OPNsense Forum

Archive => 22.7 Legacy Series => Topic started by: sparticle on November 12, 2022, 05:36:40 pm

Title: Confused by Traffic Graph showing lan to lan traffic
Post by: sparticle on November 12, 2022, 05:36:40 pm
Hello,

I updated to the latest version today. I noticed I am seeing traffic stats for lan to lan traffic. I thought at first something was sending data out from the lan. But then realised it was showing stats for direct lan to lan connections!

Very confused by this as this particular server is a Video Surveillance server with cameras talking to it directly across the lan.

My understanding of the traffic graph is it is showing traffic traversing the opnsense interfaces.

How am I seeing traffic that is going from an IP camera to the server across the lan?

Cheers
Spart
Title: Re: Confused by Traffic Graph showing lan to lan traffic
Post by: jlab on November 13, 2022, 06:14:55 pm
Are you seeing traffic from those cameras going out of the LAN ?

Post a screen shot ?
Title: Re: Confused by Traffic Graph showing lan to lan traffic
Post by: sparticle on November 25, 2022, 11:11:04 am
No just massive amount of log spam that is halting my opnsense router when it runs out of space ~12G of logs in 6 hours.

It seems to be routing lan traffic that is lan to lan. I have no idea why it is even going through the opnsense router. It should simply be lan to lan traffic.

I thought it might be due to promiscuous mode. But that is off on the Lan.

opnsense is running on esxi 6.7

Any help is appreciated as I am having to reset logs multiple times a day.

Cheers
Spart
Title: Re: Confused by Traffic Graph showing lan to lan traffic
Post by: sparticle on November 25, 2022, 11:21:42 am
If I turn off ntopng the problem goes away. I believe it is related to promiscuous mode being set when ntopng is enabled.

Any advice appreciated.

Cheers
Spart
Title: SOLVED Re: Confused by Traffic Graph showing lan to lan traffic
Post by: sparticle on November 26, 2022, 01:52:14 pm
As OpnSense is running on ESXI I had to create a dedicated Port Group and attach the OpnSense LAN adaptor to it and reject promiscuous mode on that PG.

Activating NtopNG still sets promiscuous mode inside the guest but it now only sees traffic on its PG and not on the vswitch.

I hope this helps others that may see this kind of issue.

Cheers
Spart