Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Crazy Graphs?

    Scheduled Pinned Locked Moved General pfSense Questions
    8 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      burdandrei
      last edited by

      Hi, i got SG-8860 1U pfSense® Security Gateway Appliance running a standart office network, and everything is cool but it shows 20G througput and millions of packets.
      on the graphs trouble started when i enabled vlans. I had Flat network, and changed it to vlans separated.
      there are no bridges configured, and to the LAN port i got Ubiquity TOUGHTSwitch connected, that is not showing so high packet rate
      vlans.png
      vlans.png_thumb
      lanpacketsmonth.png
      lanpacketsmonth.png_thumb
      lanweekpackets.png
      lanweekpackets.png_thumb
      lanweek.png
      lanweek.png_thumb
      weekthroughput.png
      weekthroughput.png_thumb
      ![Screenshot from 2015-09-22 16:51:45.png](/public/imported_attachments/1/Screenshot from 2015-09-22 16:51:45.png)
      ![Screenshot from 2015-09-22 16:51:45.png_thumb](/public/imported_attachments/1/Screenshot from 2015-09-22 16:51:45.png_thumb)

      1 Reply Last reply Reply Quote 0
      • H Offline
        Harvy66
        last edited by

        You could possibly have a network loop. Your firewall has an Intel i350, which has a build in switch where if the destination MAC address from one port is to another MAC of the same network card, it will switch in the network card itself, so the packet doesn't need to go through the GBE interface, and it switches at full PCIe rates, which is VERY fast.

        1 Reply Last reply Reply Quote 0
        • B Offline
          burdandrei
          last edited by

          that what i tried to find,
          but correct me if i wrong, this should be loop in the firewall itself, right?

          1 Reply Last reply Reply Quote 0
          • C Offline
            cmb
            last edited by

            Even a loop within itself shouldn't exceed 1 Gbps in pf's counters. Check the output of 'pfctl -vvsr' to see the counters.

            Probably best to open a support case with us, you won't get an incident docked for any software issues which that seems to be. Please attach the status_output.tgz from status.php, so we can see the relevant back end data.

            1 Reply Last reply Reply Quote 0
            • H Offline
              Harvy66
              last edited by

              @cmb:

              Even a loop within itself shouldn't exceed 1 Gbps in pf's counters. Check the output of 'pfctl -vvsr' to see the counters.

              Probably best to open a support case with us, you won't get an incident docked for any software issues which that seems to be. Please attach the status_output.tgz from status.php, so we can see the relevant back end data.

              Why wouldn't it exceed 1Gbps?

              1 Reply Last reply Reply Quote 0
              • B Offline
                burdandrei
                last edited by

                Thanks @cmd, will do.
                i restarted the firewall, and looks like it stopped.  I got status tgz before and after, will open the ticket when i'll have more info

                1 Reply Last reply Reply Quote 0
                • C Offline
                  cmb
                  last edited by

                  @Harvy66:

                  Why wouldn't it exceed 1Gbps?

                  With the nature of how those counters work, it isn't possible to exceed the link speed of the interface if you're getting sane values.

                  @burdandrei:

                  Thanks @cmd, will do.
                  i restarted the firewall, and looks like it stopped.  I got status tgz before and after, will open the ticket when i'll have more info

                  Thanks, curious to see that.

                  1 Reply Last reply Reply Quote 0
                  • H Offline
                    Harvy66
                    last edited by

                    @cmb:

                    @Harvy66:

                    Why wouldn't it exceed 1Gbps?

                    With the nature of how those counters work, it isn't possible to exceed the link speed of the interface if you're getting sane values.

                    @burdandrei:

                    Thanks @cmd, will do.
                    i restarted the firewall, and looks like it stopped.  I got status tgz before and after, will open the ticket when i'll have more info

                    Thanks, curious to see that.

                    So even if the actual link speed is faster than the reported link speed? It's not a common situation, but this is one of them.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.