Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Fatal Error Unable to create lock file: No space left on device (28)

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    23 Posts 4 Posters 3.7k Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • srgwilliamsS Offline
      srgwilliams
      last edited by srgwilliams

      Unable to access the pfsense via gui and so I connected via console. After typing exit I keep on getting this error (Fatal Error Unable to create lock file: No space left on device (28)) that keeps on looping and looping. This allows me to not type anything, and the fw is basically unresponsive. I suspect the disk space is full as I recently installed Snort and this log files must have filed up all the space, but I'm unable to get in and make the changes to fix this.

      Urgent guidance is greatly appreciated! The FW acts as the DHCP for production PCs, and pcs are already losing connection and not able to renew their leases.

      94dd74f0-cd65-45f5-be11-df0f8f7b14dd-image.png

      patient0P 1 Reply Last reply Reply Quote 0
      • patient0P Offline
        patient0 @srgwilliams
        last edited by

        @srgwilliams your best chance is rebooting the firewall while connected to the console (not SSH but physically to the machine).

        And then boot into single user mode - boot menu entry 2 - and check and remove the snort logfile (in directory /var/log/snort/) if that is the reason. Your issue could also be a failing disk.

        srgwilliamsS 1 Reply Last reply Reply Quote 0
        • srgwilliamsS Offline
          srgwilliams @patient0
          last edited by srgwilliams

          @patient0

          I was able to power cycle using the button on the phyiscal fw after production was done for the day, and Iwas able to communicate with the fw again. b93faf14-11d6-4121-a76f-19ed51868ba1-image.png
          now the issue is that the fw which is the dchp has not started issuing and renewing ips normally, what would you suggest could be a fix?

          patient0P 1 Reply Last reply Reply Quote 0
          • patient0P Offline
            patient0 @srgwilliams
            last edited by

            @srgwilliams said in Fatal Error Unable to create lock file: No space left on device (28):

            now the issue is that the fw which is the dchp has not started issuing and renewing ips normally, what would you suggest could be a fix?

            It seems you booted into an older ZFS snapshot now. Is that on purpose?

            Your prompt reads 23.09-RELEASE now and first it was 25.07.1-RELEASE. Switching the snapshot also includes the config which may or may not be different to your configuration before.

            srgwilliamsS 1 Reply Last reply Reply Quote 0
            • srgwilliamsS Offline
              srgwilliams @patient0
              last edited by

              @patient0 no this was not on purpose. Booted automatically, it was the first time I was able to have any type of info entered into the firewall again. I appreciate your quick replies. How would I boot up into the previous snapshot 25.07.1?

              patient0P 1 Reply Last reply Reply Quote 0
              • patient0P Offline
                patient0 @srgwilliams
                last edited by patient0

                @srgwilliams said in Fatal Error Unable to create lock file: No space left on device (28):

                How would I boot up into the previous snapshot 25.07.1?

                At the boot menu, entry 8 is "Boot Environments" where you can choose which snapshot you want to boot from.

                Netgate Documentation: Selecting Boot Environments in the Loader Menu

                Btw: if in the 25.07.1 you may still get the out of space issue. In that case you will have to reboot into the single user mode. Since no services are being startet in that mode you may have a better chance to delete the snort log.

                Netgate Documenation: Troubleshooting in Single User Mode

                srgwilliamsS 1 Reply Last reply Reply Quote 0
                • srgwilliamsS Offline
                  srgwilliams @patient0
                  last edited by

                  @patient0
                  I tried booting into the different boot environment. It's not showing all the information I believe. I haven't done this process before but I don't think it's supposed to look like this

                  After hitting pause
                  c2c864a0-2319-4a3a-a12a-22cce055295b-image.png
                  After hitting 8
                  280f5ed9-20e8-4463-a3ff-ceed0353b273-image.png
                  After hitting up key to cycle to 2 out of 7
                  66443b8e-7147-481e-abf2-ce74b610594b-image.png
                  3 out of 7
                  022e8806-3a19-4544-b8aa-ea0937e70610-image.png
                  4 out of 7
                  fb369f0f-3c64-465a-a9b1-3185fc44c254-image.png

                  and so forth for 5,6,7.

