Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Some traffic is escaping from vpn!

    Scheduled Pinned Locked Moved General pfSense Questions
    14 Posts 6 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      moxi @Cool_Corona
      last edited by

      @Cool_Corona hi, what do you suggest me to use for this? Thanks!

      1 Reply Last reply Reply Quote 0
      • M
        moxi @chpalmer
        last edited by moxi

        @chpalmer hi, it is the case. Clients are using this gateway as their primary dns server. But the traffic delta is enormous for just dns usage: currently wan used 750 mb out, vpn only 375mb out. Thanks!

        1 Reply Last reply Reply Quote 0
        • M
          moxi @Pippin
          last edited by

          @Pippin everything is up to date and looks running well.

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            Even in a perfect setup with the default gateway on the VPN, the WAN usage would always be higher due to a couple factors:

            • The WAN gateway monitoring traffic (if enabled) will still go straight out WAN since it has a static route out that way
            • The VPN control channel traffic (establishing the tunnel, key management, keep alive, internal pings, etc) still goes over WAN, and it is not tunneled data so it does not count against the VPN interface
            • VPN encapsulation and padding means that packets which carry VPN traffic must always be larger than the packets being carried across the VPN. At least enough for an extra set of headers, plus the data is encrypted so it will be larger than the original data. (Compression gets tricky here but nobody should be using VPN data compression since it's insecure)

            So unless you know for sure that a specific packet/connection/whatever is bypassing the VPN, it's probably normal.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            M 1 Reply Last reply Reply Quote 2
            • M
              moxi @jimp
              last edited by moxi

              @jimp

              • The WAN gateway monitoring traffic (if enabled). How to Disable it?
              • VPN encapsulation and padding means... How to make sure the carriers are larger the carried packets? and How to disable compression?
              • The VPN control channel traffic... I guess can't do nothing about this one?

              Thanks!!

              jimpJ 1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate @moxi
                last edited by

                @moxi said in Some traffic is escaping from vpn!:

                @jimp

                • The WAN gateway monitoring traffic (if enabled). How to Disable it?

                System > Routing, edit the gateway, check Disable Gateway Monitoring

                • VPN encapsulation and padding means... How to make sure the carriers are larger the carried packets? and How to disable compression?

                Edit the VPN, set either "Disable compression, retain compression packet framing" or "Omit Preference".

                • The VPN control channel traffic... I guess can't do nothing about this one?

                No, and you shouldn't care about it either -- any tunneled protocol will have overhead like that, and any encrypted traffic will have it as well. It's not "leaking" anything, it's just a natural part of the process.

                Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                M 1 Reply Last reply Reply Quote 0
                • M
                  moxi @jimp
                  last edited by moxi

                  @jimp the traffic going through the lan is almost the double of the one going through the vpm, aftercrunning for days. Seriously, if a moderator answers me that I should not care, I would start thinking that this whole game of privacy protection is not 100% legit. Specially after experiencing the new pfblockerng (maxmind) which is doing everything to get our daya and which impossible to remove unless we format the drive...

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    I said you shouldn't care about VPN overhead specifically -- control traffic, encryption overhead, internal monitoring.

                    If you suspect traffic is not going the way you want, then run packet captures and check. Odds are it's not what you think it is, but that's the good thing about running something like pfSense: You can look for yourself.

                    Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      moxi @jimp
                      last edited by

                      This post is deleted!
                      1 Reply Last reply Reply Quote 0
                      • GertjanG
                        Gertjan
                        last edited by

                        @moxi said in Some traffic is escaping from vpn!:

                        but why the firewall rule of: ( block any out on wan) never works?

                        Can you show that rule (an image ;) )?
                        Where did you put that rule ?

                        A final solution will be : use the VPN client on the device where you use the VPN. That is, if that device isn't a TV set or something like that.

                        @moxi said in Some traffic is escaping from vpn!:

                        I would start thinking that this whole game of privacy protection is not 100% legit

                        You start to understand. There is hope for you.
                        You really believed the VPN publicity ??

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.