1
23.7 Legacy Series / Re: Connection lost on all interfaces after boot for few minutes
« on: January 09, 2024, 07:58:08 pm »I guess suricata IPS mode or Zenarmor does that since it needs to hook netmap which will bring down all attached interfaces for technical reasons
Cheers,
Franco
Just noticed that ~10 min connection gap has started just after flowd vacuum process. I soon as I was able to login had to restart squid because it wasnt processing any connection. (Surricata disabled, no more eth up/down)
Code: [Select]
<13>1 2024-01-09T19:38:04+01:00 OPNsense.local flowd_aggregate.py 74241 - [meta sequenceId="26"] start watching flowd
<13>1 2024-01-09T19:38:05+01:00 OPNsense.local flowd_aggregate.py 74241 - [meta sequenceId="27"] vacuum src_addr_details_086400.sqlite
<13>1 2024-01-09T19:38:08+01:00 OPNsense.local flowd_aggregate.py 74241 - [meta sequenceId="28"] vacuum src_addr_000300.sqlite
<13>1 2024-01-09T19:38:08+01:00 OPNsense.local flowd_aggregate.py 74241 - [meta sequenceId="29"] vacuum src_addr_003600.sqlite
<13>1 2024-01-09T19:38:08+01:00 OPNsense.local flowd_aggregate.py 74241 - [meta sequenceId="30"] vacuum src_addr_086400.sqlite
<13>1 2024-01-09T19:38:08+01:00 OPNsense.local flowd_aggregate.py 74241 - [meta sequenceId="31"] vacuum interface_000030.sqlite
<13>1 2024-01-09T19:38:08+01:00 OPNsense.local flowd_aggregate.py 74241 - [meta sequenceId="32"] vacuum interface_000300.sqlite
<13>1 2024-01-09T19:38:08+01:00 OPNsense.local flowd_aggregate.py 74241 - [meta sequenceId="33"] vacuum interface_003600.sqlite
<13>1 2024-01-09T19:38:08+01:00 OPNsense.local flowd_aggregate.py 74241 - [meta sequenceId="34"] vacuum interface_086400.sqlite
<13>1 2024-01-09T19:38:08+01:00 OPNsense.local flowd_aggregate.py 74241 - [meta sequenceId="35"] vacuum dst_port_000300.sqlite
<13>1 2024-01-09T19:38:08+01:00 OPNsense.local flowd_aggregate.py 74241 - [meta sequenceId="36"] vacuum dst_port_003600.sqlite
<13>1 2024-01-09T19:38:08+01:00 OPNsense.local flowd_aggregate.py 74241 - [meta sequenceId="37"] vacuum dst_port_086400.sqlite
<13>1 2024-01-09T19:38:09+01:00 OPNsense.local flowd_aggregate.py 74241 - [meta sequenceId="38"] vacuum done
<13>1 2024-01-09T19:48:03+01:00 OPNsense.local opnsense 53536 - [meta sequenceId="1"] /usr/local/sbin/pluginctl: plugins_configure webproxy (1,restart)
<165>1 2024-01-09T19:48:23+01:00 OPNsense.local squid 30216 - [meta sequenceId="2"] Squid Parent: squid-1 process 31999 exited due to signal 15 with status 0
<161>1 2024-01-09T19:48:23+01:00 OPNsense.local squid 30216 - [meta sequenceId="3"] Exiting due to unexpected forced shutdown
<165>1 2024-01-09T19:48:30+01:00 OPNsense.local squid 12231 - [meta sequenceId="4"] Squid Parent: will start 1 kids
<165>1 2024-01-09T19:48:30+01:00 OPNsense.local squid 12231 - [meta sequenceId="5"] Squid Parent: (squid-1) process 12654 started