High VSphere cpu load but low pfsense cpu load



  • Hello there, i have a problem that's been bugging me for a while. When i have a mid to high load on the wan, pfsense's cpu spikes in vsphere but not in the pfsense guest vm. Is this a common problem or is it just me that has this and might there be a solution? I made a quick screenshot collage to make this more transparent rather than my unclear explanation. I'm very grateful for any help!

    The screenshot's were taken when i did a wan speedtest at 21-23 mb/sec over a loadbalancing config consisting of 2x100mbit connections, but the problem remains even if i only use one of the two's. Internaly there's no problem, at 100mb/sec transfer speeds inside lan the cpu doesn't go over 100mhz.

    It uses 5700mhz out of 21000mhz, this can not be right?

    ESXi 5.5
    Intel E5-1650v2
    Supermicro X9SRL-F
    Virtual nics with vmxnet3

    Direct link: http://i59.tinypic.com/b6szh2.jpg



  • no one have ever heard of this problem?



  • There is a post 15 posts down from yours titled pfsense 2.1 vmware cpu host high usage.  Have you looked at it?



  • @KOM:

    There is a post 15 posts down from yours titled pfsense 2.1 vmware cpu host high usage.  Have you looked at it?

    oh, didn't notice it, thanks. However, there doesn't seem to be a fix for this problem. But i'm "glad" that i'm not the only one with this issue.



  • Are you using pfSense in a basic manner, or do you have lots of extra packages installed like Squid and Snort?



  • @KOM:

    Are you using pfSense in a basic manner, or do you have lots of extra packages installed like Squid and Snort?

    very basic manner, i only have nmap and OpenVPN Client Export Utility installed.



  • i have the sameproblem and make some tests.

    so here the results of my test

    the current pfs 2.1.5 have defenitly a bug under vmware 5.5u1.

    in one test the failure occurse 2 min after the restart, i think the reasen was the high load (400mbit) traffic.

    after several times something is crash and i get Dup! if i make a ping.

    the power will trunkated by 100mbit on each Interface.

    i test it with 8 cores then with 4 cores. my vm have 4 nics all intel 1000.

    also 8gb ram. thr Maschine is a ibm blade.

    here the ping:

    PING 193.84.xxx.xxx (193.84.178.161) 56(84) bytes of data.
    64 bytes from 193.84.xxx.xxx: icmp_seq=1 ttl=64 time=8.10 ms
    64 bytes from 193.84.xxx.xxx: icmp_seq=1 ttl=64 time=8.10 ms (DUP!)
    64 bytes from 193.84.xxx.xxx: icmp_seq=2 ttl=64 time=8.38 ms
    64 bytes from 193.84.xxx.xxx: icmp_seq=2 ttl=64 time=8.38 ms (DUP!)

    after a reboot of the pfs everything is ok.



  • so i made some tests and change the e1000 nic  with the vmxnet3 nic.

    the result was a freezing of the esxi host maschine.

    the 2.1.5 release version is definitly not stabel under esxi 5.5u1.

    i say bye bye pfsense it is not usable with high load of nic traffic.

    i test also vlan support with e1000 and vmxnet3 is also buggy, packet drops and so on.



  • must be something specific on your end ….
    i've never had stability issue's on esxi with any version of pfsense.

    i do experience somewhat high cpu usage when going from VLAN_x to VLAN_y at wire speed of 1gbit/s.

    if you want to use the vmxnet drivers, then you should wait for pf 2.2, they are builtin.



  • I use pfSense on ESXi 5.5.0 with e1000 NICs without any issue.  Now, we only have a 90/90Mbps link and it is rarely that busy.


  • LAYER 8 Global Moderator

    I run esix 5.5u1 build 2143827 with pfsense 2.1.5 32bit without any issue, using vmxnet3 drivers - installed from esxi media, etc.

    I don't have any issues with stability at all.. now I only have a 60mbps internet connection, but I do move lots of files over gig connections locally from physical network to vm's not having any issues.

    I don't see anything out of wac to be honest.. So cpu on pfsense spikes when I max out my connection, and shows it - and sure vm shows it using more mhz..  But its running on a n40L for gosh sake with AMD Turion™ II Neo 2x1.5ghz cpus

    couple things I see from the OP, not running tools - running old version 8 of the hardware, I would run 10 - but have to run 9 since the client can not edit version 10 hardware.. Stupid vmware ;)

    I am out of town currently - all these tests where done while I was vpn'd into the pfsense network even..  Be happy to put something gig on the wan and pump as much bandwidth as it can through it. But I seems to be reporting ok to me - unless I am seeing something wrong here..  pfsense cpu goes up, esxi reports uses more mhz..








  • how many cpu's are inside of your maschines ?

    i reduced the cpu to 2 cores and now i have 400 mbit, bevore only 50 mbit



  • @Terrabit_AH:

    so i made some tests and change the e1000 nic  with the vmxnet3 nic.

    the result was a freezing of the esxi host maschine.

    the 2.1.5 release version is definitly not stabel under esxi 5.5u1.

    i say bye bye pfsense it is not usable with high load of nic traffic.

    Clearly you have an ESX issue to take up with VMware, a VM should never, ever, under any circumstances, be able to crash the host.

    There are many thousands if not tens of thousands of production installs out there running on ESX, many of those on 5.5u1. There are no stability issues.



  • you wrong, we send the logs to vmware and it is realy true the pfsense maschine freezed the vswitch on the esx host.


  • LAYER 8 Global Moderator

    And why don't you post those findings here, share with pfsense team so they could correct it if really the case.. Did you create a bug report from the info that vmware gave you from the logs.. What logs did you send exactly?



  • this is very simple, the pfsense team give me no response.

    i made the offer but now response !

    https://forum.pfsense.org/index.php?topic=70092.45



  • i've noticed your Pfsense VM doesn't have a Vmware Tools installed !



  • i made the offer but now response !

    I suspect that they would be much more likely to attach to your cloud and try to fix the problem you're having if you had a support contract.



  • @Jamerson:

    i've noticed your Pfsense VM doesn't have a Vmware Tools installed !

    Yeah i've had problems with vmtools for pfsense, but thats not the issue here since i've had it running before with the same issue, unfortunetly :/


Log in to reply