Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - computeralex92

#16
23.1 Legacy Series / dhcpd running amok
March 18, 2023, 03:42:59 PM
Hello,

since a while sometimes my Opnsense firewall gets unresponsive and the only way to "fix" this is to make a hard reboot via powercycle.
The last time this happens I was by luck present (normally this happen e.g. over night etc).
I checked everything and the firewall had 100% CPU usage and used over 6,5 GB memory.
Reason for this where over 400(!) processes with this command:
/usr/local/sbin/dhcpd -6 -user dhcpd -group dhcpd -chroot /var/dhcpd -cf /etc/dhcpdv6.conf -pf /var/run/dhcpdv6.pid igb0

igb0 is my LAN interface btw.

Config content is:

option dhcp6.domain-search "localdomain";
option dhcp6.rapid-commit;

default-lease-time 7200;
max-lease-time 86400;
log-facility local7;
one-lease-per-client true;
deny duplicates;
ping-check true;
update-conflict-detection false;
authoritative;

subnet6 IPv6_SUBNET::/64 {
  range6 IPv6_SUBNET::1000 IPv6_SUBNET::2000;
  option dhcp6.name-servers IPv6_SUBNET:227c:14ff:fea0:644e;
  prefix6 2003:ef:bf20:c080:: 2003:ef:bf20:c0f0::/62;
}

ddns-update-style none;


Did someone also experience this issue?

Thanks,
Alex
#17
From which version do you try to update to 23.1?
#18
Hello Max & Franco,

thanks a lot to look deeper into this topic.
I can confirm that the patch from Franco is fixing the issue for me; my IPv6 is back.

@Franco: If you need further details or a guinea pig for future tests in this topic, feel free to ping me.

For now, I will close this topic.
Thanks again for your help.

Alex
#19
Hello Franco,

thank you for your reply.
For me the line looks good, it is "only" the gateway assignment for the PPPoE interface.
My setup is a "little" complex, but I try to explain it shotly:

2x WAN Connection
1x PPPoE (Telekom VDSL via Draytek Vigor165)
1x DHCP (Vodafone Cable via Vodafone Gigastation in Bridge-Mode)

The Vodafone have an additional IP configured to have access to the webinterface of the Gigastation.
The network interface for the PPPoE connection is configured with a static IP to be able to connect to the Draytek modem.

I disabled both the Vodafone and Telekom Static interface + the complete gateway monitoring, without any change.
Here is the interface config via ifconfig:

igb0: flags=8863<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
        description: LAN (lan)
        options=4e0272b<RXCSUM,TXCSUM,VLAN_MTU,JUMBO_MTU,TSO4,TSO6,LRO,WOL_MAGIC,RXCSUM_IPV6,TXCSUM_IPV6,NOMAP>
        ether 20:7c:14:a0:64:4e
        inet 10.0.0.1 netmask 0xffffff00 broadcast 10.0.0.255
        media: Ethernet autoselect (1000baseT <full-duplex>)
        status: active
        nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
igb1: flags=8822<BROADCAST,SIMPLEX,MULTICAST> metric 0 mtu 1500
        options=4e0272b<RXCSUM,TXCSUM,VLAN_MTU,JUMBO_MTU,TSO4,TSO6,LRO,WOL_MAGIC,RXCSUM_IPV6,TXCSUM_IPV6,NOMAP>
        ether 20:7c:14:a0:64:4f
        media: Ethernet autoselect
        status: no carrier
        nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
igb2: flags=8863<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
        description: Vodafone (opt1)
        options=4e0272b<RXCSUM,TXCSUM,VLAN_MTU,JUMBO_MTU,TSO4,TSO6,LRO,WOL_MAGIC,RXCSUM_IPV6,TXCSUM_IPV6,NOMAP>
        ether 20:7c:14:a0:64:50
        inet 192.168.100.2 netmask 0xffffff00 broadcast 192.168.100.255
        media: Ethernet autoselect (1000baseT <full-duplex>)
        status: active
        nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
igb3: flags=8863<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
        description: TelekomStatic (opt3)
        options=4e0272b<RXCSUM,TXCSUM,VLAN_MTU,JUMBO_MTU,TSO4,TSO6,LRO,WOL_MAGIC,RXCSUM_IPV6,TXCSUM_IPV6,NOMAP>
        ether 20:7c:14:a0:64:51
        media: Ethernet autoselect (1000baseT <full-duplex>)
        status: active
        nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
enc0: flags=0<> metric 0 mtu 1536
        groups: enc
        nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384
        options=680003<RXCSUM,TXCSUM,LINKSTATE,RXCSUM_IPV6,TXCSUM_IPV6>
        inet6 ::1 prefixlen 128
        inet6 fe80::1%lo0 prefixlen 64 scopeid 0x6
        inet 127.0.0.1 netmask 0xff000000
        groups: lo
        nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
pflog0: flags=20100<PROMISC,PPROMISC> metric 0 mtu 33160
        groups: pflog
pfsync0: flags=0<> metric 0 mtu 1500
        syncpeer: 0.0.0.0 maxupd: 128 defer: off
        syncok: 1
        groups: pfsync
pppoe0: flags=88d1<UP,POINTOPOINT,RUNNING,NOARP,SIMPLEX,MULTICAST> metric 0 mtu 1492
        description: Telekom (opt2)
        inet6 fe80::227c:14ff:fea0:644e%pppoe0 prefixlen 64 scopeid 0x9
        inet 91.9.130.251 --> 62.155.242.170 netmask 0xffffffff
        nd6 options=23<PERFORMNUD,ACCEPT_RTADV,AUTO_LINKLOCAL>


