Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Assimetric Bandwidth usage WAN - LAN

    Scheduled Pinned Locked Moved Traffic Monitoring
    12 Posts 5 Posters 3.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • jimpJ Offline
      jimp Rebel Alliance Developer Netgate
      last edited by

      That would indicate it's the firewall itself using the bandwidth in some way. I'd look at packages you have installed. If you have squid, that is likely the culprit.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • A Offline
        Aburger
        last edited by

        Will NAT also cause this? I have the same issue that happens when I turn on NAT

        1 Reply Last reply Reply Quote 0
        • jimpJ Offline
          jimp Rebel Alliance Developer Netgate
          last edited by

          No.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • P Offline
            ploquets
            last edited by

            @Aburger:

            Will NAT also cause this? I have the same issue that happens when I turn on NAT

            YES, we do use Squid…. how to monitor traffic by IP ? inside Squid ?

            1 Reply Last reply Reply Quote 0
            • M Offline
              m4kin
              last edited by

              @jimp:

              No.

              My Squid is doing the same thing, he uses 90mb/s and the lan is using 20 mb/s.
              If I turn squid off… the consume goes down... and normalizes... if I turn it on... goes up again.

              Any tips of what to do?

              1 Reply Last reply Reply Quote 0
              • P Offline
                ploquets
                last edited by

                @jimp:

                That would indicate it's the firewall itself using the bandwidth in some way. I'd look at packages you have installed. If you have squid, that is likely the culprit.

                But…. even using Squid, it should show traffic, from firewall (where squid is installed, going out thru the LAN interface) to the cliente.

                Squid is caching content, but, traffic will also be send to the client host? no ?

                This is really weird, unless the firewall itself is using, to make an update or something like that, it should show on traffic LAN interface graph.

                1 Reply Last reply Reply Quote 0
                • jimpJ Offline
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  Squid can sometimes pull data back into its cache to revalidate and such without delivering that to clients. The specifics have fallen out of my brain but it's not unusual. Especially if you have squid caching things like windows updates or other large files.

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • M Offline
                    m4kin
                    last edited by

                    Even if I turn off the squid cache?

                    1 Reply Last reply Reply Quote 0
                    • jimpJ Offline
                      jimp Rebel Alliance Developer Netgate
                      last edited by

                      That would be a question for the proxy board.

                      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      1 Reply Last reply Reply Quote 0
                      • M Offline
                        m4kin
                        last edited by

                        With my squid turned off, just the traffic graph, continue showing this strange thing.;

                        1 Reply Last reply Reply Quote 0
                        • C Offline
                          cmb
                          last edited by

                          You'll need to packet capture on WAN and see what that traffic is. Squid is a good guess where you're running it, but it could be any number of things, including traffic you're not soliciting (like a DoS of some sort).

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.