Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFSense doesn't answer while transferring large data between LAN and DMZ

    Scheduled Pinned Locked Moved Traffic Shaping
    7 Posts 3 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pburgisser
      last edited by

      Hello everyone,

      my company has a PFSense appliance (OpenAliance) and 2 networks LAN+DMZ.

      A backup server is available on the LAN zone where a server on the DMZ transfer a large backup file (zip) through SSH.

      As the transfer takes the whole bandwidth the PFSense doesn't deserve any request during the transfer, this is very annoying because we can't use internet anymore.

      With the traffic shaping, am I capable to limit de bandwidth between those 2 zones ? Or any other solution ?

      Thank you for you help

      Phil.

      1 Reply Last reply Reply Quote 0
      • S
        SeventhSon
        last edited by

        You could look into the shaper to limit the bandwidth or try NIC polling or both maybe.

        1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          There could be other things going on that just using up all of the bandwidth there.

          If your LAN<->DMZ transfers are pushing more traffic than your hardware is capable of moving, then other things (like the GUI, DNS forwarder, etc) won't have any spare CPU cycles on the router to work properly.

          Remember: Upvote with the šŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • P
            pburgisser
            last edited by

            @jimp:

            There could be other things going on that just using up all of the bandwidth there.

            If your LAN<->DMZ transfers are pushing more traffic than your hardware is capable of moving, then other things (like the GUI, DNS forwarder, etc) won't have any spare CPU cycles on the router to work properly.

            I think this is the problem… how can I avoid this issue?

            Thank you

            1 Reply Last reply Reply Quote 0
            • S
              SeventhSon
              last edited by

              I would first make sure what the problem is (look at the RRD graphs for CPU and traffic for example).

              You might just need more powerful hardware, or disable some CPU consuming packages/settings?
              Is pfSense also doing VPN crypto?

              Traffic shaping is going to take more CPU than just routing the packets, so if the problem is CPU, shaping probably won't help that much (transfer is still taking 100% CPU, transfer will be slower).

              1 Reply Last reply Reply Quote 0
              • P
                pburgisser
                last edited by

                Hi SeventhSon,

                As the graphs describe, it reach 99% while huge transfer :-(

                I'm going to see if I can build a second firewall on a VM or upgrading this one…

                Thank you for your help

                1 Reply Last reply Reply Quote 0
                • S
                  SeventhSon
                  last edited by

                  So it reaches 100% CPU?Ā  ???

                  If so, polling might help:

                  http://blog.pfsense.org/?p=115

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.