Occasionally need a restart of the ZenArmor service

Comments

10 comments

  • Official comment
    SVN Support Team

    Hi Bruce,

    It seems a netmap issue. Netmap has a known issue with VLAN interfaces. Do you have VLAN(s) on the protected interface?

    Comment actions Permalink
  • Bruce Tenison

    Yes. The protected networks are vlan networks. It works for a period of time then fails.

    Would emulated work? At least until I can adjust my physical networking to move the vlans to separate interfaces?

    0
    Comment actions Permalink
  • SVN Support Team

    Hi Bruce,

    Please install patched kernel withe the following command, and then try with emulated driver.

    opnsense-update -zkr 23.1.1-netmap2 && opnsense-shell reboot (it will restart after installation)

    More detail for the kernel is in the following forum topic

    https://forum.opnsense.org/index.php?topic=32114.45

    0
    Comment actions Permalink
  • Bruce Tenison

    Thank you!! Will do. I’ll let you know how it goes.

    0
    Comment actions Permalink
  • Bruce Tenison

    Once this is complete and I switch to physical connections for all my VLANS (remove the single physical interface for my vlans) should I switch back to the non emulated driver?

    0
    Comment actions Permalink
  • SVN Support Team

    Hi Bruce,

    Please keep it in the emulated driver.

    0
    Comment actions Permalink
  • Bruce Tenison

    Will do. One more question. I will be switching hardware soon. The current setup is a Dell R710 that I had around (had to replace a failed Protectli). The new one is a bit smaller but has an Intel EXPI9404PTL PRO/1000 PT Quad Port Server Adapter in it. When I provision that box, should I go native, or keep the emulated?

    0
    Comment actions Permalink
  • SVN Support Team

    Hi Bruce,

    The team fixes the issue for emulated driver. So, if you will have VLAN interface(s) on new hardware, keep to use emulated driver.

    0
    Comment actions Permalink
  • Bruce Tenison

    OK.  My plan is to, when I transition to the new hardware, I will be splitting the VLAN interface to untagged (no VLAN tag) interfaces so that this issue will (hopefully) go away.  If that's the case, then can I / should I change back the non-emulated driver?

    Since I am CURRENTLY using tagged VLANs on one interface, I will remain on the emulated driver.

    Is that all correct?

    0
    Comment actions Permalink
  • SVN Support Team

    Hi Bruce,

    Yes, that is correct.

    0
    Comment actions Permalink

Please sign in to leave a comment.

Powered by Zendesk