0w I don't know. I never use flow control. I will look more deeply into this.

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @vf1954
        last edited by

        @vf1954 flow control issues not going to have your client change its IP.. There is zero reason to turn off flow control on anything.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        w0wW 1 Reply Last reply Reply Quote 0
        • V
          vf1954 @johnpoz
          last edited by

          @johnpoz So I did some more testing.

          Testing arp and ipconfig all reveals a DHCP server sending a 192.168.0.x broadcast. No picture attached, just letting you know.
          Communicating to TP-Link engineers revealed that the wifi-router (Archer AX73v1) will act as a DHCP server as an emergency only if it detects no DHCP server anymore.

          Since the network went down again this morning, I produced the following test results:

          • Disconnecting the tp-link router(s) does NOT allow a client to establish a connection to netGATE pfSense.
          • This means netGATE pfSense is somehow dropping the DHCP server randomly, and the tp-link notices this and says "uh oh" and does what it can.
          • While in this strange state, I can enter into console and enter into shell and ping, for example, our OES server at 192.168.3.xx.
          • In our OES server, it cannot access or ping anything back
          • Our debian pihole dns on 192.168.3.yy server does seem to work with ping...
          • Attempting to connect my laptop to the netGATE does not produce any connection (see picture).
            Screenshot from 2025-02-27 09-57-04.png
          • Running codes while in shell produced the following (I am using KEA)
            Screenshot from 2025-02-27 09-57-14.png

          With the wifi-router disconnected, I re-ran two commands on a windows PC but nothing really connects.
          Screenshot from 2025-02-27 09-50-14.png
          Screenshot from 2025-02-27 09-53-28.png

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @vf1954
            last edited by

            @vf1954 169.254 is a link local IP range windows will use when a dhcp server is not available.

            Run isc for your dhcp server - kea is still in preview to be honest..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            V 1 Reply Last reply Reply Quote 0
            • V
              vf1954 @johnpoz
              last edited by

              @johnpoz I did as you advised. I am back on ISC. I just see that it will be depreciated.
              based upon the ps aux command, only a ipv6 is visible, and no ipv4 at all. Is that correct? Is that the result of KEA?

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @vf1954
                last edited by johnpoz

                @vf1954 said in Subnet collapses periodically since 24.11-RELEASE:

                I just see that it will be depreciated.

                And how many versions of down the road do you think that is? 3 - 6, 12?

                kea is not at feature parity yet.. So there is no chance you going to see isc removed as an option that is for sure.

                I would bet you that there will be a switch over to where kea is default, and then some time later after that would it be removed. I don't see kea becoming default for at least a few more versions of pfsense.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • w0wW
                  w0w @johnpoz
                  last edited by

                  @johnpoz said in Subnet collapses periodically since 24.11-RELEASE:

                  @vf1954 flow control issues not going to have your client change its IP.. There is zero reason to turn off flow control on anything.

                  As long as it's not Windows and not 169.x.x.x, you are right...

                  @vf1954 said in Subnet collapses periodically since 24.11-RELEASE:

                  I never use flow control.

                  For example, I didn't even know it was enabled.

                  BTW, I've been using KEA in a small network for over a year with VLANs, LAGs, VPN, and CARP. So far, there have been no issues with collapses or clients not receiving addresses.
                  But switching to ISC is a good idea for debug anyway.

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @w0w
                    last edited by

                    @w0w yeah its coming along - but just look at the board, many posts about kea. Don't see any reason to use it if your having issues. Try again next release to be honest.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    V 1 Reply Last reply Reply Quote 1
                    • V
                      vf1954 @johnpoz
                      last edited by vf1954

                      @johnpoz Hello.

                      Well knocking on wood. The switch back to ISC was the solution. So far no issues for 3 weeks straight.

                      What should I do to report KEA malfunctioning?

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @vf1954
                        last edited by

                        @vf1954 unless your running 25.03 beta and want to report stuff in that section. I see little point in pointing out what might be wrong with 24.11 version of kea. Now if your using what is about to come out, and you see problems - they still might be able to be fixed before release.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.