Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SOLVED Traffic on WAN interface only

    Scheduled Pinned Locked Moved General pfSense Questions
    17 Posts 4 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      State not cleared from the firewall?

      Steve

      1 Reply Last reply Reply Quote 0
      • G
        G.D. Wusser Esq.
        last edited by

        UDP - no state. Most of the packets get blocked, just a few single ones get through…

        I am going to restart the box for good measure, and test again, though.

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Ha! good point.  ::)

          1 Reply Last reply Reply Quote 0
          • G
            G.D. Wusser Esq.
            last edited by

            I rebooted the pfSense and the packet leak has stopped. Hmmm…

            1 Reply Last reply Reply Quote 0
            • K
              kejianshi
              last edited by

              I'd be looking for malware on my network.  I doubt seriously its a pfsense problem.

              1 Reply Last reply Reply Quote 0
              • G
                G.D. Wusser Esq.
                last edited by

                It is smells like a reflected attack, not amplified though, since the packets in and out are the same size. I stopped the attack at the firewall level.

                I think there is an issue with pfSense traffic graph, the traffic does not add up. I think it shows exactly double outgoing the traffic for local interfaces. I am still investigating, this will take more time to accumulate the data from different network segments and add it all up.

                1 Reply Last reply Reply Quote 0
                • G
                  G.D. Wusser Esq.
                  last edited by

                  Found this: https://forum.pfsense.org/index.php?topic=67295.0

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Check the forum. There are a number of threads about double counting on the traffic graphs. I've never seen it though, it seems to happen only under specific conditions.

                    Ah, typed too slow! Yep that's one of them.

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • K
                      kejianshi
                      last edited by

                      Yep - Sometimes pfsense reports traffic bandwidthh incorrectly, which is much less troubling than having a bunch of phantom traffic.

                      1 Reply Last reply Reply Quote 0
                      • G
                        G.D. Wusser Esq.
                        last edited by

                        Thanks for your help everybody. This was a compound issue, and it looks like everything has been explained now. I appreciate the help.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.