Repeated change of link status'

Possibly relevant info: I have two machines running FreeBSD systems. One is also running two jails, one is an Apache web server and the other is a Postfix / Dovecot server. The machine without the jails is running Squid Proxy with C-Icap and ClamAV. The squid machine has been up and running with very few issues since September of 2021. The other machine has been running the Apache server since February of 2022 also with no or few issues and the Postfix / Dovecot server since early December of 2022.

Recently I have noticed in /var/log/messages, reports stating, "send_packet: Network is down" as well as "error resolving pool 0.freebsd.pool.ntp.org: Name does not resolve (8)" on the machine running the Squid Proxy. And in dmesg.today on the host running the jails, there are repeated entries for the network interfaces changing states from "Up" to "Down" constantly. Everything up until this point has seemed to function properly for quite some time on both machines but I am currently in the midst of troubleshooting some connectivity issues with the Postfix / Dovecot server (mail will not go out), and I am wondering if what I am describing here may be playing a role in that. It's proving difficult to tell where the issue is stemming from because all of the systems also pass through a PfSense firewall before hitting the public net.

Although these two machines are not interacting with each other, I'm including them for reason of the behavior being similar.

Any insight would be greatly appreciated and I will supply any further details, logs, screenshots that may help.

The first screenshot (left) is of the machine running the Squid Proxy and the second is of the host to jails.

FreeBSD 1.jpg
FreeBSD 2.jpg
 
Seeing no net wizards have yet pounced ... a couple of guesses from ancient past.

To me the first looks likely a problem upstream (DNS not resolving), here the pfsense router or switch? or cabling getting to it, with the link being down for most of it, then the link flapping down /up every ~4s.

Maybe check logs on the pfsense box to be sure it's not having upstream issues?

The second shot doesn't show timing, but 3 interfaces going down/up, possibly in synch? Which one connects to the router? Maybe show the net topology?

And the promiscuous mode dance at bottom suggests perhaps someone? using tcpdump (ono) to watch or capture [edit: em0 and] em3, hopefully you?
 
Back
Top