Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Traffic graphs completely broken when Snort and limiters used

    Scheduled Pinned Locked Moved webGUI
    5 Posts 2 Posters 682 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      stepanov1975
      last edited by

      After I installed Snort package Traffic graphs showing strange values not correlated with actual traffic. I also have limiters configured and I think that a combination of limiters and Snorts break the Traffic graphs

      bmeeksB 1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks @stepanov1975
        last edited by bmeeks

        @stepanov1975 said in Traffic graphs completely broken when Snort and limiters used:

        After I installed Snort package Traffic graphs showing strange values not correlated with actual traffic. I also have limiters configured and I think that a combination of limiters and Snorts break the Traffic graphs

        Specifically it's the Inline IPS Mode, when used, that breaks limiters and the traffic graph. It is due to the use of the netmap kernel device by Snort when you enable Inline IPS Mode. The netmap device is not compatible with the other features. I'm assuming in this reply you have enabled the Inline IPS Mode with Snort. The Legacy Blocking Mode should not impact limiters or the traffic graph.

        S 1 Reply Last reply Reply Quote 1
        • S
          stepanov1975 @bmeeks
          last edited by

          @bmeeks Thanks for the replay. But in my case "Block Offenders" not enabled at all.

          bmeeksB 1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks @stepanov1975
            last edited by

            @stepanov1975 said in Traffic graphs completely broken when Snort and limiters used:

            @bmeeks Thanks for the replay. But in my case "Block Offenders" not enabled at all.

            With blocking not enbled, then I really don't see how Snort can interfere. All it does is get copies of packets as they leave the NIC driver using libpcap (before the firewall sees them for traffic inbound on an interface; and after the firewall for traffic outbound on an interface).

            S 1 Reply Last reply Reply Quote 0
            • S
              stepanov1975 @bmeeks
              last edited by

              @bmeeks Sorry. I am an idiot :( I expected graphs to be in bits, but they were in bytes. Actually they works just fine

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.