I will search further today after work; maybe I see something strange in the logs or configs.

Thanks,

Alex
#20
OK, I just saved and applied a little change in the interface config, and now the apply runs for forever.
When checking the system.log, I found this:


<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="35"] /usr/local/etc/rc.newwanip: IP renwal starting (new: 79.234.201.75, old: , interface: Telekom[opt2], device: pppoe0)
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain dhcp6c 17706 - [meta sequenceId="36"] RTSOLD script - Sending SIGHUP to dhcp6c
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="37"] /usr/local/etc/rc.newwanip: ROUTING: entering configure using 'opt2'
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="38"] /usr/local/etc/rc.newwanip: ROUTING: IPv4 default gateway set to opt2
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="39"] /usr/local/etc/rc.newwanip: ROUTING: setting IPv4 default route to 62.155.242.170
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="40"] /usr/local/etc/rc.newwanip: ROUTING: treating '62.155.242.170' as far gateway for '79.234.201.75/32'
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="41"] /usr/local/etc/rc.newwanip: ROUTING: keeping current default gateway '62.155.242.170'
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="42"] /usr/local/etc/rc.newwanip: ROUTING: IPv6 default gateway set to opt2
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="43"] /usr/local/etc/rc.newwanip: ROUTING: skipping IPv6 default route
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="44"] /usr/local/etc/rc.newwanip: plugins_configure monitor (,TELEKOM_DHCP6)
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="45"] /usr/local/etc/rc.newwanip: plugins_configure monitor (execute task : dpinger_configure_do(,TELEKOM_DHCP6))
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="46"] /usr/local/etc/rc.newwanip: Gateway currently empty for 2001:4860:4860::8888 on opt2
<12>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="47"] /usr/local/etc/rc.newwanip: The required TELEKOM_DHCP6 IPv6 interface address could not be found, skipping.
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="48"] /usr/local/etc/rc.newwanip: plugins_configure monitor (,TELEKOM_PPPOE)
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="49"] /usr/local/etc/rc.newwanip: plugins_configure monitor (execute task : dpinger_configure_do(,TELEKOM_PPPOE))
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="50"] /usr/local/etc/rc.newwanip: Gateway currently empty for 2001:4860:4860::8888 on opt2
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="51"] /usr/local/etc/rc.newwanip: Chose to bind TELEKOM_PPPOE on 79.234.201.75 since we could not find a proper match.
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="52"] /usr/local/etc/rc.newwanip: plugins_run return_gateways_status ()
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="53"] /usr/local/etc/rc.newwanip: plugins_run return_gateways_status (execute task : dpinger_status())
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="54"] /usr/local/etc/rc.newwanip: plugins_run return_gateways_status ()
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="55"] /usr/local/etc/rc.newwanip: plugins_run return_gateways_status (execute task : dpinger_status())
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="56"] /usr/local/etc/rc.newwanip: Ignore down inet gateways : TELEKOM_DHCP6
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="57"] /usr/local/etc/rc.newwanip: ROUTING: treating '62.155.242.170' as far gateway for '79.234.201.75/32'
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="58"] /usr/local/etc/rc.newwanip: ROUTING: keeping current default gateway '62.155.242.170'
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="59"] /usr/local/etc/rc.newwanip: Ignore down inet6 gateways : TELEKOM_DHCP6
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 46601 - [meta sequenceId="60"] /interfaces.php: ROUTING: entering configure using defaults
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 46601 - [meta sequenceId="61"] /interfaces.php: ROUTING: IPv4 default gateway set to opt2
