Project

General

Profile

Actions

Bug #16148

closed

OpenVPN socket listen queue overflow in pfSense 2.7.2

Added by reza karimi 20 days ago. Updated 18 days ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
OpenVPN
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
2.7.2
Affected Architecture:
arm64

Description

We have been running pfSense CE for several years with multiple OpenVPN server instances (5+), and everything worked flawlessly until recently. After upgrading to version 2.7.2-RELEASE, we started encountering recurring Listen queue overflow kernel messages related to OpenVPN Unix sockets.

Relevant kernel log entries:
sonewconn: pcb 0xfffff80051466600 (local:/var/etc/openvpn/server2/sock): Listen queue overflow: 2 already in queue awaiting acceptance
sonewconn: pcb 0xfffff8001000be00 (local:/var/etc/openvpn/server8/sock): Listen queue overflow: 2 already in queue awaiting acceptance

We attempted the following mitigation:

Set kern.ipc.soacceptqueue=1024 via System > Advanced > System Tunables

Also added the same setting to /boot/loader.conf.local and rebooted

However, the issue persists.

System specs:

10 CPU cores

16 GB RAM

Resource usage is not maxed out

vmstat -z shows no mbuf depletion

We also noticed that the pfSense WebGUI has become significantly slower to load around the same time this started happening, possibly related.

Please advise if this is a known issue and whether a fix is included in the upcoming 2.8 release. Let us know if you need additional logs, diagnostic outputs, or test feedback.

Thanks in advance.

Actions

Also available in: Atom PDF