CP not work correctly



  • After update to last  from 26.04 v2 CP not work correctly

    
    # ipfw pipe list
    20002:   2.050 Kbit/s    0 ms burst 0 
    q151074 100 sl. 0 flows (1 buckets) sched 85538 weight 0 lmax 0 pri 0 droptail
     sched 85538 type FIFO flags 0x0 0 buckets 1 active
      0 ip           0.0.0.0/0             0.0.0.0/0       30     5170 15 2136   0
    20003:   5.120 Kbit/s    0 ms burst 0 
    q151075 100 sl. 0 flows (1 buckets) sched 85539 weight 0 lmax 0 pri 0 droptail
     sched 85539 type FIFO flags 0x0 0 buckets 1 active
      0 ip           0.0.0.0/0             0.0.0.0/0        3     3126  1   98   0
    # ipfw pipe list
    20002:   2.050 Kbit/s    0 ms burst 0 
    q151074 100 sl. 0 flows (1 buckets) sched 85538 weight 0 lmax 0 pri 0 droptail
     sched 85538 type FIFO flags 0x0 0 buckets 1 active
      0 ip           0.0.0.0/0             0.0.0.0/0       33     5432 12 1878   0
    20003:   5.120 Kbit/s    0 ms burst 0 
    q151075 100 sl. 0 flows (1 buckets) sched 85539 weight 0 lmax 0 pri 0 droptail
     sched 85539 type FIFO flags 0x0 0 buckets 1 active
      0 ip           0.0.0.0/0             0.0.0.0/0        8     3568  4  344   0
    # ipfw table 1 list
    192.168.10.253/32 mac 00:15:c5:20:27:78 20002
    # ipfw table 2 list
    192.168.10.253/32 mac 00:15:c5:20:27:78 20003
    
    

  • Rebel Alliance Developer Netgate

    Nothing changed on the builder or in the code between the 26th to today that would have affected CP. Are you sure nothing else changed?



  • @jimp:

    Nothing changed on the builder or in the code between the 26th to today that would have affected CP. Are you sure nothing else changed?

    I update from  release 4.4.2011.There no problem at all.We use external radius.

    
    uname -a
    FreeBSD 8.1-RELEASE-p2 #1: Mon Apr  4 06:03:23 EDT 2011     sullrich@FreeBSD_8.0_pfSense_2.0-snaps.pfsense.org:/usr/obj.pfSense/usr/pfSensesrc/src/sys/pfSense_SMP.8  i386
    
    20012:   2.048 Mbit/s    0 ms burst 0 
    q151084 100 sl. 0 flows (1 buckets) sched 85548 weight 0 lmax 0 pri 0 droptail
     sched 85548 type FIFO flags 0x0 0 buckets 1 active
      0 ip           0.0.0.0/0             0.0.0.0/0       11      726  0    0   0
    20013:   5.120 Mbit/s    0 ms burst 0 
    q151085 100 sl. 0 flows (1 buckets) sched 85549 weight 0 lmax 0 pri 0 droptail
     sched 85549 type FIFO flags 0x0 0 buckets 1 active
      0 ip           0.0.0.0/0             0.0.0.0/0        2     1652  0    0   0
    
    Login OK: [user/1111] (from client pfsense port 12 cli 00:15:f2:a7:45:4d) 
    +- entering group post-auth {...}
    Exec-Program output: WISPr-Bandwidth-Max-Up=2048,WISPr-Bandwidth-Max-Down=5120,
    Exec-Program-Wait: value-pairs: WISPr-Bandwidth-Max-Up=2048,WISPr-Bandwidth-Max-Down=5120
    Exec-Program: returned: 0
    ++[exec] returns noop
    Sending Access-Accept of id 21 to 192.168.0.254 port 57887
    	WISPr-Bandwidth-Max-Up = 2048
    	WISPr-Bandwidth-Max-Down = 5120
    Finished request 9.
    Going to the next request
    
    

    This is release with problem with radius bandw. parameters
    (pipe show  is different from release 4.4.2011):

    
    name -a
    FreeBSD 8.1-RELEASE-p3 #1: Mon Apr 25 20:44:39 EDT 2011     sullrich@FreeBSD_8.0_pfSense_2.0-snaps.pfsense.org:/usr/obj.pfSense/usr/pfSensesrc/src/sys/pfSense.8  i386
    
