Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    In need of help to solve a bandwidth issue

    General pfSense Questions
    11
    61
    18.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      wallabybob
      last edited by

      In a pfSense console session run pftop to get dynamic display of current firewall states (connections). Type h too get a display of the options. The R option should sort connections on rate and that should give you some clues about who is using the bandwidth.

      1 Reply Last reply Reply Quote 0
      • L
        luke240778
        last edited by

        @tommyboy180:

        True. I forgot that about your post. Let me run this by some of my colleagues at work and see if I can give you a better hint.

        Thanks for this.. looking forward to what you come up with..

        1 Reply Last reply Reply Quote 0
        • L
          luke240778
          last edited by

          @wallabybob:

          In a pfSense console session run pftop to get dynamic display of current firewall states (connections). Type h too get a display of the options. The R option should sort connections on rate and that should give you some clues about who is using the bandwidth.

          I have done this, at a time when the WAN says 20mb usage, and below is what i see, i can't understand it well enough to see if it actually gives me an answer or not (i see alot of INBOUND traffic with port 127.0.0.1:3128 (squid Proxy Port).. is that my problem? and what uses that port?)

          Getting confused with what In and Out refer to here..

          pftop.png
          pftop.png_thumb

          1 Reply Last reply Reply Quote 0
          • T
            tommyboy180
            last edited by

            Squid uses 3128 by default.

            -Tom Schaefer
            SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

            Please support pfBlocker | File Browser | Strikeback

            1 Reply Last reply Reply Quote 0
            • Cry HavokC
              Cry Havok
              last edited by

              In and Out are interface related - so a download will generally be In on WAN and Out on LAN (and so on).

              1 Reply Last reply Reply Quote 0
              • L
                luke240778
                last edited by

                Right, just saw that in my squid config.  So, what i am not understanding is this… if it is possibly ptp traffic, wouldnt that show up on the Traffic Graph also on the LAN interface, where all my clients are connected?  This high WAN usage issue to me seems like i am leaking bandwidth somehow, somewhere.. cause the LAN interface is always quite low in usage, but just the WAN is max'd. Does that pftop output make any sense to you?

                1 Reply Last reply Reply Quote 0
                • Cry HavokC
                  Cry Havok
                  last edited by

                  Have you looked at the reverse DNS (rDNS) and WhoIS of the highest volume remote nodes? The top 2 I picked both related to Google services.

                  What is 192.168.10.240, since it seems associated with some of the highest transfers, through Squid.

                  1 Reply Last reply Reply Quote 0
                  • L
                    luke240778
                    last edited by

                    @Cry:

                    Have you looked at the reverse DNS (rDNS) and WhoIS of the highest volume remote nodes? The top 2 I picked both related to Google services.

                    What is 192.168.10.240, since it seems associated with some of the highest transfers, through Squid.

                    192.168.10.240 is one of my clients.. who according is limited to maximum 2mb/1mb.. as are all my clients

                    Here is a current snapshot of my pftop… currently my WAN is showing 20mb usage..  I have no idea what is going down... all my clients are limited via captive portal to 2mb, and are also limited on my AP (wireless cliente connecting via antenna).. when this shows 20mb usage, my LAN (192.168.10.0) is showing 4mb usage

                    20mb.png
                    20mb.png_thumb

                    1 Reply Last reply Reply Quote 0
                    • Cry HavokC
                      Cry Havok
                      last edited by

                      Three of your top 4 lines refer to 65.54.93.42 (cds39.mia9.msecn.net.). I don't know what that is - does it make sense to you?

                      1 Reply Last reply Reply Quote 0
                      • L
                        luke240778
                        last edited by

                        No.. not at all..  Currently it is chewing up 20mb.. and that IP is no longer there in the pftop output.

                        1 Reply Last reply Reply Quote 0
                        • L
                          luke240778
                          last edited by

                          Also, i should add that this just became more confusing.. i thought it would be some clients doing alot of ptp or torrenting or something, but i just completely turned all the clients off for 10 minutes and the bandwidth never changes, was still max'd at 20mb with no one using the box..

                          1 Reply Last reply Reply Quote 0
                          • M
                            Metu69salemi
                            last edited by

                            Try to change admin passwords and disable outbound ssh connection for testing

                            1 Reply Last reply Reply Quote 0
                            • L
                              luke240778
                              last edited by

                              Ok, just changed passwords and disabled SSH.. will report back in a little while

                              1 Reply Last reply Reply Quote 0
                              • L
                                luke240778
                                last edited by

                                Ok, so its currently back up stuck at 20mb usage..  this just makes no sense.. the LAN traffic is only 2mb usage..  Can i have been hacked or something?  Is it even possible that squid or something else is using up all the bandwidth?

                                1 Reply Last reply Reply Quote 0
                                • P
                                  podilarius
                                  last edited by

                                  @luke240778:

                                  Ok, so its currently back up stuck at 20mb usage..  this just makes no sense.. the LAN traffic is only 2mb usage..  Can i have been hacked or something?  Is it even possible that squid or something else is using up all the bandwidth?

                                  Did you try and disabling squid and see if that cuts the bandwidth down?

                                  1 Reply Last reply Reply Quote 0
                                  • L
                                    luke240778
                                    last edited by

                                    Thats the only thing i havent already done.. as i am a little worried if this will delete my cache or something?  Cache is something that i really need running as i havent got a great deal of bandwidth..  If its ok to disable it and then re-enable it then i'll give it shot

                                    1 Reply Last reply Reply Quote 0
                                    • P
                                      podilarius
                                      last edited by

                                      It has been a long time since I used squid. I don't think I remember if it clears it or not.

                                      1 Reply Last reply Reply Quote 0
                                      • L
                                        luke240778
                                        last edited by

                                        Just quickly.. what do you mean by 'disable' squid?  I dont see a disable check bo like some other packages have.. do you mean just stop int binding to the interface? Mine currently binds to my LAN and OPT1 interface, and not my WAN interface..

                                        1 Reply Last reply Reply Quote 0
                                        • P
                                          podilarius
                                          last edited by

                                          Sorry, just stopping it will disable it until reboot or until you start it again.

                                          1 Reply Last reply Reply Quote 0
                                          • L
                                            luke240778
                                            last edited by

                                            Any idea how to STOP it? i have just done it a few times via the dashboard 'Services" widget, but it keeps just turning itself back on..

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.