Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [SOLVED] Traffic graph weirdness

    Scheduled Pinned Locked Moved 2.4 Development Snapshots
    26 Posts 7 Posters 4.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      PiBa
      last edited by

      Looks fine for me. see attachment.. Not sure why your graph would be that different..

      While downloading does iftop show your same double bandwidth for the connection on lan side?
      Does tcpdump show any 'extra' traffic? Is everything re-transmitted?

      Is it virtual? Bridged? Lacp? Or anything else 'special'?

      ![2017-08-01 20_48_48-Status_ Dashboard - pfSe.localdomain.png](/public/imported_attachments/1/2017-08-01 20_48_48-Status_ Dashboard - pfSe.localdomain.png)
      ![2017-08-01 20_48_48-Status_ Dashboard - pfSe.localdomain.png_thumb](/public/imported_attachments/1/2017-08-01 20_48_48-Status_ Dashboard - pfSe.localdomain.png_thumb)

      1 Reply Last reply Reply Quote 0
      • M
        maverick_slo
        last edited by

        Hi.
        Nothing special but I think only http traffic is counted like this, need to confirm that first.
        No bridge or lacp, just vlans and thats it.

        1 Reply Last reply Reply Quote 0
        • M
          maverick_slo
          last edited by

          OK.
          So…
          No retransmissions.
          All traffic affected.
          Iftop shows correct data
          Traffic graph is wrong.
          Tried 3 browsers same thing.
          Ipv6 and IPv4 are both affected
          Tried with 4 machines on LAN
          Only DOWNLOAD is affected, upload from LAN to WAN displays correct data.

          WTF :)

          iftop.PNG
          iftop.PNG_thumb
          iftop2.PNG
          iftop2.PNG_thumb
          iftop3.PNG
          iftop3.PNG_thumb

          1 Reply Last reply Reply Quote 0
          • M
            maverick_slo
            last edited by

            It seems that only "out" is affected.
            That`s weird.

            iftop4.PNG
            iftop4.PNG_thumb

            1 Reply Last reply Reply Quote 0
            • H
              Harvy66
              last edited by

              Are you using VLANs?

              1 Reply Last reply Reply Quote 0
              • M
                maverick_slo
                last edited by

                post no. 3
                yes

                1 Reply Last reply Reply Quote 0
                • H
                  Harvy66
                  last edited by

                  Do you have any untagged VLANs on that physical network interface?

                  1 Reply Last reply Reply Quote 0
                  • M
                    maverick_slo
                    last edited by

                    nope, all 4 tagged

                    1 Reply Last reply Reply Quote 0
                    • S
                      scott83
                      last edited by

                      I'm running 2.4.0.b.20170802.1526 and I'm in the same boat, my tagged VLAN interface out is showing double of my WAN in. I also verified using iftop that the VLAN interface is not showing double, only the traffic graph does. I also have 4 tagged VLANs on that interface and no untagged VLANs.

                      1 Reply Last reply Reply Quote 0
                      • jahonixJ
                        jahonix
                        last edited by

                        Double-quoted traffic on VLAN interfaces was a problem in the past but solved (about a year or so ago).
                        Seems to be newly featured on Github again. Report on Redmine!

                        1 Reply Last reply Reply Quote 0
                        • M
                          maverick_slo
                          last edited by

                          done
                          https://redmine.pfsense.org/issues/7751

                          1 Reply Last reply Reply Quote 0
                          • M
                            maverick_slo
                            last edited by

                            Hi!

                            Any idea if this is pfsense bug or upstream?
                            I would really like this to be resolved in 2.4…

                            1 Reply Last reply Reply Quote 0
                            • P
                              PiBa
                              last edited by

                              Maybe you could install "nload" on ssh/console?

                              pkg add http://pkg.freebsd.org/freebsd:11:x86:64/latest/All/nload-0.7.4_1.txz
                              
                              

                              Start it use arrows to switch to desired nic/vlan and compare with traffic graphs.

