<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Traffic Monitoring]]></title><description><![CDATA[Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.]]></description><link>https://forum.netgate.com/category/54</link><generator>RSS for Node</generator><lastBuildDate>Wed, 12 Aug 2026 06:31:16 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/category/54.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 18 Jul 2026 22:09:38 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Made my own Netflow Collector…]]></title><description><![CDATA[@luckman212 said in Made my own Netflow Collector…:

@keyser Sounds really excellent - can't wait to give this a try!

I have a zip archive with the setup including a brief deployment guide ready, so PM me if you would like to give it spin ;-)
EDIT: It's not a Docker container. Haven't found the time to create and deploy those yet.
FYI: All I expect back is a little feedback on issues/performance@scale, and that you do not share the setup with others :-)
]]></description><link>https://forum.netgate.com/topic/200973/made-my-own-netflow-collector</link><guid isPermaLink="true">https://forum.netgate.com/topic/200973/made-my-own-netflow-collector</guid><dc:creator><![CDATA[keyser]]></dc:creator><pubDate>Sat, 18 Jul 2026 22:09:38 GMT</pubDate></item><item><title><![CDATA[Recurring kernel panics (page fault in bpf_mtap) on pfSense Plus 26.03 with Suricata + VLAN interfaces]]></title><description><![CDATA[It looks like this is being worked on in https://redmine.pfsense.org/issues/16790 and a fix may be in 26.03.1.
]]></description><link>https://forum.netgate.com/topic/200683/recurring-kernel-panics-page-fault-in-bpf_mtap-on-pfsense-plus-26.03-with-suricata-vlan-interfaces</link><guid isPermaLink="true">https://forum.netgate.com/topic/200683/recurring-kernel-panics-page-fault-in-bpf_mtap-on-pfsense-plus-26.03-with-suricata-vlan-interfaces</guid><dc:creator><![CDATA[mouseskowitz]]></dc:creator><pubDate>Fri, 15 May 2026 00:04:32 GMT</pubDate></item><item><title><![CDATA[ZEEK 3.0.4 service wont start on pfSense 26.03]]></title><description><![CDATA[<p dir="auto">not sure when this problem started since i have been updating pfsense for a few years.</p>
<p dir="auto">but recently i had the pfsense ssd wear out (108%) and wanted to replace it before i had a catastrophic failure.</p>
<p dir="auto">so i replaced it, reinstalled pfsense, and restored the config file.  everything except the zeek service started</p>
<p dir="auto">poked around and found that there are two directories missing that was keeping zeek from starting:<br />
/usr/local/logs<br />
/usr/local/spool</p>
<p dir="auto">i assume this always worked before because at some point they were created by zeek or some other program, but not on a new 26.03 install.  as soon as i created these, zeek started and works fine.</p>
<p dir="auto">not sure who to send this to, but whoever is maintaining zeek needs to compensate for these two directories not being created natively.</p>
<p dir="auto">and thanks for making these packages available</p>
<p dir="auto">mark</p>
]]></description><link>https://forum.netgate.com/topic/200623/zeek-3.0.4-service-wont-start-on-pfsense-26.03</link><guid isPermaLink="true">https://forum.netgate.com/topic/200623/zeek-3.0.4-service-wont-start-on-pfsense-26.03</guid><dc:creator><![CDATA[markgca]]></dc:creator><pubDate>Sun, 03 May 2026 13:48:38 GMT</pubDate></item><item><title><![CDATA[Traffic Totals Retention]]></title><description><![CDATA[@Mission-Ghost My understanding is that Traffic Totals uses vnstat for data collection. There are a whole host of options that can be set in the /usr/local/etc/vnstat.conf file. Only 1 or two of them are exposed via the GUI.
]]></description><link>https://forum.netgate.com/topic/200570/traffic-totals-retention</link><guid isPermaLink="true">https://forum.netgate.com/topic/200570/traffic-totals-retention</guid><dc:creator><![CDATA[codechurn]]></dc:creator><pubDate>Wed, 22 Apr 2026 02:35:51 GMT</pubDate></item><item><title><![CDATA[Ntopng changing live traffic list from 10 to 20 crashed 6100 Max]]></title><description><![CDATA[@hulleyrob said in Ntopng changing live traffic list from 10 to 20 crashed 6100 Max:

Is Ntopng just that dangerous to leave running or is there something else going on?

