opnsense-revert -r 20.7.3 suricata
Maybe disable all rules, perhaps your ram blows away
You have to look in the difference between legacy and inline mode to find the culprit.
2020-11-02T12:23:08 opnsense[20113] /usr/local/etc/rc.linkup: DEVD Ethernet detached event for wan
Look at the console for the error why it freezes
...466.167540 [1742] nm_rxsync_prologue em0 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 0 c 0 t 1022 rh 0 rc 0 rt 1022 hc 1021 ht 1022466.181403 [1787] netmap_ring_reinit called for em0 RX1472.463680 [1742] nm_rxsync_prologue em0 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 31 c 31 t 21 rh 31 rc 31 rt 21 hc 20 ht 21472.477197 [1787] netmap_ring_reinit called for em0 RX1473.254040 [1742] nm_rxsync_prologue igb2 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 714 c 714 t 713 rh 714 rc 714 rt 713 hc 711 ht 713473.268350 [1787] netmap_ring_reinit called for igb2 RX1475.718351 [1742] nm_rxsync_prologue igb2 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 725 c 725 t 723 rh 725 rc 725 rt 723 hc 721 ht 723475.732652 [1787] netmap_ring_reinit called for igb2 RX1475.740008 [1742] nm_rxsync_prologue igb2 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 724 c 724 t 723 rh 724 rc 724 rt 723 hc 566 ht 723475.754306 [1787] netmap_ring_reinit called for igb2 RX1483.402555 [1742] nm_rxsync_prologue igb0 RX2: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 26 c 26 t 22 rh 26 rc 26 rt 22 hc 21 ht 22483.416156 [1787] netmap_ring_reinit called for igb0 RX2489.248676 [1742] nm_rxsync_prologue em0 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 106 c 106 t 100 rh 106 rc 106 rt 100 hc 99 ht 100489.262805 [1787] netmap_ring_reinit called for em0 RX1492.266657 [1742] nm_rxsync_prologue em0 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 114 c 114 t 108 rh 114 rc 114 rt 108 hc 107 ht 108492.280870 [1787] netmap_ring_reinit called for em0 RX1492.324378 [1742] nm_rxsync_prologue igb2 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 752 c 752 t 747 rh 752 rc 752 rt 747 hc 744 ht 747492.338674 [1787] netmap_ring_reinit called for igb2 RX1496.058933 [1742] nm_rxsync_prologue em0 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 142 c 142 t 127 rh 142 rc 142 rt 127 hc 126 ht 127496.073143 [1787] netmap_ring_reinit called for em0 RX1502.387235 [1742] nm_rxsync_prologue em0 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 144 c 144 t 142 rh 144 rc 144 rt 142 hc 141 ht 142502.401452 [1787] netmap_ring_reinit called for em0 RX1504.390558 [1742] nm_rxsync_prologue em0 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 147 c 147 t 145 rh 147 rc 147 rt 145 hc 144 ht 145504.404775 [1787] netmap_ring_reinit called for em0 RX1
Quote from: mimugmail on November 02, 2020, 09:21:32 amLook at the console for the error why it freezesNormally there is no error message in the serial console when the WAN goes down, but some minutes ago I had in the console while WAN down (on the second machine, starting this morning, with 20.7.3 installed):Code: [Select]...466.167540 [1742] nm_rxsync_prologue em0 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 0 c 0 t 1022 rh 0 rc 0 rt 1022 hc 1021 ht 1022466.181403 [1787] netmap_ring_reinit called for em0 RX1472.463680 [1742] nm_rxsync_prologue em0 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 31 c 31 t 21 rh 31 rc 31 rt 21 hc 20 ht 21472.477197 [1787] netmap_ring_reinit called for em0 RX1473.254040 [1742] nm_rxsync_prologue igb2 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 714 c 714 t 713 rh 714 rc 714 rt 713 hc 711 ht 713473.268350 [1787] netmap_ring_reinit called for igb2 RX1475.718351 [1742] nm_rxsync_prologue igb2 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 725 c 725 t 723 rh 725 rc 725 rt 723 hc 721 ht 723475.732652 [1787] netmap_ring_reinit called for igb2 RX1475.740008 [1742] nm_rxsync_prologue igb2 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 724 c 724 t 723 rh 724 rc 724 rt 723 hc 566 ht 723475.754306 [1787] netmap_ring_reinit called for igb2 RX1483.402555 [1742] nm_rxsync_prologue igb0 RX2: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 26 c 26 t 22 rh 26 rc 26 rt 22 hc 21 ht 22483.416156 [1787] netmap_ring_reinit called for igb0 RX2489.248676 [1742] nm_rxsync_prologue em0 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 106 c 106 t 100 rh 106 rc 106 rt 100 hc 99 ht 100489.262805 [1787] netmap_ring_reinit called for em0 RX1492.266657 [1742] nm_rxsync_prologue em0 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 114 c 114 t 108 rh 114 rc 114 rt 108 hc 107 ht 108492.280870 [1787] netmap_ring_reinit called for em0 RX1492.324378 [1742] nm_rxsync_prologue igb2 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 752 c 752 t 747 rh 752 rc 752 rt 747 hc 744 ht 747492.338674 [1787] netmap_ring_reinit called for igb2 RX1496.058933 [1742] nm_rxsync_prologue em0 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 142 c 142 t 127 rh 142 rc 142 rt 127 hc 126 ht 127496.073143 [1787] netmap_ring_reinit called for em0 RX1502.387235 [1742] nm_rxsync_prologue em0 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 144 c 144 t 142 rh 144 rc 144 rt 142 hc 141 ht 142502.401452 [1787] netmap_ring_reinit called for em0 RX1504.390558 [1742] nm_rxsync_prologue em0 RX1: fail 'head < kring->nr_hwcur || head > kring->nr_hwtail' h 147 c 147 t 145 rh 147 rc 147 rt 145 hc 144 ht 145504.404775 [1787] netmap_ring_reinit called for em0 RX1But I could not catch all the output.
Quote from: chemlud on November 02, 2020, 01:15:21 pm...Thats a netmap related error and enough of them will crash the machine.Legacy mode doesnt use netmap.
...Thats a netmap related error and enough of them will crash the machine.Legacy mode doesnt use netmap.
I updated the second box to 20.7.4, same game, whenever I enable IPS, the WAN is dead within 1-2 minutes. No idea what to try next...
Quote from: chemlud on November 02, 2020, 10:57:27 pmI updated the second box to 20.7.4, same game, whenever I enable IPS, the WAN is dead within 1-2 minutes. No idea what to try next...And it was 20.7.3 before?
I get here:Code: [Select]# opnsense-update -kr 20.7.3 Fetching kernel-20.7.3-amd64.txz: ...... done !!!!!!!!!!!! ATTENTION !!!!!!!!!!!!!!! ! A critical upgrade is in progress. ! ! Please do not turn off the system. ! !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! Installing kernel-20.7.3-amd64.txz... done Please reboot. After reboot I enabled suricata, but it took only about one minute to kill the WAN again. And then I saw that kernel is still 20.7.4?!? I disabled again suricata for the moment, any ideas what went wrong? opnsense-revert instead of opnsense-update, maybe?
# opnsense-update -kr 20.7.3 Fetching kernel-20.7.3-amd64.txz: ...... done !!!!!!!!!!!! ATTENTION !!!!!!!!!!!!!!! ! A critical upgrade is in progress. ! ! Please do not turn off the system. ! !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! Installing kernel-20.7.3-amd64.txz... done Please reboot.