                  Do I disregard all this and just try troubleshooting in the single user mode?

                  patient0P w0wW 2 Replies Last reply Reply Quote 0
                  • patient0P Offline
                    patient0 @srgwilliams
                    last edited by

                    @srgwilliams said in Fatal Error Unable to create lock file: No space left on device (28):

                    Do I disregard all this and just try troubleshooting in the single user mode?

                    You do have to select the right snapshot otherwise you are ending up cleaning up another snapshot.

                    The snapshot/boot environment naming contains the date and time, e.g. default_20251004112311 would be 04 October 2025 11:23:11.

                    But the lasted boot environment is usually called 'default' which would be 3 of 7 in your case.

                    I see you tried number 3 and it did not boot but automatically reboot?

                    If you get it to boot into 23.09 that be a start if you can access the GUI from there and check the boot environments. In the GUI you see the pfSense+ version.

                    If you have lots of snapshot - let's say older than 23.09 - you can make space be deleting at least one of them. That maybe is enough to reboot successfully into 25.07.1. Don't delete any of 23., 24. or 25.* yet.

                    patient0P srgwilliamsS 2 Replies Last reply Reply Quote 0
                    • w0wW Offline
                      w0w @srgwilliams
                      last edited by

                      @srgwilliams
                      Is the GUI still accessible? When you boot into 23.09-RELEASE? Go to the System - Boot environments and post the screenshot.

                      1 Reply Last reply Reply Quote 0
                      • patient0P Offline
                        patient0 @patient0
                        last edited by

                        And maybe check if you have all information for a potential reinstall:

                        • pfSense+ installation ISO/USB or other image
                        • the new installer need internet connection: WAN settings will be needed
                        • configuration backup

                        If Automatic Configuration Backup is/was enabled (maybe you can check when it's possible to boot into an older snapshot) then you would need the device key and the encryption password. With these infos you can restore the latest backup if no current config backup file is available.

                        1 Reply Last reply Reply Quote 0
                        • srgwilliamsS Offline
                          srgwilliams @patient0
                          last edited by

                          @patient0 @w0w No I'm not able to access the GUI. When I load into 1/7 I have internet connection but still not able to access the gui.

                          After loading 3/7 again, it has loaded into 25.07.1-Release and I am able to see my configured interfaces for my vlan again
                          b0872c93-39e5-4ae2-9b82-ad99d1a5bfae-image.png

                          The fw is still not issuing IPs, though.

                          GertjanG patient0P 2 Replies Last reply Reply Quote 0
                          • GertjanG Offline
                            Gertjan @srgwilliams
                            last edited by

                            @srgwilliams

                            If you're here :
                            4ce3d25f-ae34-4e74-b541-18acbc220593-image.png

                            then : option 8.
                            Then

                            cd /var/log/
                            

                            look (use ls -al) for any 'snort' log files. Maybe its using a sub folder, if so :

                            cd snort
                            ls -al
                            

                            If you find some big log files 'kill them all' ^^

                            No "help me" PM's please. Use the forum, the community will thank you.

                            1 Reply Last reply Reply Quote 0
                            • patient0P Offline
                              patient0 @srgwilliams
                              last edited by

                              @srgwilliams said in Fatal Error Unable to create lock file: No space left on device (28):

                              The fw is still not issuing IPs, though.

                              Have you cleared out space? And if yes restart the GUI (11).

                              If DHCP is not giving out IPs and you can't access the GUI because the client doesn't get an IP, you can set a static IP on your client in the same IP range and try again.

                              srgwilliamsS 1 Reply Last reply Reply Quote 0
                              • srgwilliamsS Offline
                                srgwilliams @patient0
                                last edited by srgwilliams

                                @Gertjan said in Fatal Error Unable to create lock file: No space left on device (28):

                                cd /var/log/

                                okay, this doesn't seem to do anything though

                                @patient0 said in Fatal Error Unable to create lock file: No space left on device (28):

                                Have you cleared out space? And if yes restart the GUI (11).

