System Crash after enabling Intrusion Prevention System

Started by mattiarainieri, September 25, 2023, 03:17:36 PM

Previous topic - Next topic
Hi everyone,
I'm trying to investigate about a curious problem that make my system crash every times that i enable the IPS. There is no still problem using IDS. The computer has two network cards: the 1Gbit motherboard one, and a 2 x 2.5Gbit Realtek installed on a pci slot. Enabling the IPS when only the motherboard one is installed works fine; when i install the Realtek, after a couple of second, it crash and the computer restarts.

The system reports the attached message.


I've tried to copy your configuration, but the error persists. I've also tried to install the driver through "pkg install realtek-re-kmod" but this create also another problem.
This installation method require to add some lines in /boot/loader.conf file, witch are ofter overwritten.

I've read that os-realtek-re packet is still not needed, but without it Opnsense does not recognise the network card
???

Quote from: mattiarainieri on September 25, 2023, 09:08:09 PM
I've tried to copy your configuration, but the error persists. I've also tried to install the driver through "pkg install realtek-re-kmod" but this create also another problem.
This installation method require to add some lines in /boot/loader.conf file, witch are ofter overwritten.

And if you look at the first lines of /boot/loader.conf, there are two options to solve that problem:


##############################################################
# This file was auto-generated using the rc.loader facility. #
# In order to deploy a custom change to this installation,   #
# please use /boot/loader.conf.local as it is not rewritten, #
# or better yet use System: Settings: Tunables from the GUI. #
##############################################################

Intel N100, 4 x I226-V, 16 GByte, 256 GByte NVME, ZTE F6005

1100 down / 440 up, Bufferbloat A+

I apologize but in my haste I didn't even read the first line
Now i've configure as follow. I'll ask you if it's right, because the documentation is not so detailed.



Yes, but you need another setting for if_re_load="YES".
Intel N100, 4 x I226-V, 16 GByte, 256 GByte NVME, ZTE F6005

1100 down / 440 up, Bufferbloat A+

Off course, i didn't attach the screenshot because the configuration schema was the same.
But, unfortunately, also with this driver, the problem persists  :-\

Quote from: mattiarainieri on September 26, 2023, 07:50:25 AM
Off course, i didn't attach the screenshot because the configuration schema was the same.
But, unfortunately, also with this driver, the problem persists  :-\
Did you solve it? I have the same issue.

Unfortunately not, the physical machine was changed and there the problem did not recur