Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Some traffic is escaping from vpn!

    Scheduled Pinned Locked Moved General pfSense Questions
    14 Posts 6 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • PippinP
      Pippin
      last edited by

      IIRC all traffic from the firewall itself will go out WAN.
      Check for updates, NTP, Unbound, etc.

      I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
      Halton Arp

      M 1 Reply Last reply Reply Quote 0
      • M
        moxi @Cool_Corona
        last edited by

        @Cool_Corona hi, what do you suggest me to use for this? Thanks!

        1 Reply Last reply Reply Quote 0
        • M
          moxi @chpalmer
          last edited by moxi

          @chpalmer hi, it is the case. Clients are using this gateway as their primary dns server. But the traffic delta is enormous for just dns usage: currently wan used 750 mb out, vpn only 375mb out. Thanks!

          1 Reply Last reply Reply Quote 0
          • M
            moxi @Pippin
            last edited by

            @Pippin everything is up to date and looks running well.

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              Even in a perfect setup with the default gateway on the VPN, the WAN usage would always be higher due to a couple factors:

              • The WAN gateway monitoring traffic (if enabled) will still go straight out WAN since it has a static route out that way
              • The VPN control channel traffic (establishing the tunnel, key management, keep alive, internal pings, etc) still goes over WAN, and it is not tunneled data so it does not count against the VPN interface
              • VPN encapsulation and padding means that packets which carry VPN traffic must always be larger than the packets being carried across the VPN. At least enough for an extra set of headers, plus the data is encrypted so it will be larger than the original data. (Compression gets tricky here but nobody should be using VPN data compression since it's insecure)

              So unless you know for sure that a specific packet/connection/whatever is bypassing the VPN, it's probably normal.

              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              M 1 Reply Last reply Reply Quote 2
              • M
                moxi @jimp
                last edited by moxi

                @jimp

                • The WAN gateway monitoring traffic (if enabled). How to Disable it?
                • VPN encapsulation and padding means... How to make sure the carriers are larger the carried packets? and How to disable compression?
                • The VPN control channel traffic... I guess can't do nothing about this one?

                Thanks!!

                jimpJ 1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate @moxi
                  last edited by

                  @moxi said in Some traffic is escaping from vpn!:

                  @jimp

                  • The WAN gateway monitoring traffic (if enabled). How to Disable it?

                  System > Routing, edit the gateway, check Disable Gateway Monitoring

                  • VPN encapsulation and padding means... How to make sure the carriers are larger the carried packets? and How to disable compression?

                  Edit the VPN, set either "Disable compression, retain compression packet framing" or "Omit Preference".

                  • The VPN control channel traffic... I guess can't do nothing about this one?

                  No, and you shouldn't care about it either -- any tunneled protocol will have overhead like that, and any encrypted traffic will have it as well. It's not "leaking" anything, it's just a natural part of the process.

                  Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    moxi @jimp
                    last edited by moxi

                    @jimp the traffic going through the lan is almost the double of the one going through the vpm, aftercrunning for days. Seriously, if a moderator answers me that I should not care, I would start thinking that this whole game of privacy protection is not 100% legit. Specially after experiencing the new pfblockerng (maxmind) which is doing everything to get our daya and which impossible to remove unless we format the drive...

                    1 Reply Last reply Reply Quote 0
                    • jimpJ
                      jimp Rebel Alliance Developer Netgate
                      last edited by

                      I said you shouldn't care about VPN overhead specifically -- control traffic, encryption overhead, internal monitoring.

                      If you suspect traffic is not going the way you want, then run packet captures and check. Odds are it's not what you think it is, but that's the good thing about running something like pfSense: You can look for yourself.

                      Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        moxi @jimp
                        last edited by

                        This post is deleted!
                        1 Reply Last reply Reply Quote 0
                        • GertjanG
                          Gertjan
                          last edited by

                          @moxi said in Some traffic is escaping from vpn!:

                          but why the firewall rule of: ( block any out on wan) never works?

                          Can you show that rule (an image ;) )?
                          Where did you put that rule ?

                          A final solution will be : use the VPN client on the device where you use the VPN. That is, if that device isn't a TV set or something like that.

                          @moxi said in Some traffic is escaping from vpn!:

                          I would start thinking that this whole game of privacy protection is not 100% legit

                          You start to understand. There is hope for you.
                          You really believed the VPN publicity ??

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.