• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Incorrect bandwidth monitor values

Scheduled Pinned Locked Moved General pfSense Questions
40 Posts 2 Posters 3.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    stephenw10 Netgate Administrator
    last edited by May 24, 2022, 8:56 PM

    Hmm, do you see an outbound state for the openvpn traffic on vmx1?

    M 1 Reply Last reply May 24, 2022, 10:11 PM Reply Quote 0
    • M
      MindlessMavis @stephenw10
      last edited by May 24, 2022, 10:11 PM

      This post is deleted!
      1 Reply Last reply Reply Quote 0
      • S
        stephenw10 Netgate Administrator
        last edited by May 24, 2022, 10:29 PM

        Hmm, you could try something more radical like importing the config into a new VM and seeing if it's still replicated.

        M 1 Reply Last reply May 24, 2022, 10:45 PM Reply Quote 0
        • M
          MindlessMavis @stephenw10
          last edited by May 24, 2022, 10:45 PM

          This post is deleted!
          1 Reply Last reply Reply Quote 0
          • S
            stephenw10 Netgate Administrator
            last edited by May 25, 2022, 12:15 PM

            Mmm, I mean it looks like some values have been switched somehow such that pf is referencing the wrong interface(s). But if that was the case I would expect the policy routing and firewall rules to also be wrong. Also I've never seen that happen before and really I have no idea how it could!

            I could imagine the interfaces becomes switched, for example ovpnc2 is no longer the tunnel you think it is. Or the interfaces are re-ordered in vmware. But that would not account for traffic switching from vmx to ovpn.

            M 1 Reply Last reply May 25, 2022, 3:07 PM Reply Quote 0
            • M
              MindlessMavis @stephenw10
              last edited by May 25, 2022, 3:07 PM

              This post is deleted!
              1 Reply Last reply Reply Quote 0
              • S
                stephenw10 Netgate Administrator
                last edited by May 25, 2022, 3:55 PM

                You could create a new NIC on the same vswitch and then reassign WAN to that, vmx2 for example.

                pf has an interface for all OpenVPN traffic that is uses for firewall rules on unassigned interfaces. I wonder if somehow the ovpnc8 graph is pulling data from that. Though that would still include data from ovpnc9.

                For anything like that to happen it would have to very low level. I assume ifconfig still reports the correct number of interfaces with the correct names?

                Steve

                1 Reply Last reply Reply Quote 0
                • M
                  MindlessMavis
                  last edited by MindlessMavis May 26, 2022, 9:26 AM May 26, 2022, 9:24 AM

                  This post is deleted!
                  M 1 Reply Last reply May 26, 2022, 10:52 AM Reply Quote 0
                  • M
                    MindlessMavis @MindlessMavis
                    last edited by May 26, 2022, 10:52 AM

                    This post is deleted!
                    1 Reply Last reply Reply Quote 1
                    • S
                      stephenw10 Netgate Administrator
                      last edited by May 26, 2022, 1:08 PM

                      @hvr-lust said in Incorrect bandwidth monitor values:

                      PPROMISC

                      Hmm, that's.... interesting!

                      Is it in a bridge by any chance? Or are any of those interfaces in a bridge?

                      I wouldn't normally expect to see a TAP mode client in a bridge in that sort of setup but...

                      Steve

                      M 1 Reply Last reply May 26, 2022, 1:34 PM Reply Quote 0
                      • M
                        MindlessMavis @stephenw10
                        last edited by May 26, 2022, 1:34 PM

                        This post is deleted!
                        1 Reply Last reply Reply Quote 0
                        • S
                          stephenw10 Netgate Administrator
                          last edited by May 26, 2022, 1:34 PM

                          Mmm, it seems the interface is being used in some unexpected way to cause it to be flagged like that. This seems very likely to be related.

                          Steve

                          1 Reply Last reply Reply Quote 0
                          • S
                            stephenw10 Netgate Administrator
                            last edited by May 26, 2022, 1:36 PM

                            And the actual pfctl output shows that data on the wrong interfaces too?

                            1 Reply Last reply Reply Quote 0
                            • S
                              stephenw10 Netgate Administrator
                              last edited by May 26, 2022, 1:39 PM

                              It would be good to test a 2.7 snapshot if you can. There have been a lot of pf changes there recently. There's a good chance it will at least behave differently.

                              M 1 Reply Last reply May 26, 2022, 1:50 PM Reply Quote 0
                              • M
                                MindlessMavis @stephenw10
                                last edited by MindlessMavis May 26, 2022, 1:55 PM May 26, 2022, 1:50 PM

                                This post is deleted!
                                1 Reply Last reply Reply Quote 0
                                • S
                                  stephenw10 Netgate Administrator
                                  last edited by May 26, 2022, 2:03 PM

                                  Ok so to be clear you don't have any bridge interfaces?

                                  No TAP mode openvpn clients?

                                  Did your config include the RRD data? Definitely worth testing without it if so.

                                  Steve

                                  M 1 Reply Last reply May 26, 2022, 2:46 PM Reply Quote 0
                                  • M
                                    MindlessMavis @stephenw10
                                    last edited by May 26, 2022, 2:46 PM

                                    This post is deleted!
                                    M 1 Reply Last reply May 26, 2022, 3:12 PM Reply Quote 0
                                    • M
                                      MindlessMavis @MindlessMavis
                                      last edited by May 26, 2022, 3:12 PM

                                      This post is deleted!
                                      1 Reply Last reply Reply Quote 0
                                      • S
                                        stephenw10 Netgate Administrator
                                        last edited by May 26, 2022, 3:37 PM

                                        Is that a config from 2.4.5?

                                        SSH keys were not included in the config until 2.6. You can probably remove that section from the config to allow it restore.

                                        Steve

                                        1 Reply Last reply Reply Quote 0
                                        • M
                                          MindlessMavis
                                          last edited by May 26, 2022, 6:30 PM

                                          This post is deleted!
                                          1 Reply Last reply Reply Quote 0
                                          40 out of 40
                                          • First post
                                            40/40
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received