OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • Insight - Interface wrong
« previous next »
  • Print
Pages: [1]

Author Topic: Insight - Interface wrong  (Read 3789 times)

AndyX90

  • Jr. Member
  • **
  • Posts: 55
  • Karma: 2
    • View Profile
Insight - Interface wrong
« on: March 04, 2019, 08:38:32 am »
Hey guys,

i have a Problem regarding Netflow/Insight and specific WAN-Traffic.
Basically i have one WAN Interface, one LAN Interface and one Interface linked to another firewall.
There are Internet-connections coming into my LAN from the other firewalls interface.
But Netflow displays them on my WAN-Interface.
Any suggestions?

Thanks in advance!
Logged

hbc

  • Hero Member
  • *****
  • Posts: 501
  • Karma: 47
    • View Profile
Re: Insight - Interface wrong
« Reply #1 on: March 04, 2019, 03:02:55 pm »
Did you verify via tcpdump that packets are coming from 2nd firewall and not from local WAN? Maybe a routing issue and packets are actually received from local WAN?
Logged
Intel(R) Xeon(R) Silver 4116 CPU @ 2.10GHz (24 cores)
256 GB RAM, 300GB RAID1, 3x4 10G Chelsio T540-CO-SR

AndyX90

  • Jr. Member
  • **
  • Posts: 55
  • Karma: 2
    • View Profile
Re: Insight - Interface wrong
« Reply #2 on: March 07, 2019, 09:08:32 am »
Quote from: hbc on March 04, 2019, 03:02:55 pm
Did you verify via tcpdump that packets are coming from 2nd firewall and not from local WAN? Maybe a routing issue and packets are actually received from local WAN?
Sorry for the late reply. Yes, the traffic is on the other interface.
It is a HA-Setup between 2 DEC-4630.
Another example is the Carp-Traffic.
I see the traffic on the HA-Interface (separate 1G-Interface between both firewalls), but in Insight the HA-Interface is empty and the Carp-Traffic is also displayed on WAN... :-\
Logged

hbc

  • Hero Member
  • *****
  • Posts: 501
  • Karma: 47
    • View Profile
Re: Insight - Interface wrong
« Reply #3 on: March 19, 2019, 05:06:15 pm »
Where do you have CARP running? From your sketch, I do not see where you use it.

CARP means you have a virtual IP shared between both firewalls and the active node is holding it. But this does also mean that you need a redundand connection to somewhere.

Your LAN is just connected to FW1 and your WAN looks like two seperate ISP for each firewall. Or do you send CARP via internet from firewall to firewall? Then WAN would be correct displayed but wrong used.
Logged
Intel(R) Xeon(R) Silver 4116 CPU @ 2.10GHz (24 cores)
256 GB RAM, 300GB RAID1, 3x4 10G Chelsio T540-CO-SR

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • Insight - Interface wrong
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2