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 46601 - [meta sequenceId="62"] /interfaces.php: ROUTING: setting IPv4 default route to 62.155.242.170
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 46601 - [meta sequenceId="63"] /interfaces.php: ROUTING: treating '62.155.242.170' as far gateway for '79.234.201.75/32'
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 46601 - [meta sequenceId="64"] /interfaces.php: ROUTING: keeping current default gateway '62.155.242.170'
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 46601 - [meta sequenceId="65"] /interfaces.php: ROUTING: IPv6 default gateway set to opt2
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 46601 - [meta sequenceId="66"] /interfaces.php: ROUTING: skipping IPv6 default route
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 46601 - [meta sequenceId="67"] /interfaces.php: plugins_configure monitor (,)
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 46601 - [meta sequenceId="68"] /interfaces.php: plugins_configure monitor (execute task : dpinger_configure_do(,))
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 46601 - [meta sequenceId="69"] /interfaces.php: Gateway currently empty for 2001:4860:4860::8888 on opt2
<12>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 46601 - [meta sequenceId="70"] /interfaces.php: The required TELEKOM_DHCP6 IPv6 interface address could not be found, skipping.
<13>1 2023-01-18T22:20:32+01:00 OPNsense.localdomain opnsense 46601 - [meta sequenceId="71"] /interfaces.php: Chose to bind TELEKOM_PPPOE on 79.234.201.75 since we could not find a proper match.
<27>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain dhcp6c 13927 - [meta sequenceId="72"] transmit failed: Can't assign requested address
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="73"] /usr/local/etc/rc.newwanip: plugins_configure vpn (,opt2)
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="74"] /usr/local/etc/rc.newwanip: plugins_configure vpn (execute task : ipsec_configure_do(,opt2))
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="75"] /usr/local/etc/rc.newwanip: plugins_configure vpn (execute task : openvpn_configure_do(,opt2))
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="76"] /usr/local/etc/rc.newwanip: Resyncing OpenVPN instances for interface Telekom.
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="77"] /usr/local/etc/rc.newwanip: plugins_configure newwanip (,opt2)
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="78"] /usr/local/etc/rc.newwanip: plugins_configure newwanip (execute task : dnsmasq_configure_do())
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="79"] /usr/local/etc/rc.newwanip: plugins_configure newwanip (execute task : ntpd_configure_do())
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 54696 - [meta sequenceId="80"] /usr/local/etc/rc.filter_configure: plugins_run return_gateways_status ()
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 54696 - [meta sequenceId="81"] /usr/local/etc/rc.filter_configure: plugins_run return_gateways_status (execute task : dpinger_status())
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 54696 - [meta sequenceId="82"] /usr/local/etc/rc.filter_configure: plugins_run return_gateways_status ()
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 54696 - [meta sequenceId="83"] /usr/local/etc/rc.filter_configure: plugins_run return_gateways_status (execute task : dpinger_status())
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 54696 - [meta sequenceId="84"] /usr/local/etc/rc.filter_configure: Ignore down inet gateways : TELEKOM_DHCP6
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 54696 - [meta sequenceId="85"] /usr/local/etc/rc.filter_configure: ROUTING: treating '62.155.242.170' as far gateway for '79.234.201.75/32'
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 54696 - [meta sequenceId="86"] /usr/local/etc/rc.filter_configure: ROUTING: keeping current default gateway '62.155.242.170'
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 54696 - [meta sequenceId="87"] /usr/local/etc/rc.filter_configure: Ignore down inet6 gateways : TELEKOM_DHCP6
