Help with random reboots

Started by SecAficionado, August 06, 2019, 04:27:21 AM

Previous topic - Next topic
Hi there,

I am experiencing random reboots on my system (19.7.1). Not sure where to start looking for the cause. I don't think they are necessarily CPU panics, but I can't prove it yet. I have no problem with the command line, but I'm still a noob when it comes to Free-BSD. Browsing through the System logs with the web GUI has not given me anything. I can see when the system is starting, but I can't see when or why it went down.

Which file/directory is the best place to start looking? I have two approximate times to look for in the logs that can hopefully tell me how the system went down.

This is my home firewall and I don't really have a need for 24/7 internet, so my firewall goes down every day at night and starts in the morning. I don't think this is a stability issue, unless there are known problems with some CPUs or hardware.

My system is as follows:
OPNsense 19.7.2-amd64 -- Updated on 8/5/2019
FreeBSD 11.2-RELEASE-p12-HBSD
LibreSSL 2.9.2 -- Soon to revert back to OpenSSL
Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz (4 cores)
8GB RAM
450GB HDD
Intel Gig Network cards for LAN and WAN
Plugins:
Suricata with Hyperscan enabled
UnboundDNS with DNSSEC enabled
WebProxy with some ACLs

This system should be overpowered for its load. Even with Suricata running, I never see significant memory usage and have lots of it assigned to Squid, for faster browsing. I don't think I had these problems before 19.7.1, but I can't be sure unless I dig into my log files. I work from home often, though, and I would definitely notice firewall reboots if they happened during office hours. I really think this is a new issue.

Thanks in advance for any help/advice.

Well, turns out that everything is the good old /var/log folder.

There are no kernel panics or any indication that the system is shutting down. I fear this is a hardware issue. HDD tests and Memory tests both passed. I turned on SMART tools and will monitor those for a while for errors.

I read that there were some issues with CPU patches for new vulnerabilities, but my symptoms don't match what I have read so far. I'll keep digging to see if there are any clues anywhere.

Hi,

If logs just silently stop and no crash report it was a power-off issue for sure, maybe hardware or environment. Not much can be done to debug this...


Cheers,
Franco