Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Sarg and Light squid do not see VPN and TOR

    Scheduled Pinned Locked Moved Traffic Monitoring
    6 Posts 5 Posters 2.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dgall
      last edited by

      Yesterday I decided to do some tests with Traffic monitoring and ran a tor browser and a vpn all day on a couple of computers and at the end of the day Sarg reports and Light Squid did not show traffic from the VPN or Tor browser not even an IP Address but it showed everything else that used bandwidth. What did I configure wrong and what would be the best way to see the traffic flow from an anonymous browser. Dave

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        Sarg and Lightsquid report on the usage of the Squid web proxy.  That's all.  If you want to monitor overall bandwidth then use bandwidthd, ntopng or darkstat.

        1 Reply Last reply Reply Quote 0
        • D
          dgall
          last edited by

          I am now also using spideroak one for backing up to the cloud it is encrypted and the the traffic graph and ntopng show it using bandwidth ntopng also shows the ip address of spideroak but light squid or sarg show it in the logs. How can something upload 50 gigabytes and it not show up in any logs ?

          1 Reply Last reply Reply Quote 0
          • J
            JuantonJohn
            last edited by

            https traffic is not picked up / logged by squid unless you're doing man in the middle / certs.

            1 Reply Last reply Reply Quote 0
            • H
              hvac14400
              last edited by

              @JuantonJohn:

              https traffic is not picked up / logged by squid unless you're doing man in the middle / certs.

              but what if we for example don't need to analyze https traff qualitatively - only quantitatively, so there is no need to decipher it? then why the F squid can't just count bytes he redirects from client to web server?

              is there any patches for squid to resolve this?
              is it possible at all?

              anyone?

              1 Reply Last reply Reply Quote 0
              • M
                mrbrax
                last edited by

                @hvac14400:

                @JuantonJohn:

                https traffic is not picked up / logged by squid unless you're doing man in the middle / certs.

                but what if we for example don't need to analyze https traff qualitatively - only quantitatively, so there is no need to decipher it? then why the F squid can't just count bytes he redirects from client to web server?

                is there any patches for squid to resolve this?
                is it possible at all?

                anyone?

                Squid only logs what's sent to it. ntopng does pick up what you want, but it has poor historical data management.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.