You're not alone. I also have kernel crashes.. https://forum.opnsense.org/index.php?topic=45138.msg225446#msg225446
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuDevice: 1024-blocks Used:
/dev/gpt/swapfs 8620216 0
swapctl -l
abuse.ch/Feodo Tracker, abuse.ch/ThreatFox, abuse.ch/URLhaus, ET open/botcc, ET open/drop, ET open/dshield, ET open/emerging-dos, ET open/emerging-exploit, ET open/emerging-exploit_kit, ET open/emerging-phishing, ET open/emerging-scan, ET open/emerging-shellcode, ET open/emerging-sql, ET open/emerging-web_server, ET open/emerging-worm
Quote from: meyergru on January 22, 2025, 10:01:28 AMIDS mode can inspect packets after the fact and only generate an alarm. At this time, the packet was already processed. IPS mode has to actually check all the rules before it will decide on whether to actually allow the packet to pass.
QuoteOne of the most commonly asked questions is which interface to choose. Considering the continued use IPv4, usually combined with Network Address Translation, it is quite important to use the correct interface. If you are capturing traffic on a WAN interface you will see only traffic after address translation. This means all the traffic is originating from your firewall and not from the actual machine behind it that is likely triggering the alert.
Rules for an IDS/IPS system usually need to have a clear understanding about the internal network; this information is lost when capturing packets behind NAT.
[...]
Since the firewall is dropping inbound packets by default it usually does not improve security to use the WAN interface when in IPS mode because it would drop the packet that would have also been dropped by the firewall.
<7>cannot forward src fe80:6::99bc:8c8c:d836:c182, dst 2620:2d:4000:1::2a, nxt 6, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::99bc:8c8c:d836:c182, dst 2620:2d:4000:1::2b, nxt 6, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::99bc:8c8c:d836:c182, dst 2620:2d:4000:1::23, nxt 6, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::99bc:8c8c:d836:c182, dst 2620:2d:4002:1::197, nxt 6, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::99bc:8c8c:d836:c182, dst 2620:2d:4002:1::198, nxt 6, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2a01:111:f100:9001::1761:9097, nxt 6, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2a04:4e42::485, nxt 6, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2a04:4e42::485, nxt 6, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2a04:4e42::485, nxt 6, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2a04:4e42:200::485, nxt 6, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2a04:4e42:400::485, nxt 17, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2620:1ec:bdf::67, nxt 6, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2a04:4e42:400::485, nxt 17, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2a04:4e42:400::485, nxt 17, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2a04:4e42:400::485, nxt 17, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2a04:4e42:400::485, nxt 17, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2a04:4e42:400::485, nxt 17, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2a04:4e42:400::485, nxt 17, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2a04:4e42:400::485, nxt 17, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2606:50c0:8001::154, nxt 6, rcvif ax1, outif pppoe0
<7>cannot forward src fe80:6::e486:95ff:fe5b:1003, dst 2606:50c0:8003::154, nxt 6, rcvif ax1, outif pppoe0
Fatal trap 12: page fault while in kernel mode
cpuid = 0; apic id = 00
fault virtual address = 0xfffff809e2afe000
fault code = supervisor read data, page not present
instruction pointer = 0x20:0xffffffff810baf61
stack pointer = 0x28:0xfffffe001d772cd0
frame pointer = 0x28:0xfffffe001d772d00
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 0 (if_io_tqg_0)
rdi: 000000082c140000 rsi: 0000000000000001 rdx: 0000000000000011
rcx: 000000002b95d7ff r8: 000000002b95e000 r9: fffffe001d773000
rax: fffff801b69be000 rbx: fffffe00d9baa000 rbp: fffffe001d772d00
r10: 0000000000000000 r11: 0000000000000000 r12: 0000000000000010
r13: fffff80004007800 r14: 0000000000000000 r15: 0000000000000000
trap number = 12
panic: page fault
cpuid = 0
time = 1736267408
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x2b/frame 0xfffffe001d7729c0
vpanic() at vpanic+0x131/frame 0xfffffe001d772af0
panic() at panic+0x43/frame 0xfffffe001d772b50
trap_fatal() at trap_fatal+0x40b/frame 0xfffffe001d772bb0
trap_pfault() at trap_pfault+0x46/frame 0xfffffe001d772c00
calltrap() at calltrap+0x8/frame 0xfffffe001d772c00
--- trap 0xc, rip = 0xffffffff810baf61, rsp = 0xfffffe001d772cd0, rbp = 0xfffffe001d772d00 ---
axgbe_isc_rxd_available() at axgbe_isc_rxd_available+0xc1/frame 0xfffffe001d772d00
iflib_rxeof() at iflib_rxeof+0xc5/frame 0xfffffe001d772e00
_task_fn_rx() at _task_fn_rx+0x72/frame 0xfffffe001d772e40
gtaskqueue_run_locked() at gtaskqueue_run_locked+0x14e/frame 0xfffffe001d772ec0
gtaskqueue_thread_loop() at gtaskqueue_thread_loop+0xc2/frame 0xfffffe001d772ef0
fork_exit() at fork_exit+0x7f/frame 0xfffffe001d772f30
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe001d772f30
--- trap 0xe9939ae2, rip = 0x61d4934a6d94934e, rsp = 0xc6e30806caa30802, rbp = 0x7adc2428769c242c ---
KDB: enter: panic
Quote from: opnsenseuser1 on August 02, 2024, 05:43:12 PM**** Interface statistics was better in the old version with all details rather than the current PIE chart.****
Can we have it configurable ? with choose PIE chart or details like in old version ????