Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    View source & destination IP address for traffic

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    10 Posts 6 Posters 3.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      keith_opswat
      last edited by

      Hi,

      I'm not 100% sure whether this should be here or General questions. Also, I tried to search for this but wasn't sure how to word it. So if this is a common question I apologize and please feel free to verbally berate me.

      Anyways, I switched from a Cisco ASA 5505 and on it's GUI I could get a graph that would show me both the source & destination IP address.

      When I see a large amount of bandwidth by a user on our LAN right now I can only see what the LAN IP is and figure out what user it is. However, I can't see the destination to figure out where it's going. Hopefully I'm explaining this right…

      Is there a package that I missed that can give me this in realtime or some option I need to turn on? It would be really nice to see that there is say 9.3 Mbps of data coming to my LAN IP address of 192.168.1.15 but it's coming from IP address 73.212.52.12 or something like that. Because before on my Cisco I could look it up and figure out oh it's Microsoft Update... Or they're streaming something from Netflix.

      Thanks in advance and please let me know if you need anymore info.

      1 Reply Last reply Reply Quote 0
      • M
        Metu69salemi
        last edited by

        If this helps, your missing hostwatch(as watchguard, names that feature)
        I haven't seen that in pfsense, but i didn't use time to look it.

        1 Reply Last reply Reply Quote 0
        • G
          Gloom
          last edited by

          I think NTOP is what you are looking for. Not sure of it's current state on RC2

          You could also look at the states table under Diagnostics and just filter on the IP to see the flows. It won't give you the amount of data but it will tell you where it's coming from.

          Never underestimate the power of human stupidity

          1 Reply Last reply Reply Quote 0
          • N
            Nachtfalke
            last edited by

            I have a similar "problem".
            I could filter the source IP in the states but it'n not realtime so you can not be sure if the destination IP is the IP which causes high traffic or if the user has many connections open.

            The Traffic Graph shows really good the source IP but it would be really nice if you could watch the destination IP.

            But a workaround could be:
            Use packet capture and capture all traffic from the source IP and then you will see to which destination IPs the source IP will connect.

            Perhaps sometimes a DNS lookup of the destination IPs will help, too.

            1 Reply Last reply Reply Quote 0
            • P
              phospher
              last edited by

              check out iftop. works great.

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                @phospher:

                check out iftop. works great.

                Wow, that's a great tool! How have I missed that in the past.
                Thanks.  ;D

                Steve

                1 Reply Last reply Reply Quote 0
                • K
                  keith_opswat
                  last edited by

                  Oh yeh.. I had that installed on my test PFSense box… Never re-installed it after I moved it into productions.

                  Thanks. Will check that out again soon.

                  1 Reply Last reply Reply Quote 0
                  • N
                    Nachtfalke
                    last edited by

                    Is iftop a pfsense package ?
                    I didn't find it in amd64 RC-2

                    1 Reply Last reply Reply Quote 0
                    • P
                      phospher
                      last edited by

                      No it's not a package that you can add through the pfsense gui. But from the shell```
                      pkg_add -r iftop

                      1 Reply Last reply Reply Quote 0
                      • N
                        Nachtfalke
                        last edited by

                        thx

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.