                              It should pull statistics from sysctl just like pfSense.. And if also wrong then points a little to freebsd.
                              Though i suppose it could still be a issue introduced by pfSense's changes somewhere..

                              1 Reply Last reply Reply Quote 0
                              • M
                                maverick_slo
                                last edited by

                                Hehe :)
                                So here we go, guess pfsense bug after all….

                                Untitled.png
                                Untitled.png_thumb

                                1 Reply Last reply Reply Quote 0
                                • P
                                  PiBa
                                  last edited by

                                  Oké i guess its still not 100% definitive…

                                  Pfsense calls sysctl with:

                                  CTL_NET, PF_LINK, NETLINK_GENERIC, IFMIB_IFDATA, {ifidx}, IFDATA_GENERAL
                                  

                                  Where it retrieves the data: bytes, packets, collisions, multicasts, mtu
                                  https://github.com/pfsense/FreeBSD-ports/blob/devel/devel/php56-pfSense-module/files/pfSense.c#L3210

                                  While nload calls sysctl with:

                                  CTL_NET, PF_ROUTE, 0, 0, NET_RT_IFLIST, 0
                                  

                                  Where it retrieves the data: bytes, packets, errors
                                  https://github.com/liuyang1/nload/blob/master/src/devreader-bsd.cpp#L108

                                  So its similar but not the same, and that might be for a good reason. I'm not exactly sure.. Though i guess most of those extra data items are not needed for traffic graphs..

                                  1 Reply Last reply Reply Quote 0
                                  • M
                                    maverick_slo
                                    last edited by

                                    Jarred is on the case 😁
                                    Maybe just fewer flags and thats it.

                                    1 Reply Last reply Reply Quote 0
                                    • jdillardJ
                                      jdillard
                                      last edited by

                                      I think this is the issue jahonix was referring to: https://redmine.pfsense.org/issues/3314

                                      If that's the case someone else might pick up the ticket, but for now I'll try and find the commit with the patch.

                                      edit: I tried running:

                                      git log --since "MAY 18 2015" --until "MAY 20 2015" --pretty=format:"%Cred%h%Creset -%C(yellow)%d%Creset %s %Cgreen(%ad) %C(bold blue)<%an>%Creset"
                                      

                                      on the following repos:

                                      
                                      pfsense/pfsense
                                      pfsense/FreeBSD-ports
                                      pfsense/FreeBSD-src
                                      
                                      

                                      without any luck finding the patch so far. I may have accidentally missed it or be taking the wrong approach.

                                      1 Reply Last reply Reply Quote 0
                                      • P
                                        PiBa
                                        last edited by

                                        Found it: https://github.com/pfsense/pfsense-tools/commit/ad55e66a3fb817f8e54bae7bf38306039b82e3ad

                                        Or: https://github.com/pfsense/FreeBSD-src/commit/939f11b196e7d22a1ce3da8533e97ff3e92510b6#diff-437f2b0c100f75faf75f7c5b60eca6a4R1156

                                        1 Reply Last reply Reply Quote 0
                                        • P
                                          PiBa
                                          last edited by

                                          2.3:

                                           			ifp->if_opackets++;
                                           			//ifp->if_omcasts += mcast;
                                           			//ifp->if_obytes += len;
                                          

                                          2.4:

                                          			if_inc_counter(ifp, IFCOUNTER_OPACKETS, 1);
                                          			if_inc_counter(ifp, IFCOUNTER_OBYTES, len);
                                          			if_inc_counter(ifp, IFCOUNTER_OMCASTS, mcast);
                                          

                                          In 2.4 it looks different.. probably needs some // as well.. https://github.com/pfsense/FreeBSD-src/blob/RELENG_2_4/sys/net/if_vlan.c#L1132

                                          1 Reply Last reply Reply Quote 0
                                          • jahonixJ
                                            jahonix
                                            last edited by

                                            I love this kind of collaboration, really great!

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.