pfSense-pkg-crowdsec icon indicating copy to clipboard operation
pfSense-pkg-crowdsec copied to clipboard

Machine "pfsense" removed after reboot

Open pvillmann opened this issue 1 year ago • 1 comments

Hi,

i'am using crowdsec on my pfsense as central LAPI. (6 Log processors for different applications).

The problem is, after each reboot of pfsense the crowdsec service starts not automatically because the local "machine" cannot connect to "local lapi". On the Machine list there is no "pfsense" machine listed.

If I run after each startup the command "cscli machine add pfsense -a --force" and start then the crowdsec service manually, everthing works fine.

Any ideas?

Thanks a lot :)

pvillmann avatar Mar 15 '24 14:03 pvillmann

I have the same issue. I already mentioned that in a comment on another issue https://github.com/crowdsecurity/pfSense-pkg-crowdsec/issues/84#issuecomment-1873790678

But other than that workaround after every boot I don't know how to fix it.

Maybe it's related to the fact that the setting for "LAPI host" is set to something that's not the default. (not 127.0.0.1)

p-schneider avatar Apr 26 '24 12:04 p-schneider

For this issue, I think the reason is you have /var in a ram disk. If that's not the case, please try the latest version

https://github.com/crowdsecurity/pfSense-pkg-crowdsec/releases/tag/v0.1.4-1.6.3_2

mmetc avatar Oct 11 '24 12:10 mmetc

Hi... sorry i forgot to give feeback here... After i have updated to 1.6.2 and register my local pfsense instance again to 127.0.0.1 everything works fine... So at the end, for me, issue can be closed.

pvillmann avatar Oct 11 '24 13:10 pvillmann

For me that issue still persists with the latest v0.1.4-1.6.3_2 (having local lapi host set to my LAN IP instead of 127.0.0.1). But the workaround I've been using for a long time also still works, so I'll keep doing that for now.

p-schneider avatar Oct 11 '24 15:10 p-schneider

If you do so, check the bouncer logs for any surprise. It's also stored in the local db and if it can't connect, there is no protection. If you have /var in ram see if you can change that

mmetc avatar Oct 11 '24 21:10 mmetc