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 19564 - [meta sequenceId="88"] /usr/local/etc/rc.newwanip: plugins_configure newwanip (execute task : opendns_configure_do())
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 19564 - [meta sequenceId="89"] /usr/local/etc/rc.newwanip: plugins_configure newwanip (execute task : openssh_configure_do(,opt2))
<13>1 2023-01-18T22:20:33+01:00 OPNsense.localdomain opnsense 19564 - [meta sequenceId="90"] /usr/local/etc/rc.newwanip: plugins_configure newwanip (execute task : unbound_configure_do(,opt2))
<27>1 2023-01-18T22:20:34+01:00 OPNsense.localdomain dhcp6c 13927 - [meta sequenceId="91"] transmit failed: Network is down
<13>1 2023-01-18T22:20:34+01:00 OPNsense.localdomain opnsense 19564 - [meta sequenceId="92"] /usr/local/etc/rc.newwanip: plugins_configure newwanip (execute task : vxlan_configure_do())
<13>1 2023-01-18T22:20:34+01:00 OPNsense.localdomain opnsense 19564 - [meta sequenceId="93"] /usr/local/etc/rc.newwanip: plugins_configure newwanip (execute task : webgui_configure_do(,opt2))
<13>1 2023-01-18T22:20:34+01:00 OPNsense.localdomain opnsense 46601 - [meta sequenceId="94"] /interfaces.php: plugins_configure newwanip (,opt2)
<13>1 2023-01-18T22:20:34+01:00 OPNsense.localdomain opnsense 46601 - [meta sequenceId="95"] /interfaces.php: plugins_configure newwanip (execute task : dnsmasq_configure_do())
<13>1 2023-01-18T22:20:34+01:00 OPNsense.localdomain opnsense 46601 - [meta sequenceId="96"] /interfaces.php: plugins_configure newwanip (execute task : ntpd_configure_do())
<27>1 2023-01-18T22:20:36+01:00 OPNsense.localdomain dhcp6c 13927 - [meta sequenceId="97"] transmit failed: Network is down
<13>1 2023-01-18T22:20:39+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="98"] /usr/local/etc/rc.newwanip: plugins_configure newwanip (execute task : opendns_configure_do())
<13>1 2023-01-18T22:20:39+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="99"] /usr/local/etc/rc.newwanip: plugins_configure newwanip (execute task : openssh_configure_do(,opt2))
<13>1 2023-01-18T22:20:39+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="100"] /usr/local/etc/rc.newwanip: plugins_configure newwanip (execute task : unbound_configure_do(,opt2))
<13>1 2023-01-18T22:20:39+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="101"] /usr/local/etc/rc.newwanip: plugins_configure newwanip (execute task : vxlan_configure_do())
<13>1 2023-01-18T22:20:39+01:00 OPNsense.localdomain opnsense 95887 - [meta sequenceId="102"] /usr/local/etc/rc.newwanip: plugins_configure newwanip (execute task : webgui_configure_do(,opt2))
<27>1 2023-01-18T22:20:40+01:00 OPNsense.localdomain dhcp6c 13927 - [meta sequenceId="103"] transmit failed: Network is down
<27>1 2023-01-18T22:20:48+01:00 OPNsense.localdomain dhcp6c 13927 - [meta sequenceId="104"] transmit failed: Network is down
<27>1 2023-01-18T22:21:02+01:00 OPNsense.localdomain dhcp6c 13927 - [meta sequenceId="105"] transmit failed: Network is down
<27>1 2023-01-18T22:21:31+01:00 OPNsense.localdomain dhcp6c 13927 - [meta sequenceId="106"] transmit failed: Network is down
<27>1 2023-01-18T22:22:28+01:00 OPNsense.localdomain dhcp6c 13927 - [meta sequenceId="107"] transmit failed: Network is down
<13>1 2023-01-18T22:22:50+01:00 OPNsense.localdomain opnsense 83565 - [meta sequenceId="108"] /usr/local/opnsense/scripts/routes/gateway_status.php: plugins_run return_gateways_status ()
<13>1 2023-01-18T22:22:50+01:00 OPNsense.localdomain opnsense 83565 - [meta sequenceId="109"] /usr/local/opnsense/scripts/routes/gateway_status.php: plugins_run return_gateways_status (execute task : dpinger_status())
<13>1 2023-01-18T22:22:55+01:00 OPNsense.localdomain opnsense 38992 - [meta sequenceId="110"] /usr/local/opnsense/scripts/routes/gateway_status.php: plugins_run return_gateways_status ()
<13>1 2023-01-18T22:22:55+01:00 OPNsense.localdomain opnsense 38992 - [meta sequenceId="111"] /usr/local/opnsense/scripts/routes/gateway_status.php: plugins_run return_gateways_status (execute task : dpinger_status())
<27>1 2023-01-18T22:24:21+01:00 OPNsense.localdomain dhcp6c 13927 - [meta sequenceId="1"] transmit failed: Network is down
<27>1 2023-01-18T22:26:25+01:00 OPNsense.localdomain dhcp6c 13927 - [meta sequenceId="1"] transmit failed: Network is down


