OPNsense Forum

English Forums => Zenarmor (Sensei) => Topic started by: jonny5 on July 28, 2025, 07:42:39 PM

Title: Zenarmor more or less shows activity in reverse
Post by: jonny5 on July 28, 2025, 07:42:39 PM
External hosts includes internal IPs, Internal hosts includes external IPs

I'm only in detection for 3 LAN Interfaces, I do have RSS enabled (it suggests I disable it... but it has been around for years now and certainly appears to work for everything else including Suricata)

The "Traffic Graph (Throughput)" Dashboard that shows activity, only shows activity for Upload, not Download (even if I speed test Up/Down, just shows Upload)

Any ideas, I'm completely new to Zenarmor and have a free account but have it integrated to their Cloud too?

That said, I have had a few detections for hosts going to odd FQDNs, not bad!
Title: Re: Zenarmor more or less shows activity in reverse
Post by: sy on July 31, 2025, 02:48:08 PM
Hi,

Can you check if the WAN interface is protected in Settings - Configuration - Protected Interface?