While I do not generally recommend running ntopng on a continuous basis, doing so should not cause pfSense itself to become unresponsive. Although ntopng is a rather large and busy program, it runs in user space rather than kernel space and as such should not be able to crash the kernel.
You may have an underlying system problem. If it happens again, my recommendation would be to connect to the console and see what you can discover.
]]></description><link>https://forum.netgate.com/topic/200468/ntopng-changing-live-traffic-list-from-10-to-20-crashed-6100-max</link><guid isPermaLink="true">https://forum.netgate.com/topic/200468/ntopng-changing-live-traffic-list-from-10-to-20-crashed-6100-max</guid><dc:creator><![CDATA[dennypage]]></dc:creator><pubDate>Sat, 04 Apr 2026 10:17:02 GMT</pubDate></item><item><title><![CDATA[ntopng gone from packages?]]></title><description><![CDATA[@lohphat Netgate has always announced an end of sale and end of life date, and actually emailed registered purchasers about the 3100 (the "EOL in 5 days" email).  However they have also provided pfSense for all models "until they can't anymore" due to insufficient RAM or other incompatibilities.  It sounds like it is more of a "best effort" vs "guaranteed to work."  Given we all had "5 days" notice I would consider multiple years' time as a bonus.
Perhaps what they need to do, if the package list is still dwindling, is to add a note on the 3100's package pages to explain why, if it's not in the release notes.  Based on a prior discussion I once had, 3100 support is not mentioned in the current release notes because it is not a new issue/change, and (my interpretation) they assume one has read all previous notes.
]]></description><link>https://forum.netgate.com/topic/200463/ntopng-gone-from-packages</link><guid isPermaLink="true">https://forum.netgate.com/topic/200463/ntopng-gone-from-packages</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Fri, 03 Apr 2026 02:52:01 GMT</pubDate></item><item><title><![CDATA[Teamspeak Login generates Surricata alert: Base64 HTTP Password detected unencrypted on]]></title><description><![CDATA[@johnpoz The decoded base 64 isn't something I recognise. It's simply "teamspeak5:" and then a random string of numbers/letters/symbols.
]]></description><link>https://forum.netgate.com/topic/200166/teamspeak-login-generates-surricata-alert-base64-http-password-detected-unencrypted-on</link><guid isPermaLink="true">https://forum.netgate.com/topic/200166/teamspeak-login-generates-surricata-alert-base64-http-password-detected-unencrypted-on</guid><dc:creator><![CDATA[ghar36k]]></dc:creator><pubDate>Mon, 16 Feb 2026 05:28:13 GMT</pubDate></item><item><title><![CDATA[Zeek version and ability to utilize plugins]]></title><description><![CDATA[<p dir="auto">All,</p>
<p dir="auto">As the installable version of Zeek is 6.x and zeek.org shows LTS release as 8.0.6 - anyone happen to know if/when an updated version may become available?</p>
<p dir="auto">Also, a litany of the plugins (via zkg) demand compilation (clang, etc.).  Given that pfSense doesn't ship with (nor provide ability to install) - has anyone figured out a means to utilize some of those plugins?</p>
<p dir="auto">Thanks!</p>
]]></description><link>https://forum.netgate.com/topic/200083/zeek-version-and-ability-to-utilize-plugins</link><guid isPermaLink="true">https://forum.netgate.com/topic/200083/zeek-version-and-ability-to-utilize-plugins</guid><dc:creator><![CDATA[justme2]]></dc:creator><pubDate>Thu, 05 Feb 2026 14:44:52 GMT</pubDate></item><item><title><![CDATA[After last upgrade (25.11)  the trafic seem to LAG on wan level]]></title><description><![CDATA[<p dir="auto">if I do a speed test to a specific host it runs ok - but streaming have a lot of LAG.<br />
before upgrade it was only one or 2 times a day now it 10-15 times a day</p>
<p dir="auto">is there any one else experins that kind of beheaver</p>
<p dir="auto">my router is Netgate 1100</p>
<p dir="auto">thanks in advance</p>
<p dir="auto">John</p>
]]></description><link>https://forum.netgate.com/topic/199679/after-last-upgrade-25.11-the-trafic-seem-to-lag-on-wan-level</link><guid isPermaLink="true">https://forum.netgate.com/topic/199679/after-last-upgrade-25.11-the-trafic-seem-to-lag-on-wan-level</guid><dc:creator><![CDATA[john_h_k]]></dc:creator><pubDate>Fri, 26 Dec 2025 18:22:34 GMT</pubDate></item><item><title><![CDATA[experiments.apple.com]]></title><description><![CDATA[@tinfoilmatt that os is new to me.
]]></description><link>https://forum.netgate.com/topic/199526/experiments.apple.com</link><guid isPermaLink="true">https://forum.netgate.com/topic/199526/experiments.apple.com</guid><dc:creator><![CDATA[JonathanLee]]></dc:creator><pubDate>Tue, 09 Dec 2025 23:25:21 GMT</pubDate></item><item><title><![CDATA[Got a lot of errors of permission with ntopng]]></title><description><![CDATA[@kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example:
/usr/sbin/chown -R nobody:nobody /var/db/ntopng

