Wireguard and ZeroTier switched interface on Reporting-Insight

Started by jaykumar2005, June 22, 2022, 10:22:27 AM

Previous topic - Next topic
I am running both Wireguard and Zerotier the Opnsense firewall ( OPNsense 22.1.8 ) , with firewall rules & Gateway for each interface. I have enabled Netflow on LAN/WAN interface capturing locally.

For some reason, Reporting --> Insight shows Wireguard traffic on Zerotier interface and Zerotier traffic on Wireguard interface. This is true for Insight Graph and Traffic tab as well.

Strangely enough, realtime traffic under Reporting --> Traffic (Graph and Top Talkers) show correct traffic for each of these interfaces.

This looks like a cosmetic issue with no affect on Firewall rules, Routing or Gateway etc.. What could be causing this?
Hardware: Lenovo ThinkStation P330 Tiny (Intel Core i5-8500 @ 3.00GHz, 1xI219-LM, 4xI350)
BUFFERBLOAT GRADE A+

Did a packet capture of both WG0 and ZT0, don't see any source/destination mismatch.

Looks like this might be issue with Netflow tagging the interface incorrectly, any idea how to troubleshoot and fix it?
Hardware: Lenovo ThinkStation P330 Tiny (Intel Core i5-8500 @ 3.00GHz, 1xI219-LM, 4xI350)
BUFFERBLOAT GRADE A+

Netflow uses interface index instead of name to represent data which can overlap interfaces created after boot for different reasons. The output is most reliable on fixed hardware interfaces.


Cheers,
Franco

Sorry don't understand the inner working of Netflow, but can I manally override this index?

Any other suggestion to fix this?
Hardware: Lenovo ThinkStation P330 Tiny (Intel Core i5-8500 @ 3.00GHz, 1xI219-LM, 4xI350)
BUFFERBLOAT GRADE A+