Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    RRD Graph issue showing Opt traffic in WAN RRD Graph

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 2 Posters 3.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      FJSchrankJr
      last edited by

      I've been noticing very interesting trends in traffic between 2 WAN interfaces. WAN and OPT1 (WAN2). The outbound traffic in RRD shows similar trending between the 2, and today  when OPT1 went down, the drop in traffic is also visible on the WAN graph.

      So, because this firewall is setup as NAT is it possible that WAN traffic graphs are including WAN traffic + OPT1 traffic? It was a very strange issue and has had me confused. I was looking towards a routing issue but came up with nothing. Something else thats very interesting is the traffic in Traffic Graph is not consistant with the traffic in RRD unless you add both interface traffic together, then RRD appears to be accurate.

      This is on a pfSense 2.0-RC1 built on Wed Jun 15 19:13:09 EDT 2011. Thank you for your help guys!

      FJS - Embedded Systems Engineer
      Pictures are worth a thousand words, but <u>posting config.xml backups are worth 10,000</u>.  Alter the IPs, change anything revealing but leave subnets intact. Use find and replace. Please try to keep it brief on the description.
      ALWAYS disable TSO  & LRO EXCEPT CHKSUM IF SUPPORTED. TSO/LRO breaks traffic, pf scrub and this goes for any passive device inline

      1 Reply Last reply Reply Quote 0
      • F Offline
        FJSchrankJr
        last edited by

        confirmed, everytime WAN2 (OPT1) has a traffic burst, the RRD for WAN shows the burst too but the traffic for WAN and WAN2 are different, WAN appears to be WAN traffic plus WAN2 traffic added together.

        I should note I am using virtual IPs on both interfaces setup through CARP.

        This only applies to outbound traffic, inbound traffic in the WAN and WAN2 rrd is accurate. For some reason it looks like WAN RRD is inaccurate only for outbound traffic. If I were to disconnect WAN2 and drop all WAN2 traffic, WAN RRD shows only WAN traffic but it does show the big drop now that WAN2 is down and all traffic from WAN2 gets subtracted.

        Somehow, the data is conflicting but the routing is fine and everything else works as it's supposed to. I found a few bug reports in bugtracker about RRD graphs with outbound traffic and I am wondering if it's the same deal here.
        maybe it was fixed in a newer build? thanks all

        FJS - Embedded Systems Engineer
        Pictures are worth a thousand words, but <u>posting config.xml backups are worth 10,000</u>.  Alter the IPs, change anything revealing but leave subnets intact. Use find and replace. Please try to keep it brief on the description.
        ALWAYS disable TSO  & LRO EXCEPT CHKSUM IF SUPPORTED. TSO/LRO breaks traffic, pf scrub and this goes for any passive device inline

        1 Reply Last reply Reply Quote 0
        • F Offline
          FJSchrankJr
          last edited by

          another pfsense firewall we run with public IPs in a transparent bridge is showing WAN in traffic on the out traffic.

          RRD graph attached:

          ![status_rrd_graph_img (1).png](/public/imported_attachments/1/status_rrd_graph_img (1).png)
          ![status_rrd_graph_img (1).png_thumb](/public/imported_attachments/1/status_rrd_graph_img (1).png_thumb)

          FJS - Embedded Systems Engineer
          Pictures are worth a thousand words, but <u>posting config.xml backups are worth 10,000</u>.  Alter the IPs, change anything revealing but leave subnets intact. Use find and replace. Please try to keep it brief on the description.
          ALWAYS disable TSO  & LRO EXCEPT CHKSUM IF SUPPORTED. TSO/LRO breaks traffic, pf scrub and this goes for any passive device inline

          1 Reply Last reply Reply Quote 0
          • C Offline
            ccb056
            last edited by

            I am also having the same problem, 2 WAN facing interfaces (WAN and OPT1), rrd traffic graph for WAN shows WAN+OPT1 upload data.

            Is there a fix for this?

            Interesting that the dynamic traffic graph does not have a problem, only the rrd graphs.

            1 Reply Last reply Reply Quote 0
            • F Offline
              FJSchrankJr
              last edited by

              @ccb056:

              I am also having the same problem, 2 WAN facing interfaces (WAN and OPT1), rrd traffic graph for WAN shows WAN+OPT1 upload data.

              Is there a fix for this?

              Interesting that the dynamic traffic graph does not have a problem, only the rrd graphs.

              It's listed in the bug tracker and it might have been resolved in 2.0.1, traffic is not affected though and it only appears to happen in a multi-wan setup. I will check the bug tracker and let you know.

              FJS - Embedded Systems Engineer
              Pictures are worth a thousand words, but <u>posting config.xml backups are worth 10,000</u>.  Alter the IPs, change anything revealing but leave subnets intact. Use find and replace. Please try to keep it brief on the description.
              ALWAYS disable TSO  & LRO EXCEPT CHKSUM IF SUPPORTED. TSO/LRO breaks traffic, pf scrub and this goes for any passive device inline

              1 Reply Last reply Reply Quote 0
              • F Offline
                FJSchrankJr
                last edited by

                I checked the bug tracker but didn't see that it was resolved. I will take a look within the next few days and try to locate/fix the problem.

                It only happens on a multi-wan setup and the wan graphs also include traffic from the other wan interfaces. Is this what others are seeing? The more info you can provide the better. Thank you guys.

                FJS - Embedded Systems Engineer
                Pictures are worth a thousand words, but <u>posting config.xml backups are worth 10,000</u>.  Alter the IPs, change anything revealing but leave subnets intact. Use find and replace. Please try to keep it brief on the description.
                ALWAYS disable TSO  & LRO EXCEPT CHKSUM IF SUPPORTED. TSO/LRO breaks traffic, pf scrub and this goes for any passive device inline

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.