• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

In need of help to solve a bandwidth issue

Scheduled Pinned Locked Moved General pfSense Questions
61 Posts 11 Posters 18.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • L
    luke240778
    last edited by Sep 10, 2011, 10:00 PM Sep 10, 2011, 9:44 PM

    So i have a 20mb link.. when i look at the Traffic Graph, i often see like the attached screenshot..  its saying that the WAN connection is downloading full at 20mbps.. and that my HOTSPOT which is all my clients, is only using a small amount.. 3-4 mbps..

    As far as i see here, my bandwidth is all being used up but i dont see how??  All my clients are connected on the HOTSPOT interface.. On my pfsense box i just use captive portal MAC pass through and squid transparent proxy.

    Can someone please help here? I am adding more clients everyday and am worried that the bandwidth is somehow getting eaten up.

    traffic_graph.png
    traffic_graph.png_thumb

    1 Reply Last reply Reply Quote 0
    • C
      Cry Havok
      last edited by Sep 11, 2011, 9:08 AM

      There have been a number of threads on diagnosing bandwidth usage - I would suggest you start by working through those. What other interfaces do you have and what packages do you have?

      1 Reply Last reply Reply Quote 0
      • L
        luke240778
        last edited by Sep 11, 2011, 3:28 PM

        I have the following packages installed:

        bandwidthd.  
        Cron
        darkstat 
        iperf
        Lightsquid  
        OpenVPN Client Export Utility
        phpSysInfo
        RRD Summary
        squid
        widescreen

        Interfaces i just have WAN, LAN  and an OPT1 which is just my office Wireless network.. which only 2 or 3 people use, very minimal usage on that.

        Ive looked through a bunch of the threads and saw a few that mention maybe a networl switch or something causing problems, but i dont have that at all.. very simple setup here.  The LAN interface is plugged to Ruckus equipment on the roof which serves my WiSP clients.

        1 Reply Last reply Reply Quote 0
        • T
          tommyboy180
          last edited by Sep 11, 2011, 3:36 PM

          Are you doing any type of traffic shaping QoS?

          -Tom Schaefer
          SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

          Please support pfBlocker | File Browser | Strikeback

          1 Reply Last reply Reply Quote 0
          • L
            luke240778
            last edited by Sep 12, 2011, 4:36 AM

            No, nothing at all.

            Just using Captive portal Mac pass through.. and squid as a transparent proxy

            1 Reply Last reply Reply Quote 0
            • K
              kapara
              last edited by Sep 14, 2011, 5:43 AM

              pfTop via SSH

              Type the following commands to get ip's with highest throughput utilization…  do not type the commas

              7,  R (Capital R), s, 1

              Another option is install the pflowd package and downloading ManageEngines netflow monitor on a PC or Server on the lan.  Point the pfflowd to the PC with manageengine.  I used to use it alot!!!!

              You get 2 free devices to monitor.  Free phone support for setup too!

              Skype ID:  Marinhd

              1 Reply Last reply Reply Quote 0
              • L
                luke240778
                last edited by Sep 16, 2011, 12:46 PM

                Thanks for that .. i am using both these options now.. great

                Just quickly, that RATE in pftop.. is that in bytes or kilobyes?  So for example 348015 is what?

                1 Reply Last reply Reply Quote 0
                • P
                  podilarius
                  last edited by Sep 16, 2011, 3:05 PM

                  I think it is in BYTES per sec.

                  1 Reply Last reply Reply Quote 0
                  • D
                    dreamslacker
                    last edited by Sep 16, 2011, 4:09 PM

                    If your Squid is set to cache, it is possible that clients have initiated and cancelled downloads which results in Squid still persistently downloading the content for caching purposes though the clients no longer require it.

                    1 Reply Last reply Reply Quote 0
                    • L
                      luke240778
                      last edited by Sep 16, 2011, 4:16 PM

                      Ah.. interesting… I do indeed have squid setup as a transparent proxy..  I will keep an eye on this.

                      Whilst on the subject of Squid.. Having the swap.state log rotate daily, doesnt affect the actual cache or clients getting content from cache right?  I need all the help i can to conserve bandwidth

                      1 Reply Last reply Reply Quote 0
                      • S
                        serialdie
                        last edited by Sep 16, 2011, 4:23 PM

                        @kapara:

                        pfTop via SSH

                        Type the following commands to get ip's with highest throughput utilization…  do not type the commas

                        7,  R (Capital R), s, 1

                        Another option is install the pflowd package and downloading ManageEngines netflow monitor on a PC or Server on the lan.  Point the pfflowd to the PC with manageengine.  I used to use it alot!!!!

