Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Traffic out of the WAN interface

    Scheduled Pinned Locked Moved Firewalling
    13 Posts 3 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      congtubac
      last edited by

      the graph below shows traffic out of the "WAN4" interface. It repeat constantly throughout the uptime of pfsense firewall. Is it good or bad?

      Help me please.

      Thank in advance!

      image link: http://i1044.photobucket.com/albums/b449/quang_long6/traffic%20run%20out_zps4gj9emms.png

      1 Reply Last reply Reply Quote 0
      • M Offline
        mer
        last edited by

        packet capture for that interface would tell you exactly what it is.  It could be anything; a periodic ping, keep alives, anything.

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator
          last edited by

          You do understand unless that inbound traffic is UDP that acks have to be sent as well.. So yeah inbound traffic creates outbound traffic…

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 26.07 | Lab VMs 2.9.0, 26.07

          1 Reply Last reply Reply Quote 0
          • C Offline
            congtubac
            last edited by

            Thanks Jonhpoz and mer,

            This is the traffic graph of server, it's role is a behind router connect to pfsense firewall. The traffic graph of server is very smooth, not same the traffic graph of pfsense.

            Link of the traffic graph of server: http://i1044.photobucket.com/albums/b449/quang_long6/server_zpsa79nv5sl.png

            1 Reply Last reply Reply Quote 0
            • M Offline
              mer
              last edited by

              A packet capture for WAN4 is the only way to tell exactly what the traffic is.  You can't tell if it's good/bad/normal until then. 
              If the server is on Windows, well, there a lot of Windows traffic related to NETBIOS and other protocols.  Get a packet capture then you can understand better.

              1 Reply Last reply Reply Quote 0
              • C Offline
                congtubac
                last edited by

                Dear Mer,

                The output of Server's network traffic is the input of Pfsense firewall's LAN traffic.
                But LAN's traffic Graph or WAN's traffic Graph of pfsense have a point which traffic run out .
                Is there something wrong with pfsense firewall ?

                Link Network traffic of server: http://i1044.photobucket.com/albums/b449/quang_long6/server_zpsa79nv5sl.png
                Link LAN traffic of pfsense firewall: http://i1044.photobucket.com/albums/b449/quang_long6/LAN_zpsbk4poz92.png
                Link WAN traffice of pfsense firewall: http://i1044.photobucket.com/albums/b449/quang_long6/traffic%20run%20out_zps4gj9emms.png

                1 Reply Last reply Reply Quote 0
                • M Offline
                  mer
                  last edited by

                  I understand the output of the server being the input of the pfSense box.  You are asking about the outputs on WAN4.  Without seeing firewall rules, nat rules, redirect rules, packet captures, it is hard to even try and help.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Offline
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    It would take all of 30 seconds to sniff on pfsense wan to see what the outbound traffic is.  I could just be acks or it could be anything - without the sniff there is no way to know what the traffic actually is.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 26.07 | Lab VMs 2.9.0, 26.07

                    1 Reply Last reply Reply Quote 0
                    • C Offline
                      congtubac
                      last edited by

                      Thanks johnpoz, mer,

                      This is Link packetcapture:
                      https://drive.google.com/file/d/0BzaRuZALM_oYNVpMOVZLYVdSaTg/view?usp=sharing

                      Help me please!

                      Thank you very much!

                      1 Reply Last reply Reply Quote 0
                      • M Offline
                        mer
                        last edited by

                        According to the packet capture, it's all HTTP and related traffic.  Some packet reassembly, some duplicate acks.  If you grab the program Wireshark you can look at the data you've captured and see if the addresses are legitimate.  The differences in the graphs between the server and the WAN output can be due to anything, I can't help debug that.

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ Offline
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          Yeah quick look - and ACKS as I stated..

                          You do understand that how tcp works when I download something from a website for example and I get that packet I send an ack saying hey I got that, etc..  Its a two way communication.  While acks are small, if you are downloading lots of info, then lots of acks add up to some amount of upload bandwidth..

                          See your small packets, which are prob all acks to what you were downloading actually make up higher percentage of the sniff then large download packets (what the server was sending you)..

                          acks.png
                          acks.png_thumb
                          smallpackets.png
                          smallpackets.png_thumb

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 26.07 | Lab VMs 2.9.0, 26.07

                          1 Reply Last reply Reply Quote 0
                          • C Offline
                            congtubac
                            last edited by

                            Dear Johnpoz,

                            there are about 300 users behide the server, which role is a router. so all of main traffic is the sum of 300 users, not server.

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ Offline
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              Yeah what is your point?? Your sniff did not show 300 different sessions that is for sure..  What part do you not understand about acks?? Your graph is showing 50mbps down, what do you think the up requirement is for the acks in that sort of download??

                              Here see I am downloading a file, nothing really before that was going on.. As you can see while I am downloading the upload is there as too.. ACKS!!  Can not talk to tcp/ip without ACKS…  Downloading going to require a % of the speed your downloading at in upload bandwidth.

                              uploadondownload.png
                              uploadondownload.png_thumb

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 26.07 | Lab VMs 2.9.0, 26.07

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                              Privacy Policy · Cookie Policy