OPNsense Forum

Archive => 18.7 Legacy Series => Topic started by: HFsi on September 22, 2018, 05:52:13 pm

Title: Not reporting outbound traffic
Post by: HFsi on September 22, 2018, 05:52:13 pm
Hi guys!
I´ve a strange problem that I can´t find anything in the forums.
Everything is working great with my config, except the LAN outbound traffic reporting...
But, for example, under Insight the traffic is accounted
As you can see in the attachment, there is WAN IN traffic, but it isnt´t reported as OUT LAN...so I can´t see who is using BW.
Any idea?
Thanks!
Title: Re: Not reporting outbound traffic
Post by: franco on September 24, 2018, 09:00:05 am
Hi,

Let me make a prediction: you are using IDS with IPS mode on LAN and your NIC driver for LAN is em(4) or igb(4)?


Cheers,
Franco
Title: Re: Not reporting outbound traffic
Post by: HFsi on September 24, 2018, 03:54:37 pm
Oh no, Franco has hacked me! jajaja
Yep, all that is correct...em0 is my LAN interface and I have IDS+IPS on it....
I assume some compatibility issue between Suricata and intel(?) driver...
Any workaround?
Title: Re: Not reporting outbound traffic
Post by: franco on September 24, 2018, 07:57:38 pm
Hi HFsi,

It's been a known issue for quite a while now, but only recently we've been able to investigate the underlying operating system code which normally lies out of our project scope. :)

https://github.com/opnsense/core/issues/1632

Incidentally, I was testing the Realtek driver update this weekend and found out that the re(4) driver does not have this defect.

So there is hope we can fix it. So far no FreeBSD version works correctly for these drivers under the IPS circumstances, but we have an idea of how to fix but no ETA other than on our way to 19.1.


Cheers,
Franco
Title: Re: Not reporting outbound traffic
Post by: HFsi on September 26, 2018, 07:51:26 pm
Right, I have some assembled boxes running OPN with Realtek NICs that don´t have this issue, that´s why I posted the topyc, thinking that something could be bad with my config.

Thanks for the info.

Keep on with the awesome work you´re doing!