Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WireGuard VPN: Traffic graph shows occasional blips, confirmed by netstat -I, but tcpdump doesn't capture anything

    Scheduled Pinned Locked Moved General pfSense Questions
    3 Posts 2 Posters 54 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      ChrisJenk
      last edited by

      I have a permanent site-to site WireGuard VPN connection which is up 24x365. It is working fine.

      Often the connection is idle and during these periods the pfSense Traffic Graph for the WGUARD interface (the VPN interface) shows occasional small blips of incoming traffic (nothing outgoing). netstat -I confirms that there was a packet or two received but tcpdump running on the interface (tun_wg1) shows absolutely nothing. When there is genuine traffic tcpdump captures it just fine.

      I'm curious to know what these occasional phantom inbound packets might be...

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        Try capturing the encapsulated traffic on the parent interface. You could be seeing traffic that's dropped before it makes it out of the WG interface. I wouldn't expect it to be an issue though.

        C 1 Reply Last reply Reply Quote 0
        • C Offline
          ChrisJenk @stephenw10
          last edited by

          @stephenw10 Thanks. I monitored the WireGuard traffic on the underlying interface at the same time and sure enough every 15 seconds the remote peer sends a 32 byte UDP packet. This ties up with the client's setting 'PersistentKeepalive = 15' so it is just the keep alive traffic. Mystery solved.

          1 Reply Last reply Reply Quote 1
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.