                        You get 2 free devices to monitor.  Free phone support for setup too!

                        Where do you get pflowd for pfsense from?

                        Is nether in the pkg list or the freebsd repo.

                        TIA!

                        1 Reply Last reply Reply Quote 0
                        • S
                          serialdie
                          last edited by Sep 16, 2011, 4:39 PM

                          found it.

                          Thanks!

                          1 Reply Last reply Reply Quote 0
                          • L
                            luke240778
                            last edited by Sep 19, 2011, 11:52 PM

                            What can i use to see what is actually happening as far as squid possibly downloading or something? I am having this issue more often now.. its becoming a problem to my clients.. for an unknown reason for times throughout the day, for hours at a time my WAN usage is right up at my 20mb limit..  Take a look at attachment, i am in need of assistance for sure..

                            problem.png
                            problem.png_thumb

                            1 Reply Last reply Reply Quote 0
                            • T
                              tommyboy180
                              last edited by Sep 20, 2011, 1:13 AM

                              Wow! Well if it were my installation I would go back to the basics and remove everything and slowly re-build over time. Try to eliminate potential causes of the issue.
                              Also, get a capture of that traffic so you can find out exactly what that is. If I had to guess without much insight to what is going on I would not eliminate p2p traffic.

                              -Tom Schaefer
                              SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                              Please support pfBlocker | File Browser | Strikeback

                              1 Reply Last reply Reply Quote 0
                              • L
                                luke240778
                                last edited by Sep 20, 2011, 2:23 AM

                                Thanks for that.. starting again and rebuilding from scratch is hard as i really rely on the build up squid cache that is on there (50gb or so)

                                Wouldn't ptp traffic show up on my LAN interface (where all my clients are) as well as the LAN?  WHen th WAN is like you see in that screenshot, the LAN (clients) is never above say 3-4mb usage..

                                1 Reply Last reply Reply Quote 0
                                • T
                                  tommyboy180
                                  last edited by Sep 20, 2011, 2:55 AM

                                  True. I forgot that about your post. Let me run this by some of my colleagues at work and see if I can give you a better hint.

                                  -Tom Schaefer
                                  SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                                  Please support pfBlocker | File Browser | Strikeback

                                  1 Reply Last reply Reply Quote 0
                                  • W
                                    wallabybob
                                    last edited by Sep 20, 2011, 3:08 AM

                                    In a pfSense console session run pftop to get dynamic display of current firewall states (connections). Type h too get a display of the options. The R option should sort connections on rate and that should give you some clues about who is using the bandwidth.

                                    1 Reply Last reply Reply Quote 0
                                    • L
                                      luke240778
                                      last edited by Sep 20, 2011, 3:58 PM

                                      @tommyboy180:

                                      True. I forgot that about your post. Let me run this by some of my colleagues at work and see if I can give you a better hint.

                                      Thanks for this.. looking forward to what you come up with..

                                      1 Reply Last reply Reply Quote 0
                                      • L
                                        luke240778
                                        last edited by Sep 20, 2011, 4:23 PM Sep 20, 2011, 4:18 PM

                                        @wallabybob:

                                        In a pfSense console session run pftop to get dynamic display of current firewall states (connections). Type h too get a display of the options. The R option should sort connections on rate and that should give you some clues about who is using the bandwidth.

                                        I have done this, at a time when the WAN says 20mb usage, and below is what i see, i can't understand it well enough to see if it actually gives me an answer or not (i see alot of INBOUND traffic with port 127.0.0.1:3128 (squid Proxy Port).. is that my problem? and what uses that port?)

                                        Getting confused with what In and Out refer to here..

                                        pftop.png
                                        pftop.png_thumb

                                        1 Reply Last reply Reply Quote 0
                                        • T
                                          tommyboy180
                                          last edited by Sep 20, 2011, 4:25 PM

                                          Squid uses 3128 by default.

                                          -Tom Schaefer
                                          SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                                          Please support pfBlocker | File Browser | Strikeback

                                          1 Reply Last reply Reply Quote 0
                                          4 out of 61
                                          • First post
                                            4/61
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received