• 0 Votes
    3 Posts
    827 Views
    N

    @dennypage said in Ntopng: mvneta0: promiscuous mode disabled, Either port in use or another ntopng instance:

    Did you discover what other process had port 3000 locked?

    Evening, not yet, and after the reboot and as of today is running as expected...., but will see how long, the only I have done is run the gui in another web tab, so I will give it a try and see what happens in a few days. Also I do run it from another system, so maybe that's causing the problem. I will test that also.

  • Traffic Totals doesn't show current month

    10
    0 Votes
    10 Posts
    1k Views
    M

    @hspindel ahh I gotcha

  • ntopng: Live Flows

    2
    0 Votes
    2 Posts
    461 Views
    keyserK

    @nasheayahu Those are only the actual namelookup attempt. If you are running pfBlockerNG and are bloking those domainnames, then the client will get a NXDOMAIN response from that namelook - and thus won't get any further.

    two things to notice:

    1: You have one client that is bypassing your Unbound Resolver on pfSense (with pfBlockerNG blokings) and are using 1.1.1.1 and 1.0.0.1 as nameservers.

    2: PfBlockerNG does not actually block any IP connections (when it comes do domain names). It only prevents the clients from resoling those names to IP adresses - and are thus unable to contact those services.

  • How to run the packet capture on pfsense and ntopng on a different VM?

    3
    2 Votes
    3 Posts
    2k Views
    keyserK

    @jacotec I know this is an old thread, but I don’t think Softflowd can quite deliver what you are asking. If you want a report of one 30 min flow in NtopNG, you have to ask softflowD not to expire flows on a timer - you need to leave the expiration field empty. (Otherwise it effectively reports flows that is not completed as unique flows).
    Then you get what you want, but the problem is then that you cannot see the flow while it is in progress. You have to wait 30 min.

    What we really need is a Nprobe package for pfSense that allows us to install Nprobe (and license it). That way it can do the actual capture/analyze part - including the much more insightfull DPI features compared to standard netflow, and report all of it to NtopNG on another machine via ZMQ.

  • >>> Darkstat [FIX] for v.2.7.0-2.7.2

    1
    0 Votes
    1 Posts
    441 Views
    No one has replied
  • Help with Influx db queries about firewall and IP info

    9
    0 Votes
    9 Posts
    2k Views
    kiokomanK

    @cuteliquid11
    you need to enable and configure this

    ac0bd3a0-8e22-4de8-9943-25bf29a0067d-image.png

  • Darkstat and BandwidthD not showing VLAN traffic.

    10
    0 Votes
    10 Posts
    2k Views
    perikoP

    @michmoor I mean tools inside pfsense, netflow run outside pfsense.

  • Lightsquid not working

    3
    0 Votes
    3 Posts
    921 Views
    JonathanLeeJ

    I agree reinstall it

    Its working for me

    Screenshot 2023-12-21 at 11.42.32 AM.png

  • bandwidthd not starting?

    2
    0 Votes
    2 Posts
    672 Views
    perikoP

    @hspindel
    band1.png
    The only issue I have is that won't show my VLANs traffic, but never have issue with the app.
    Regards.

  • Transporting Zeek logs to AC-Hunter?

    1
    0 Votes
    1 Posts
    345 Views
    No one has replied
  • Domain Logging Per Client

    7
    0 Votes
    7 Posts
    772 Views
    keyserK

    @Lockie happy to help

  • ntopng not working

    1
    0 Votes
    1 Posts
    479 Views
    No one has replied
  • Really would like ngrep

    5
    0 Votes
    5 Posts
    778 Views
    O

    OK thats a lot better there though there is a lot of crap to filter out. I was able to get most of the crap out by filtering for PSH+ACK like so: 'tcp[13] == 24'

    Theres still some junk in there though and it'd be nice to have more LFs in there between packets but this is definitely way better, thanks!

  • Simple package for monitoring IP up status

    9
    0 Votes
    9 Posts
    2k Views
    J

    @johnpoz said in Simple package for monitoring IP up status:

    why not provide it to the community?

    Never said I wouldn't. But likely just remain as a patch file that can be NAME/IP configured by the user before applying. Not sure there is a demand for more configuration than that. Based on the thread here (and no others I can find) Seems the interested usage group would be really low (ie me). Hard to tell, as the only original responses to this thread were both suggesting to do something else.

    @johnpoz said in Simple package for monitoring IP up status:

    why would there even be a thread asking for such a thing in the first place

    because I originally asked the question, not being able to find anything? is this a trick question LOL

    Anyway thanks for the feedback, it was just something to occupy a few cycles.

  • cli traffic monitoring

    1
    0 Votes
    1 Posts
    386 Views
    No one has replied
  • Traffic totals error (call this solved)

    11
    0 Votes
    11 Posts
    7k Views
    R

    what if i didn't want to loose data :(

  • Playing with IPFIX and bidirectional flows

    1
    0 Votes
    1 Posts
    547 Views
    No one has replied
  • Trying to add custom protocol for VPN category.

    1
    1 Votes
    1 Posts
    372 Views
    No one has replied
  • Losing ntopng data on reboot

    1
    1 Votes
    1 Posts
    281 Views
    No one has replied
  • Q: what are the elevated hardware requirements for running zeek?

    1
    0 Votes
    1 Posts
    729 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.