• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPsec kernel panic when enabling MSS clamping

Scheduled Pinned Locked Moved IPsec
10 Posts 2 Posters 1.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • E Offline
    ericafterdark
    last edited by May 11, 2015, 7:35 PM

    I can crash the web interface by setting 'Enable MSS clamping on VPN traffic'. Does not matter if I enter a value or keep it blank.

    Same issue when using net.inet.ipsec.directdispatch = 0.

    Same issue after a a reset of all settings.

    Even after a reboot the web interface does not respond. I have to connect a display and keyboard to the pfSense box and reset all settings to be able to work with the web interface again.

    1 Reply Last reply Reply Quote 0
    • E Offline
      eri--
      last edited by May 12, 2015, 7:29 AM

      This is related to a bug in FreeBSD which has been corrected in newer versions.
      I recorded it here https://redmine.pfsense.org/issues/4699 for follow-up.

      1 Reply Last reply Reply Quote 0
      • E Offline
        ericafterdark
        last edited by May 12, 2015, 5:55 PM

        Is there an easy way for me to resolve this problem right now so that I can work with IPsec?

        1 Reply Last reply Reply Quote 0
        • E Offline
          eri--
          last edited by May 13, 2015, 8:28 PM

          It will be when the patch referenced is put on the snapshots of snapshots.pfsense.org.
          Monitor the issue on redmine to have you notify when that is done.

          1 Reply Last reply Reply Quote 0
          • E Offline
            ericafterdark
            last edited by May 15, 2015, 11:21 AM

            @ermal:

            It will be when the patch referenced is put on the snapshots of snapshots.pfsense.org.
            Monitor the issue on redmine to have you notify when that is done.

            Ok thanks!

            1 Reply Last reply Reply Quote 0
            • E Offline
              eri--
              last edited by May 15, 2015, 5:56 PM

              Coming back to this and re-checking i was not able to see this.

              Can you specify if this is a kernel panic or just the webgui?

              1 Reply Last reply Reply Quote 0
              • E Offline
                ericafterdark
                last edited by May 17, 2015, 6:56 PM

                Yes, it completely crashes the webgui. How can I resolve this or help resolving this issue? Strange no one ever seemed to have encountered this same problem?

                1 Reply Last reply Reply Quote 0
                • E Offline
                  eri--
                  last edited by May 18, 2015, 2:54 PM

                  I think you are victim of a bad upgrade here!
                  Can you show the system logs when this happens?

                  1 Reply Last reply Reply Quote 0
                  • E Offline
                    ericafterdark
                    last edited by May 18, 2015, 5:18 PM

                    @ermal:

                    I think you are victim of a bad upgrade here!
                    Can you show the system logs when this happens?

                    I'm running a clean install - but - I did reset my settings a couple of times. I've exported my config and there is no mention of mss clamping. I'll reproduce asap and share the outcome here.

                    1 Reply Last reply Reply Quote 0
                    • E Offline
                      ericafterdark
                      last edited by May 19, 2015, 10:14 AM

                      I can reproduce it by clean installing pfSense, enabling IPsec and activate mss clamping. No more webgui, no more ssh as soon as I submit. I tried searching the logs via an attached display and keyboard but could not find anything suspicious.

                      1 Reply Last reply Reply Quote 0
                      10 out of 10
                      • First post
                        10/10
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received