    [2.0-RC1][root@xxxyyy.homeunix.org]/var/log(15): ipfw show
    65291    0      0 allow pfsync from any to any
    65292    0      0 allow carp from any to any
    65301    8    296 allow ip from any to any layer2 mac-type 0x0806
    65302    0      0 allow ip from any to any layer2 mac-type 0x888e
    65303    0      0 allow ip from any to any layer2 mac-type 0x88c7
    65304    0      0 allow ip from any to any layer2 mac-type 0x8863
    65305    0      0 allow ip from any to any layer2 mac-type 0x8864
    65306    0      0 allow ip from any to any layer2 mac-type 0x888e
    65307    0      0 deny ip from any to any layer2 not mac-type 0x0800
    65310  349  29338 allow ip from any to { 255.255.255.255 or 192.168.0.254 } in
    65311  764 147306 allow ip from { 255.255.255.255 or 192.168.0.254 } to any out
    65312    0      0 allow icmp from { 255.255.255.255 or 192.168.0.254 } to any out icmptypes 0
    65313    0      0 allow icmp from any to { 255.255.255.255 or 192.168.0.254 } in icmptypes 8
    65314    0      0 allow ip from table(3) to any in
    65315    0      0 allow ip from any to table(4) out
    65316    0      0 pipe tablearg ip from table(5) to any in
    65317    0      0 pipe tablearg ip from any to table(6) out
    65318    0      0 allow ip from any to table(7) in
    65319    0      0 allow ip from table(8) to any out
    65320    0      0 pipe tablearg ip from any to table(9) in
    65321    0      0 pipe tablearg ip from table(10) to any out
    65322 2418 144231 pipe tablearg ip from table(1) to any in
    65323  897  70184 pipe tablearg ip from any to table(2) out
    65531  815  83726 fwd 127.0.0.1,8000 tcp from any to any in
    65532  727  65756 allow tcp from any to any out
    65533    6    614 deny ip from any to any
    65534    0      0 allow ip from any to any layer2
    65535  312  31665 allow ip from any to any
    
    Login OK: [user/1111] (from client pfsense port 10 cli 00:15:f2:a7:45:4d) 
    +- entering group post-auth {...}
    Exec-Program output: WISPr-Bandwidth-Max-Up=2048,WISPr-Bandwidth-Max-Down=5120,
    Exec-Program-Wait: value-pairs: WISPr-Bandwidth-Max-Up=2048,WISPr-Bandwidth-Max-Down=5120
    Exec-Program: returned: 0
    ++[exec] returns noop
    Sending Access-Accept of id 246 to 192.168.0.254 port 12556
    	WISPr-Bandwidth-Max-Up = 2048
    	WISPr-Bandwidth-Max-Down = 5120
    
    [2.0-RC1][root@xxxyyy.homeunix.org]/var/log(16): ipfw pipe show
    20010:   2.050 Kbit/s    0 ms burst 0 
    q151082 100 sl. 0 flows (1 buckets) sched 85546 weight 0 lmax 0 pri 0 droptail
     sched 85546 type FIFO flags 0x0 0 buckets 1 active
      0 ip           0.0.0.0/0             0.0.0.0/0     2515   186655 99 7266 1806
    20011:   5.120 Kbit/s    0 ms burst 0 
    q151083 100 sl. 0 flows (1 buckets) sched 85547 weight 0 lmax 0 pri 0 droptail
     sched 85547 type FIFO flags 0x0 0 buckets 1 active
      0 ip           0.0.0.0/0             0.0.0.0/0        1       54  0    0   0
    
    

  • Rebel Alliance Developer Netgate

    If you were coming from an older snapshot then you might be seeing this:

    https://rcs.pfsense.org/projects/pfsense/repos/mainline/commits/2d4003aab1d969ed9ba3e52f2fe3ec083e4bef8c

    We were not calculating the bandwidth received from RADIUS according to the standard. You'll probably have to fix your bandwidth values in your RADIUS server.


Locked