However, the better choice would be to upgrade to a more recent version.
]]></description><link>https://forum.netgate.com/topic/199080/got-a-lot-of-errors-of-permission-with-ntopng</link><guid isPermaLink="true">https://forum.netgate.com/topic/199080/got-a-lot-of-errors-of-permission-with-ntopng</guid><dc:creator><![CDATA[dennypage]]></dc:creator><pubDate>Mon, 20 Oct 2025 09:23:19 GMT</pubDate></item><item><title><![CDATA[NetFlow data collector with ntopng]]></title><description><![CDATA[@Antibiotic No it’s not possible with NtopNG as it is not a Netflow collector. You need nProbe for that which will “translate” recieved netflows into flows that NtopNG understands and can visualize (with very very little detail might I add as Netflows has no additonal information apart from sender/reciever and volume). The NtopNG package and the product in general is more geared towards visualising and recording traffic details from actual packet captures. This contains MUCH more metadata about the sessions than netflows (DNS names, protocol information and myriads of other things).
But pffSense Plus has a builtin Netflow exporter if you have an external netflow collector on hand.
]]></description><link>https://forum.netgate.com/topic/198686/netflow-data-collector-with-ntopng</link><guid isPermaLink="true">https://forum.netgate.com/topic/198686/netflow-data-collector-with-ntopng</guid><dc:creator><![CDATA[keyser]]></dc:creator><pubDate>Wed, 03 Sep 2025 20:20:33 GMT</pubDate></item><item><title><![CDATA[Outgoing Portscans - ntopng?]]></title><description><![CDATA[@StealthNet said in Outgoing Portscans - ntopng?:

Tbh I never thought a default package would do some kind of outbound network discovery based on class C scanning of internet hosts.
I don´t think this is ok.

