Bug #4276
closed
Layer 7 not working / ipfw-classifyd high load
Added by Bartłomiej Bujak almost 10 years ago.
Updated almost 9 years ago.
Affected Architecture:
All
Description
After upgrade pfsense 2.1.5 to 2.2 i have problem with ipfw-classifyd
PID USERNAME THR PRI NICE SIZE RES STATE TIME WCPU COMMAND
76425 root 5 20 0 23584K 7760K nanslp 1:45 63.87% ipfw-classifyd
I remove Traffic Shaper Layer7 rule and now all it's ok . I had only 1 rule.
76425 root 5 20 0 23584K 7788K nanslp 3:21 0.00% ipfw-classifyd
In logs:
dnsmasq[89256]: failed to send packet: No buffer space available
After remove layer7 rule, DNS ( on client) start work correctly
- Project changed from pfSense Packages to pfSense
- Category set to Layer 7
in logs:
ipfw-classifyd: packet dropped: output queue full
- Status changed from New to Confirmed
- Target version set to 2.2.2
Pretty simple to reproduce
- Add a layer 7 container, for example, to block bittorrent
- Apply the layer 7 container on a pass rule on LAN to pass all traffic
- Observe that no traffic passes and ipfw-classifyd is consuming 100% CPU
- Subject changed from ipfw-classifyd high load after upgrade do 2.2 to Layer 7 not working / ipfw-classifyd high load
- Affected Architecture All added
- Affected Architecture deleted (
)
version 2.2.1 still have this bug
- Target version changed from 2.2.2 to 2.2.3
This is missed patch from 8.3 diverttag.diff
Hy folks, any chance to hav a patch for the 2.2.2?
regards
- Target version changed from 2.2.3 to 2.3
- Assignee set to Chris Buechler
- Status changed from Confirmed to Closed
- Target version deleted (
2.3)
- Affected Version changed from 2.2 to 2.2.x
closing in favor of #5508
version 2.2.5 still have this bug
winmasta winmasta wrote:
version 2.2.5 still have this bug
Yes. It's not being fixed. See #5508.
Too bad, i used it without any problems. Is it going to make a similar module ?
Version 2.2.5 still affected
Also available in: Atom
PDF