<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Crash Report (on pfsense SG-2440)]]></title><description><![CDATA[<p dir="auto">Hey guys - I've got a box that has crashed 2 times now in the last two days. I'm not sure what is causing it - the config is almost identical to another box I have. The only thing I've changed recently is the MSS on VPN to 1200 and set the Phase 2 to AES GCM (from AES)</p>
<p dir="auto">The crashes have happened once at a busy time in the workday (only a couple hours after updating the config) then later on after most everybody would have been home.</p>
<p dir="auto"><a href="http://pastebin.com/3jVnsNZJ" target="_blank" rel="noopener noreferrer nofollow ugc">http://pastebin.com/3jVnsNZJ</a>any ideas?</p>
]]></description><link>https://forum.netgate.com/topic/97289/crash-report-on-pfsense-sg-2440</link><generator>RSS for Node</generator><lastBuildDate>Tue, 10 Mar 2026 03:54:22 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/97289.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 29 Mar 2016 13:17:07 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Crash Report (on pfsense SG-2440) on Wed, 30 Mar 2016 21:35:39 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">I have a third site that I was planning on pushing the AES-NI to, and I think I will try that over the weekend - I will have to wait and see if it crashes that.</p>
</blockquote>
<p dir="auto">The greater brother of yours SG-4860 will be able to push 500+ MBit/s over IPSec VPN tunnel and this stable<br />
as a rock, so perhaps it will be more pending then on the lower power or a miss configuration perhaps.</p>
<blockquote>
<p dir="auto">If it doesn't, it's more than likely hardware related.</p>
</blockquote>
<p dir="auto">Do you really think that the hardware is malformed or buggy because your IPSec VPN is failing?<br />
Hm, I am not really sure but you got two support calls for that actions like explained here in that case.<br />
Did you ever thought about that, to take one of this to solve that issues by professional support?</p>
]]></description><link>https://forum.netgate.com/post/611944</link><guid isPermaLink="true">https://forum.netgate.com/post/611944</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Wed, 30 Mar 2016 21:35:39 GMT</pubDate></item><item><title><![CDATA[Reply to Crash Report (on pfsense SG-2440) on Wed, 30 Mar 2016 19:51:06 GMT]]></title><description><![CDATA[<p dir="auto">@BlueKobold:</p>
<blockquote>
<blockquote>
<p dir="auto">were 4 crashes within the first 24 hours of having the new policy…</p>
</blockquote>
<p dir="auto">Did you change the policies on both sides of the VPN tunnel?</p>
</blockquote>
<p dir="auto">Yes, it was changed on both sides. Over 24 hours reverted now and still no crashes. I'm starting to think it may be a hardware issue - my other site has the same configuration now since Monday and has not crashed.<br />
I have a third site that I was planning on pushing the AES-NI to, and I think I will try that over the weekend - I will have to wait and see if it crashes that. If it doesn't, it's more than likely hardware related.</p>
]]></description><link>https://forum.netgate.com/post/611925</link><guid isPermaLink="true">https://forum.netgate.com/post/611925</guid><dc:creator><![CDATA[dcdefiore]]></dc:creator><pubDate>Wed, 30 Mar 2016 19:51:06 GMT</pubDate></item><item><title><![CDATA[Reply to Crash Report (on pfsense SG-2440) on Wed, 30 Mar 2016 16:06:36 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">were 4 crashes within the first 24 hours of having the new policy…</p>
</blockquote>
<p dir="auto">Did you change the policies on both sides of the VPN tunnel?</p>
]]></description><link>https://forum.netgate.com/post/611870</link><guid isPermaLink="true">https://forum.netgate.com/post/611870</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Wed, 30 Mar 2016 16:06:36 GMT</pubDate></item><item><title><![CDATA[Reply to Crash Report (on pfsense SG-2440) on Wed, 30 Mar 2016 11:42:57 GMT]]></title><description><![CDATA[<p dir="auto">So far, it's been 20 hours since I've reverted the changes, and there have been no crashes, conversely, there were 4 crashes within the first 24 hours of having the new policy…</p>
]]></description><link>https://forum.netgate.com/post/611826</link><guid isPermaLink="true">https://forum.netgate.com/post/611826</guid><dc:creator><![CDATA[dcdefiore]]></dc:creator><pubDate>Wed, 30 Mar 2016 11:42:57 GMT</pubDate></item><item><title><![CDATA[Reply to Crash Report (on pfsense SG-2440) on Tue, 29 Mar 2016 18:02:32 GMT]]></title><description><![CDATA[<p dir="auto">@BlueKobold:</p>
<blockquote>
<blockquote>
<p dir="auto">the config is almost identical to another box I have.</p>
</blockquote>
<p dir="auto">If this is not be the exactly same hardware under that config as the other box is based on those comparing<br />
would be nonsense in my eyes. Different hardware may causing different action or reaction.</p>
</blockquote>
<p dir="auto">Sorry, the hardware is the same - both are SG-2440s. The configuration is almost the same (except they are different locations, so different subnets, etc).<br />
The only other difference, is that this site (with the crashing unit) has about 4 users and the other site only has 1. Again - I only make the config change Monday morning, so I'm working with a small sample set.<br />
I've changed it back as of a couple of hours ago - no crashes yet, but the crashes were (seemingly) random, so I'm playing the waiting game now.</p>
]]></description><link>https://forum.netgate.com/post/611713</link><guid isPermaLink="true">https://forum.netgate.com/post/611713</guid><dc:creator><![CDATA[dcdefiore]]></dc:creator><pubDate>Tue, 29 Mar 2016 18:02:32 GMT</pubDate></item><item><title><![CDATA[Reply to Crash Report (on pfsense SG-2440) on Tue, 29 Mar 2016 17:30:33 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">the config is almost identical to another box I have.</p>
</blockquote>
<p dir="auto">If this is not be the exactly same hardware under that config as the other box is based on those comparing<br />
would be nonsense in my eyes. Different hardware may causing different action or reaction.</p>
<blockquote>
<p dir="auto">The only thing I've changed recently is the MSS on VPN to 1200 and set the Phase 2 to AES GCM (from AES)</p>
</blockquote>
<p dir="auto">And if you change it back is the failure then gone? Or do you have then anymore problems based on that issue?</p>
]]></description><link>https://forum.netgate.com/post/611708</link><guid isPermaLink="true">https://forum.netgate.com/post/611708</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Tue, 29 Mar 2016 17:30:33 GMT</pubDate></item></channel></rss>