Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Assimetric Bandwidth usage WAN - LAN

    Scheduled Pinned Locked Moved Traffic Monitoring
    12 Posts 5 Posters 3.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      Aburger
      last edited by

      Will NAT also cause this? I have the same issue that happens when I turn on NAT

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        No.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • P Offline
          ploquets
          last edited by

          @Aburger:

          Will NAT also cause this? I have the same issue that happens when I turn on NAT

          YES, we do use Squid…. how to monitor traffic by IP ? inside Squid ?

          1 Reply Last reply Reply Quote 0
          • M Offline
            m4kin
            last edited by

            @jimp:

            No.

            My Squid is doing the same thing, he uses 90mb/s and the lan is using 20 mb/s.
            If I turn squid off… the consume goes down... and normalizes... if I turn it on... goes up again.

            Any tips of what to do?

            1 Reply Last reply Reply Quote 0
            • P Offline
              ploquets
              last edited by

              @jimp:

              That would indicate it's the firewall itself using the bandwidth in some way. I'd look at packages you have installed. If you have squid, that is likely the culprit.

              But…. even using Squid, it should show traffic, from firewall (where squid is installed, going out thru the LAN interface) to the cliente.

              Squid is caching content, but, traffic will also be send to the client host? no ?

              This is really weird, unless the firewall itself is using, to make an update or something like that, it should show on traffic LAN interface graph.

              1 Reply Last reply Reply Quote 0
              • jimpJ Offline
                jimp Rebel Alliance Developer Netgate
                last edited by

                Squid can sometimes pull data back into its cache to revalidate and such without delivering that to clients. The specifics have fallen out of my brain but it's not unusual. Especially if you have squid caching things like windows updates or other large files.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • M Offline
                  m4kin
                  last edited by

                  Even if I turn off the squid cache?

                  1 Reply Last reply Reply Quote 0
                  • jimpJ Offline
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    That would be a question for the proxy board.

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • M Offline
                      m4kin
                      last edited by

                      With my squid turned off, just the traffic graph, continue showing this strange thing.;

                      1 Reply Last reply Reply Quote 0
                      • C Offline
                        cmb
                        last edited by

                        You'll need to packet capture on WAN and see what that traffic is. Squid is a good guess where you're running it, but it could be any number of things, including traffic you're not soliciting (like a DoS of some sort).

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.