I think this lines are interesting:

dhcp6c 13927 - [meta sequenceId="72"] transmit failed: Can't assign requested address
dhcp6c 13927 - [meta sequenceId="91"] transmit failed: Network is down

For me it seems that something is blocking dhcp6c to run currectly or assign the IPv6-address it gets from Telekom.
#21
Which log-files are the most useful?

#22
Hello Franco,

my settings were on 22.7 as follow:
WAN:
IPv4: PPPoE
IPv6: DHCPv6
For IPv6 was a /56 Prefix delegation size and a request via the IPv4 connection configured.

LAN:
IPv4: Static IP
IPv6: Track interface

This configuration is also not working anymore on 23.1; DHCPv6 server is not starting and the interface is not getting any IPv6 address from the PPPoE connection.
Also the ifconfig shows the same /64 prefixlen as with PPPoEv6 configuration.

Thanks,
Alex
#23
Hello,

after updating to 23.1.r1 the IPv6 setup with Telekom Deutschland is not working anymore.
I saw there a issue on Github https://github.com/opnsense/core/issues/6245 regarding the change to the new interface type 'PPPoEv6', but this change is not working for me.
When checking the interfaces for any hint, I saw this here:

inet6 fe80::227c:14ff:fea0:644e%pppoe0 prefixlen 64 scopeid 0x9

The prefix lenght is configured to 64, but for Telekom you normally need to request a /56 subnet.
As there is no configuration for this anymore (or I didn't found it), I think that cause the issue.

Thanks,
Alex
#24
Hello everyone,

I noticed in the last months some issues regarding my Opnsense mirror dns-root.de which is routed and cached via Cloudflare.
Error's like Package checksum mismatch or missing packages which are stored on the disk but not cached by Cloudflare.  :'(
Unfortunatly out of personal reasons I was not able to deep dive into this problems in the last year, but now I want finally fix this issues and provide you a stable mirror.

My setup:

  • Nginx docker container as webserver

  • Rsync container triggered by a systemd timer
  • Cloudflare to cache everything except defined files



The Cloudflare config is configured to

  • Bypass changelog.txz, bogons.txz, meta.txz & packagesite.tgz
  • Cache everything in the /releases folder for one month (installation iso's, so fine)
  • Cache everything else for one month; but do not force this



From nginx side there are additional rules:

  • Add "no-cache" header to changelog.txz, bogons.txz, meta.txz & packagesite.tgz
  • Everything else cache 30 days
So basically both sides are configured nearly the same; only the iso's are forced to be cached for one month (which make sense because they are static).

My theory why the checksum error is happening is the following:

If a package is updated without a version change in the filename, the new checksum is part of the uncached system files, but as the file changed, the error appears.
When looking through the mirror folder I saw that the folder "Latest" in the package structure contains unversioned pkg-Files, only the "All"-folder contains all versioned pkg-files.

My ideas to solve this until now:

  • Delete the Cloudflare cache when there are files changed by rsync (not so easy to implement with rsync)
  • Not caching the "Latest"-folder (less caching rate, more traffic for server...)

Maybe some of you have a idea to solve this on a different way, or I'm missing something out of missing FreeBSD packaging knowledge  ;)

Thanks a lot,
Alex



PS.
Thanks for 2 TB traffic per month; it is great to support you and the great project on this way  :)
#25
German - Deutsch / Re: Anfängerproblem
February 17, 2022, 08:35:04 AM
Guten Morgen,

hilfreich wären jetzt deine WAN und LAN Einstellungen der Firewall; am besten per Screenshot etc.
Anfürsich sollte das mit den richtigen Einstellungen sofort funktionieren.

VG;

Alex

#26
Quote from: franco on February 15, 2022, 10:40:17 AM
Not a fix unfortunately. Will take a closer look. Might need your help reproducing.

Sure, just reach out to me if I can help somewhere.
#27
Hello Franco,

I was able to test it yesterday; after the change of the tunable, everything is working without any issue.

Thanks for the quick fix,
Alex
#28
Hello Franco,

thanks for your reply.
Ah, failures happen, when checking the changelog for 22.1 (and all versions before) I'm very glad to see how smoothly everything is working.

I set the tunable and will test it asap; but this can take until tomorrow afternoon.
I keep you updated.

