Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfSense freezes on 1Gbit/s UDP Flood

    Scheduled Pinned Locked Moved Hardware
    11 Posts 7 Posters 4.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      crashi102
      last edited by

      Hello,

      I'm building a new Firewall Cluster for our data center with pfsense and since now I'm really impressed from this software. Actually I do some different workloads. One of them is a simulated dDoS Attack with spoofed DNS UDP packets. The attack hits the firewall with about 1Gbit/s. The Uplinks are 2x 1Gbit with LACP. So now I have the problem that while an attack is going on the whole System freezes. My question is if this is normal because of such a high packet rate or should this not happen and there is eventually a problem with the hardware.

      Hardware:

      Dual Intel(R) Xeon(R) CPU E5520 @ 2.27GHz
      Supermicro X8DTU-F
      24GB ECC Ram
      Intel SSD 330
      2x Intel I350-T4 Quad Port network cards

      Thanks for any advice.

      1 Reply Last reply Reply Quote 0
      • W
        wallabybob
        last edited by

        @crashi102:

        So now I have the problem that while an attack is going on the whole System freezes.

        Freezes as in: doesn't respond to pings? ssh sessions drop out? console doesn't respond to Enter key? Keyboard indicator lights (e.g. Caps Lock, Num Lock) don't respond to presses of the corresponding key?

        UDP flood probably indicates a high interrupt rate which could result in the CPU having few spare cycles to do other than handle interrupts. Does the freeze condition clear within a few minutes of the attack finishing?

        1 Reply Last reply Reply Quote 0
        • C
          crashi102
          last edited by

          Hi,

          freezes means that the whole systems is not responding. No ssh, gui and no console (eg. top vmstat etc.) is responding. When the attacks are finished the systems works and responds immediately normal.

          I tried different settings from this FQA http://doc.pfsense.org/index.php/Tuning_and_Troubleshooting_Network_Cards. I also disabled logging Firewall logs to the local disk.

          1 Reply Last reply Reply Quote 0
          • C
            crashi102
            last edited by

            I have found the problem. The dual motherboard was equipped with only one Intel CPU, because I needed the place for my 3rd network card I now have reinstalled the second CPU and the system is running normally again. Very strange, it seems not all dual motherboards runs smooth with only one CPU.

            1 Reply Last reply Reply Quote 0
            • K
              kejianshi
              last edited by

              I'm amazed that anyone would ever find a good reason to pull a CPU off their board.  Its definitely counter-intuitive. 
              Those rack-mounted systems really do force alot of compromise.

              1 Reply Last reply Reply Quote 0
              • B
                budisantoso
                last edited by

                Can you confirm that Intel I350-T4 Quad working fine in pfsense 2.1 ?
                Thanks.

                1 Reply Last reply Reply Quote 0
                • A
                  Aluminum
                  last edited by

                  @budisantoso:

                  Can you confirm that Intel I350-T4 Quad working fine in pfsense 2.1 ?
                  Thanks.

                  Works in 2.0.3 and 2.1

                  1 Reply Last reply Reply Quote 0
                  • T
                    Tikimotel
                    last edited by

                    Have you tried to up the sysctl setting "net.inet.udp.recvspace" to at least "131072" in the "System: Advanced: System Tunables"? (this should handle +200Mbit.)

                    1 Reply Last reply Reply Quote 0
                    • C
                      crashi102
                      last edited by

                      Sorry for my late response. Finally I have found the Problem. At the dashboard i had activated the thermal sensor plugin. When I flood my pfSense system with 1Gbit UDP packets and had the dashboard in my we browser open the whole system freezes when the plugin startet to refresh. Now I have deactivated the plugin and the freezes while an UDP flood are gone.

                      1 Reply Last reply Reply Quote 0
                      • K
                        kejianshi
                        last edited by

                        Thats interesting…

                        1 Reply Last reply Reply Quote 0
                        • S
                          Supermule Banned
                          last edited by

                          It still freezes when flooding with UDP packets…

                          On the SYN  ACK scripts, you cant reach any servers behind pfsense. Like they go offline. Its still responsive (GUI) and ping works fine...

                          Give me an IP to test and I will prove it ;)

                          Mine is off and its still not responsive.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.