OPNSense Gateway Packet Loss

Howdy!

Given that your LAN clients cannot replicate the issue I would agree that it seems dpinger might be having some issue. I have seen other threads like this one over the past 6 months or so of OPNSense users reporting similar things: Dpinger make a mess on latest release

Outside of a dpinger bug, it might also be helpful to reference our tutorial on pfSense Optimal Configuration as most of these recommendations can be implemented under OPNSense as well.

Specifically, if you are using the default Bridge Mode (IP Passthrough) I would definitely recommend statically assigning the OPNSense WAN MAC in the IG configuration which is covered in the tutorial here. This may help in the case dpinger is having some issue that has its source at layer 2 (ARP cache, etc.).

Also in the pfSense guide, there is a section on how to check if your WAN has Flow Control enabled and how to disable it as it has been known to sometimes increase latency.

The larger issue found in the last couple years is that carrier deprioritization algorithms, especially observed on T-Mobile, are increasingly dropping ICMP and UDP traffic at seemingly random intervals. I am not sure why they do this but it may be to mitigate disruptive DDOS activity from bad actors. Regardless, it is quite annoying for those that utilize failover monitoring that requires reliable ICMP replies. One suggestion would be to increase the payload size of the ICMP packets that dpinger sends as by default the payload size it sends is zero which is historically more likely to be dropped. More info can be found in the OP and first reply to this thread:
https://www.reddit.com/r/opnsense/comments/10b9nlz/gateway_monitoring_without_icmp/

I hope this information is helpful to you :slight_smile:

1 Like