Alex

#29
Hello,

I use for helping my parents etc. the VNC Viewer von Realvnc which connects via Realvnc to a VNC server on their computers.
After updating to 22.1, I can crash the Opnsense when trying to connect to one of their computers.

Here part of the crash-log:

Fatal trap 12: page fault while in kernel mode
cpuid = 2; apic id = 02
fault virtual address = 0x10
fault code = supervisor read data, page not present
instruction pointer = 0x20:0xffffffff80eb0dfd
stack pointer         = 0x28:0xfffffe000e1c06c0
frame pointer         = 0x28:0xfffffe000e1c07e0
code segment = base 0x0, limit 0xfffff, type 0x1b
= DPL 0, pres 1, long 1, def32 0, gran 1
processor eflags = interrupt enabled, resume, IOPL = 0
current process = 0 (if_io_tqg_2)
trap number = 12
panic: page fault
cpuid = 2
time = 1644757931
KDB: stack backtrace:
db_trace_self_wrapper() at db_trace_self_wrapper+0x2b/frame 0xfffffe000e1c0480
vpanic() at vpanic+0x17f/frame 0xfffffe000e1c04d0
panic() at panic+0x43/frame 0xfffffe000e1c0530
trap_fatal() at trap_fatal+0x385/frame 0xfffffe000e1c0590
trap_pfault() at trap_pfault+0x4f/frame 0xfffffe000e1c05f0
calltrap() at calltrap+0x8/frame 0xfffffe000e1c05f0
--- trap 0xc, rip = 0xffffffff80eb0dfd, rsp = 0xfffffe000e1c06c0, rbp = 0xfffffe000e1c07e0 ---
ip6_forward() at ip6_forward+0x62d/frame 0xfffffe000e1c07e0
pf_refragment6() at pf_refragment6+0x164/frame 0xfffffe000e1c0830
pf_test6() at pf_test6+0xfdb/frame 0xfffffe000e1c09a0
pf_check6_out() at pf_check6_out+0x40/frame 0xfffffe000e1c09d0
pfil_run_hooks() at pfil_run_hooks+0x97/frame 0xfffffe000e1c0a10
ip6_tryforward() at ip6_tryforward+0x2ce/frame 0xfffffe000e1c0a90
ip6_input() at ip6_input+0x60f/frame 0xfffffe000e1c0b70
netisr_dispatch_src() at netisr_dispatch_src+0xb9/frame 0xfffffe000e1c0bc0
ether_demux() at ether_demux+0x138/frame 0xfffffe000e1c0bf0
ether_nh_input() at ether_nh_input+0x355/frame 0xfffffe000e1c0c50
netisr_dispatch_src() at netisr_dispatch_src+0xb9/frame 0xfffffe000e1c0ca0
ether_input() at ether_input+0x69/frame 0xfffffe000e1c0d00
iflib_rxeof() at iflib_rxeof+0xc27/frame 0xfffffe000e1c0e00
_task_fn_rx() at _task_fn_rx+0x72/frame 0xfffffe000e1c0e40
gtaskqueue_run_locked() at gtaskqueue_run_locked+0x15d/frame 0xfffffe000e1c0ec0
gtaskqueue_thread_loop() at gtaskqueue_thread_loop+0xc2/frame 0xfffffe000e1c0ef0
fork_exit() at fork_exit+0x7e/frame 0xfffffe000e1c0f30
fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe000e1c0f30
--- trap 0x80388000, rip = 0xffffffff80c2bcff, rsp = 0, rbp = 0x6 ---
mi_startup() at mi_startup+0xdf/frame 0x6
KDB: enter: panic
panic.txt0600001214202201653  7124 ustarrootwheelpage faultversion.txt0600007014202201653  7523 ustarrootwheelFreeBSD 13.0-STABLE stable/22.1-n248053-232cb14f501 SMP


I reported all three crashes via the reporting tool.
What can be the source of this crashes?

Thanks,

Alex
#30
22.1 Legacy Series / Bad pkg performance while updating
January 20, 2022, 08:29:44 PM
Hello,

when updating via pkg from 21.7 to 22.1.r1 and now from 22.1.r1 to 22.1.r2 I had a very bad speed performance.
This happens, when pkg is try to fetch the base- and kernel txz; based on the Traffic overview in the web-gui, it runs with about 500 kbps.
Switching the mirror didn't help; a test download of such an archive was working in the expected speed.

Did someone of you had the same experience?

Thanks,

Alex