I agree. I was rather shocked when I discovered this while diagnosing the same issue with another pfSense user who happens to be a close friend of min. He had also enabled it because ntopng's description made it sound like a good thing.
Anyway, I appreciate your, and others, input on this. I believe I will add a set of warning to the next version of the package, to at least have put forth the information/warning.
Thank you.
]]></description><link>https://forum.netgate.com/topic/197521/outgoing-portscans-ntopng</link><guid isPermaLink="true">https://forum.netgate.com/topic/197521/outgoing-portscans-ntopng</guid><dc:creator><![CDATA[dennypage]]></dc:creator><pubDate>Tue, 20 May 2025 21:44:31 GMT</pubDate></item><item><title><![CDATA[Limiting ntopng disk usage]]></title><description><![CDATA[@Leon-Straathof Data retention settings are handled inside of ntopng. Documentation here. Pay attention to the RRD note.
Also, if you've turned on some of the slice and dice time series information (is off by default), I'd suggest turning them back off. These balloon the storage requirements and are of little actual use.
]]></description><link>https://forum.netgate.com/topic/197431/limiting-ntopng-disk-usage</link><guid isPermaLink="true">https://forum.netgate.com/topic/197431/limiting-ntopng-disk-usage</guid><dc:creator><![CDATA[dennypage]]></dc:creator><pubDate>Tue, 13 May 2025 02:07:42 GMT</pubDate></item><item><title><![CDATA[Seeking package recommendation to monitor port forwards]]></title><description><![CDATA[<p dir="auto">I am looking for a package that can show hits on a forwarded port specifically, as well as inbound traffic that was passed on that port.  It will be tunnelled traffic being redirected to an internal wireguard server.</p>
]]></description><link>https://forum.netgate.com/topic/197375/seeking-package-recommendation-to-monitor-port-forwards</link><guid isPermaLink="true">https://forum.netgate.com/topic/197375/seeking-package-recommendation-to-monitor-port-forwards</guid><dc:creator><![CDATA[aljames]]></dc:creator><pubDate>Wed, 07 May 2025 01:56:56 GMT</pubDate></item><item><title><![CDATA[ntopng Cloud on pfsense 2.8 can’t connect to cloud.ntop]]></title><description><![CDATA[@jonatremoteeyes If ntopng runs fine locally but won't connect to Ntop Cloud, it might indeed be a package limitation or the cloud.conf not being picked up properly by the pfSense package.
]]></description><link>https://forum.netgate.com/topic/197187/ntopng-cloud-on-pfsense-2-8-can-t-connect-to-cloud-ntop</link><guid isPermaLink="true">https://forum.netgate.com/topic/197187/ntopng-cloud-on-pfsense-2-8-can-t-connect-to-cloud-ntop</guid><dc:creator><![CDATA[LukasInCloud]]></dc:creator><pubDate>Fri, 18 Apr 2025 10:06:46 GMT</pubDate></item><item><title><![CDATA[Backing up Traffic Totals on an routinely?]]></title><description><![CDATA[@pulsartiger
The database name is vnstat.db and its location is under /var/db/vnstat.
With "Backup Files/Dir" we are able to do backup or also with a cron.
]]></description><link>https://forum.netgate.com/topic/196717/backing-up-traffic-totals-on-an-routinely</link><guid isPermaLink="true">https://forum.netgate.com/topic/196717/backing-up-traffic-totals-on-an-routinely</guid><dc:creator><![CDATA[kikuyu]]></dc:creator><pubDate>Sun, 09 Mar 2025 02:16:57 GMT</pubDate></item><item><title><![CDATA[Best way of finding top talker live]]></title><description><![CDATA[@keyser Because i've seen it can be pretty intensive, I'm going to enable it only when the needs come up. Ive seen folks leave it on which i guess you can do but seems a bit much.
I appreciate your advice!
]]></description><link>https://forum.netgate.com/topic/196618/best-way-of-finding-top-talker-live</link><guid isPermaLink="true">https://forum.netgate.com/topic/196618/best-way-of-finding-top-talker-live</guid><dc:creator><![CDATA[michmoor]]></dc:creator><pubDate>Mon, 03 Mar 2025 14:45:26 GMT</pubDate></item><item><title><![CDATA[ntopng ignoring &quot;Additional configuration for ntopng.conf&quot;]]></title><description><![CDATA[@HeMan321 said in ntopng ignoring "Additional configuration for ntopng.conf":

But, to be honest, I am starting to realize that ntopng is probably somewhat too complex for my needs anyway. It is very slick and powerful, but I just wanted to keep an eye on outbound connections and so probably don't need to burden my Netgate box with everything else that ntopng does.

Smart choice.
]]></description><link>https://forum.netgate.com/topic/196493/ntopng-ignoring-additional-configuration-for-ntopng-conf</link><guid isPermaLink="true">https://forum.netgate.com/topic/196493/ntopng-ignoring-additional-configuration-for-ntopng-conf</guid><dc:creator><![CDATA[dennypage]]></dc:creator><pubDate>Thu, 20 Feb 2025 15:59:53 GMT</pubDate></item><item><title><![CDATA[IPS activas en la red]]></title><description><![CDATA[<p dir="auto">Saludos, como puedo monitorear las IPS activas en mi red</p>
]]></description><link>https://forum.netgate.com/topic/196328/ips-activas-en-la-red</link><guid isPermaLink="true">https://forum.netgate.com/topic/196328/ips-activas-en-la-red</guid><dc:creator><![CDATA[Nutri]]></dc:creator><pubDate>Thu, 06 Feb 2025 21:40:27 GMT</pubDate></item><item><title><![CDATA[Users, where they go? Report.]]></title><description><![CDATA[@periko I agree with you. Most if not all firewalls today provide some ability to peak into what kind of traffic is flowing through your device.
]]></description><link>https://forum.netgate.com/topic/196166/users-where-they-go-report</link><guid isPermaLink="true">https://forum.netgate.com/topic/196166/users-where-they-go-report</guid><dc:creator><![CDATA[michmoor]]></dc:creator><pubDate>Sat, 25 Jan 2025 19:00:04 GMT</pubDate></item></channel></rss>