Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Traffic Graph for LAN and WAN showing outside IP Addresses

    2.1 Snapshot Feedback and Problems - RETIRED
    9
    37
    17.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dhatz
      last edited by

      I just noticed some "stale" Host IPs in the traffic-graph table.

      In the screen I have in front of me right now, among others it (wrongly) shows outbound traffic to 4 different IPs. These IPs belong to a local web-portal (CDN) and I connected to those 4 IPs about 15' ago, but the related states have expired (according to pfctl -ss).

      1 Reply Last reply Reply Quote 0
      • P
        phil.davis
        last edited by

        I noticed that every now and then also. It happens when the table length reduces by more than 1 row between 1 update and the next. Seems to be a "feature" that has been in the code from day one. I believe this will fix it: https://github.com/bsdperimeter/pfsense/pull/469

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • J
          jits
          last edited by

          Hi Guys,

          Thanks very much for the fix. I updated via Git, but I noticed something else now…See picture attached...

          WAN is selected..the graph is correct, however under the headings of Bandwidth IN and Bandwidth OUT, they don't match the graph. Bw OUT should be Bw IN and vice versa, if I'm correct.

          Thanks.

          ![After Git Update. Traffic Graph..png](/public/imported_attachments/1/After Git Update. Traffic Graph..png)
          ![After Git Update. Traffic Graph..png_thumb](/public/imported_attachments/1/After Git Update. Traffic Graph..png_thumb)

          1 Reply Last reply Reply Quote 0
          • P
            phil.davis
            last edited by

            Now the bandwidth by IP table shows the data flowing with respect to addresses that are at both the external and internal ends of the network. So the column headings do not work either way round. For example, the screenshot shows me doing a download - the In and Out columns have the opposite figures with respect to the local machine and the server on the internet.
            The column headings could be "Bandwidth From" and "Bandwidth To".
            Any better suggestions for headings?

            Traffic-Graph.png
            Traffic-Graph.png_thumb

            As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
            If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

            1 Reply Last reply Reply Quote 0
            • J
              jits
              last edited by

              HI Phil,

              As you can see from the attached, the bandwidth indicators are correct for ALL WAN and LOCAL LAN, but when ALL LAN is selected and LOCAL WAN, the bandwidth usage indicators are reversed and are not in sync with the graph.

              Gifs attached, Just ignore me if I'm getting too "German" about the way things are displayed.

              Thanks, Jits.

              ![Traffic Graph LAN ALL Not sure.gif](/public/imported_attachments/1/Traffic Graph LAN ALL Not sure.gif)
              ![Traffic Graph LAN ALL Not sure.gif_thumb](/public/imported_attachments/1/Traffic Graph LAN ALL Not sure.gif_thumb)
              ![Traffic Graph Correct for LOCAL LAN.gif](/public/imported_attachments/1/Traffic Graph Correct for LOCAL LAN.gif)
              ![Traffic Graph Correct for LOCAL LAN.gif_thumb](/public/imported_attachments/1/Traffic Graph Correct for LOCAL LAN.gif_thumb)
              ![Traffic Graph Correct for ALL WAN.gif](/public/imported_attachments/1/Traffic Graph Correct for ALL WAN.gif)
              ![Traffic Graph Correct for ALL WAN.gif_thumb](/public/imported_attachments/1/Traffic Graph Correct for ALL WAN.gif_thumb)
              ![Traffic Graphing indicators.gif](/public/imported_attachments/1/Traffic Graphing indicators.gif)
              ![Traffic Graphing indicators.gif_thumb](/public/imported_attachments/1/Traffic Graphing indicators.gif_thumb)

              1 Reply Last reply Reply Quote 0
              • P
                phil.davis
                last edited by

                @jits - I work with a few Germans, so I have learnt to cope with their OCD ways ;) In the programming business OCD is good.
                I think this pull request will fix up the In/Out confusion - https://github.com/bsdperimeter/pfsense/pull/477
                The table is actually showing BW from and to each IP address listed. The meaning of In/Out flips depending on which side of the interface the IP is. So From/To are better column labels.

                As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                1 Reply Last reply Reply Quote 0
                • ?
                  Guest
                  last edited by

                  Just updated today, I did wonder why all the external ip addresses and hostnames are showing up now, very strange.

                  I do like that we can select hostnames though.

                  Is a fix coming?

                  thanks

                  1 Reply Last reply Reply Quote 0
                  • J
                    jcyr
                    last edited by

                    The fix is already comitted, but there hasn't been a snapshot build for a few days now. In the meantime, while we wait for the snapshot builds to resume, you can use gitsync to get it.

