Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Internet Speeds crushed after update to 26.07

    Scheduled Pinned Locked Moved General pfSense Questions
    9 Posts 3 Posters 596 Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      hypnosis4u2nv
      last edited by hypnosis4u2nv

      26.07-RELEASE running on my own box.

      I don't have any error messages so I don't know where to begin looking for the issue, but my download speeds seem to be capped at around 200Mbps on a 1Gig line. Speed tests from the modem show I'm getting the full 1Gig so it's not that. I also have a VPN setup and doing a speed test drops to nothing.

      1 Reply Last reply Reply Quote 0
      • H Offline
        hypnosis4u2nv
        last edited by

        Rebooted, waited 15 mins for things to settle down and I had the same results. Went back to 23.06.1 and everything is good again. Not sure what it is but the lack of error messages and my VPN becoming basically unusable is going to keep me off this 26.07 for a bit.

        1 Reply Last reply Reply Quote 0
        • H Offline
          hypnosis4u2nv
          last edited by

          Figured it out and will post here in case someone else runs across this.

          It appears to have been caused by Suricata blocks for STREAM excessive retransmissions, HTTP Response excessive header repetition, HTTP Request unrecognized authorization method, Ethertype unknown, STREAM Packet with invalid timestamp, weak cryptographic parameters (PRF).

          These were all new alerts that were blocked right after booting up on 26.07. Once I suppressed those GID:SID and cleared the blocks, everything started working again.

          SteveITSS 1 Reply Last reply Reply Quote 3
          • SteveITSS Offline
            SteveITS Rebel Alliance @hypnosis4u2nv
            last edited by

            @hypnosis4u2nv We have this note in our procedures from prior forum conversations/posts. The first sentence in particular may apply here?

            "Suricata: disable categories via dropsid.conf because categories are always re-enabled at every reinstall/upgrade. “events” rules are “designed to simply be "informative" and log particular events the IDS sees. 99% of these events are totally harmless.” disable the stream-events.rules category or it will block lots of traffic on false positives. consider disabling all *events categories.
            add disable-sid.conf file on SID Mgmt tab and assign to “Disable SID List”:

            # Example of modifying state for specific categories entirely.
            # "snort_" limits to Snort VRT rules, "emerging-" limits to 
            # Emerging Threats Open rules, "etpro-" limits to ET-PRO rules.
            # "shellcode" with no prefix would match in any vendor set.
            # snort_web-iis,emerging-shellcode,etpro-imap,shellcode
            
            stream-events.rules,quic-events.rules
            

            Check “Enable Automatic SID State Management” on SID tab (top of page)"

            To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
            Only install packages for your version of pfSense.
            Upvote 👍 helpful posts!

            H 2 Replies Last reply Reply Quote 2
            • H Offline
              hypnosis4u2nv @SteveITS
              last edited by

              @SteveITS Thanks Steve. One of those brain fart moments where you never had an issue before and then all of sudden the internet goes down - and right during the late evening when you're half asleep and about to go to bed. 🤦 It was much easier to just revert back for the night and look again through fresh eyes.

              1 Reply Last reply Reply Quote 1
              • H Offline
                hypnosis4u2nv @SteveITS
                last edited by hypnosis4u2nv

                @SteveITS I also added -events.rules as suggested to the SID management to disable all those from loading at the next update. Thank you.

                SteveITSS 1 Reply Last reply Reply Quote 0
                • SteveITSS Offline
                  SteveITS Rebel Alliance @hypnosis4u2nv
                  last edited by

                  @hypnosis4u2nv I think it matches from the beginning of the name? So we use "stream-events.rules,quic-events.rules" as above.

                  To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                  Only install packages for your version of pfSense.
                  Upvote 👍 helpful posts!

                  H 1 Reply Last reply Reply Quote 0
                  • H Offline
                    hypnosis4u2nv @SteveITS
                    last edited by hypnosis4u2nv

                    @SteveITS (-events.rules) worked as a wild card to disable all the event rules categories.

                    1 Reply Last reply Reply Quote 2
                    • M Offline
                      marcosm Netgate
                      last edited by

                      See: https://redmine.pfsense.org/issues/16808

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                      Privacy Policy · Cookie Policy