                                haven't cleared out any space on this snapshot but this is how space looks currently
                                3fe259bc-ac46-410f-87ea-39302e4bab25-image.png

                                srgwilliamsS GertjanG 2 Replies Last reply Reply Quote 0
                                • srgwilliamsS Offline
                                  srgwilliams @srgwilliams
                                  last edited by srgwilliams

                                  I believe the dhcp service wasn't working due to lack of memory but I'm not sure anymore

                                  I've already tried statically assigning ips from clients on each vlan but that doesn't seem to work

                                  srgwilliamsS patient0P 2 Replies Last reply Reply Quote 0
                                  • srgwilliamsS Offline
                                    srgwilliams @srgwilliams
                                    last edited by srgwilliams

                                    For context. I have a pc that I connect to the firewall through Anydesk. It isolated to disclose the fw log in page (for PCI requirement). This pc and the fw is on the 92.x subnet. The pc is normally 92.3 and the fw 92.1

                                    c0e92c10-faa8-4902-9696-278dc4ced87b-image.png e588363a-c01d-4513-bf8e-c6056052879e-image.png

                                    1 Reply Last reply Reply Quote 0
                                    • patient0P Offline
                                      patient0 @srgwilliams
                                      last edited by

                                      @srgwilliams and does it work now?

                                      You can check if the GUI service is running by issuing on the firewall (if it runs on the standard ports:

                                      [25.11-RELEASE][root@pfp.home.arpa]/root: sockstat | egrep ':(80|443)'
                                      root    nginx      84995  5 tcp4    *:443                 *:*                  
                                      root    nginx      84995  6 tcp6    *:443                 *:*                  
                                      root    nginx      84995  7 tcp4    *:80                  *:*                  
                                      root    nginx      84995  9 tcp6    *:80                  *:*                  
                                      root    nginx      84900  5 tcp4    *:443                 *:*                  
                                      root    nginx      84900  6 tcp6    *:443                 *:*                  
                                      root    nginx      84900  7 tcp4    *:80                  *:*                  
                                      root    nginx      84900  9 tcp6    *:80                  *:*                  
                                      root    nginx      84524  5 tcp4    *:443                 *:*                  
                                      root    nginx      84524  6 tcp6    *:443                 *:*                  
                                      root    nginx      84524  7 tcp4    *:80                  *:*                  
                                      root    nginx      84524  9 tcp6    *:80                  *:*
                                      

                                      @srgwilliams said in Fatal Error Unable to create lock file: No space left on device (28):

                                      This pc and the fw is on the 92.x subnet. The pc is normally 92.3 and the fw 92.1

                                      Mmmh, that is odd, can you ping the firewall 93.1 from the 92.3 client? And the other way around, can you ping the 92.3 client?

                                      are the LAN (lan) -> lagg0.4091 (or which ever interface you are connecting to) IPs shown correct?

                                      srgwilliamsS 1 Reply Last reply Reply Quote 0
                                      • srgwilliamsS Offline
                                        srgwilliams @patient0
                                        last edited by

                                        @patient0
                                        48e13f3e-8917-443f-a1f4-d23d3088c4e5-image.png

                                        That's the thing. At this company they chose to have not to enable ICMP so I'm not able to ping anything, which is frustrating at times.

                                        The WAN is correct. The LAN lagg.4091 is 192.168.92.1/29 which is correct

                                        patient0P 1 Reply Last reply Reply Quote 0
                                        • patient0P Offline
                                          patient0 @srgwilliams
                                          last edited by patient0

                                          @srgwilliams said in Fatal Error Unable to create lock file: No space left on device (28):

                                          The GUI is listening then, that looks ok

                                          At this company they chose to have not to enable ICMP so I'm not able to ping anything

                                          Can you ncat -v 192.168.92.1 443 from the client? You're supposed to be on the same broadcast domain as the router, that should work. Have you used that client before, no Windows firewall active?

                                          And anything in the /var/log/nginx.log that indicates you're connection attempt?

                                          srgwilliamsS 1 Reply Last reply Reply Quote 0
                                          • srgwilliamsS Offline
                                            srgwilliams @patient0
                                            last edited by srgwilliams

                                            @patient0 said in Fatal Error Unable to create lock file: No space left on device (28):

                                            ncat -v 192.168.92.1 443 from the client?

                                            I get Ncat: TIMEOUT

                                            but no Windows Firewall active

                                            @patient0 said in Fatal Error Unable to create lock file: No space left on device (28):

                                            /var/log/nginx.log
                                            e59e1ff6-b121-41c7-bd8a-491403147c40-image.png
                                            I get an access denied message unfortunately.

                                            patient0P 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                                            Privacy Policy · Cookie Policy