                    IPV6 Test: http://ipv6-test.com

                    1 Reply Last reply Reply Quote 0
                    • X
                      xbipin
                      last edited by

                      after the march 1st snaps im not able to see any ip address in list

                      CropperCapture[1].jpg
                      CropperCapture[1].jpg_thumb

                      1 Reply Last reply Reply Quote 0
                      • P
                        phil.davis
                        last edited by

                        I just upgraded to 2.1-BETA1 (i386) built on Mon Mar 11 08:59:46 EDT 2013 and it seems fine for me. The "rate" utility that generates the bandwidth by IP data just does a quick sample of the traffic. When the bandwidth is very low, it is quite easy for the short sample to not get much of a decent "average", or to see nothing much at all. Start something downloading for real and you should see it clearly.

                        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                        1 Reply Last reply Reply Quote 0
                        • X
                          xbipin
                          last edited by

                          i tried on another machine same latest snap and that one shows so how can one machine show the ips and the other not, what could be wrong?

                          1 Reply Last reply Reply Quote 0
                          • ?
                            Guest
                            last edited by

                            It works in the newest updated. But it isn't as simple to use as before.

                            I wish it would default to the previous configuration, and if you want to see external IPs then select that.

                            Listing a bzillion external IPs/hostnames coming and going isn't that visually helpful as it changes so fast.

                            1 Reply Last reply Reply Quote 0
                            • P
                              phil.davis
                              last edited by

                              I believe ermal is going to work on the In/Out sides of the display, so that the numbers for both local and remote IPs will match the In/Out convention of the graph.
                              The default for the table could easily be changed to "Filter: Local" - maybe people could give votes here for what they would prefer as the defaults? or a "Save" button could be put on the page that would save the current settings to the config and it would load those when it starts (more effort for that)?

                              As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                              If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                              1 Reply Last reply Reply Quote 0
                              • X
                                xbipin
                                last edited by

                                the table that shows in/out the ips just come and go too fast and if ur specifically monitoring a few local ips then they keep jumping up and down so y not simply keep the ip list static, meaning as soon as there is traffic from some ip, list it permanently and then just keep refreshing its in/out packets and suppose this ip stop communication for like 30 seconds then remove it from list

                                1 Reply Last reply Reply Quote 0
                                • ?
                                  Guest
                                  last edited by

                                  Does it make sense that external IPs/host names are displayed, especially when LAN interface is selected?

                                  1 Reply Last reply Reply Quote 0
                                  • I
                                    ingmthompson
                                    last edited by

                                    This same issue is present in PRERELEASE builds of 2.0.3 (see http://forum.pfsense.org/index.php/topic,58203.msg324782.html#msg324782). I note a few commits have been made to the master branch in response to this issue, although I'm not quite able to follow what is what. If any of these commits fix the original issue, can they be backported to RELENG_2_0 before 2.0.3 gets released?

                                    1 Reply Last reply Reply Quote 0
                                    • E
                                      eri--
                                      last edited by

                                      I fixed so it accounts properly for the local subnet without showing the not local ips.

                                      1 Reply Last reply Reply Quote 0
                                      • P
                                        phil.davis
                                        last edited by

                                        The "rate" utility is now back to the old behaviour, only showing local/internal IP addresses and is good for releasing 2.0.3. Whatever happens next, we need to be careful not to mess up the 2.0.n behaviour.
                                        With no remote addresses returned by "rate", the "Filter: All/Local/Remote" box on the GUI is no longer useful/relevant.
                                        I actually liked being able to see the external IP addresses. Combined with the option to display the FQDN (of IPs that have a reverse-lookup available) it often meant that I could quickly see what site a big BW user is downloading from. Of course it doesn't always work - if the IP has no reverse lookup then you have to do some work yourself on the raw IP if you want to get an idea what it is. The "Filter" option lets you suppress this output if you wish.
                                        It would be easy enough to make "rate" take an extra parameter to make it spit out external IPs also. Then that could be invoked from the 2.1 code and not break the 2.0.n behaviour.
                                        What do others think? Do you think having the external IP display option is useful?

                                        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                                        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                                        1 Reply Last reply Reply Quote 0
                                        • J
                                          jcyr
                                          last edited by

                                          Why not let the user choose his preferred display mode by remembering the last chosen selection and using it by default until a different one is chosen.

                                          IPV6 Test: http://ipv6-test.com

                                          1 Reply Last reply Reply Quote 0
                                          • P
                                            phil.davis
                                            last edited by

                                            @jcyr:

                                            Why not let the user choose his preferred display mode by remembering the last chosen selection and using it by default until a different one is chosen.

                                            That requires a config write, which would not be ideal to do every time the user changes one of the dropdown selections. Adding a "Save Settings" button is probably the way to go.

                                            As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                                            If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.