Project

General

Profile

Bug #10959

Traffic graph stopped on interface used via netmap

Added by Edivan Carneiro de castro 2 months ago. Updated 2 months ago.

Status:
Feedback
Priority:
Low
Assignee:
-
Category:
Traffic Graphs
Target version:
-
Start date:
10/05/2020
Due date:
% Done:

0%

Estimated time:
Affected Version:
2.5.0
Affected Architecture:

Description

Current Base System: 2.5.0.a.20201005.1047

Problem: After update, the traffic grafic stoped on interface with snort configured in mode "inline IPS". IF disable snort or alter snort to "legacy mode" the traffic grafic on interface work normaly

History

#1 Updated by Edivan Carneiro de castro 2 months ago

Current Base System: 2.5.0.a.20201005.1047

Problem: After update, the traffic graphic stopped on interface with snort configured in mode "inline IPS". IF disable snort or alter snort to "legacy mode" the traffic graphic on interface work normally

#2 Updated by Jim Pingle 2 months ago

  • Subject changed from traffic grafic stoped on interface with snort mode inline IPS to Traffic graph stopped on interface used via netmap
  • Category set to Traffic Graphs
  • Status changed from New to Feedback
  • Affected Version set to 2.5.0

Which traffic graphs specifically?

The ones on the dashboard?

The one on Status > Traffic Graph?

The ones under System > Monitoring?

What snapshot did you upgrade from?

And what type of network interface do you have?

It's likely from the interface being used in netmap mode, so there may not be much that can be done to work around it. The way the driver supports netmap may have changed in a way that made the traffic graphs not be able to poll data.

#3 Updated by Edivan Carneiro de castro 2 months ago

In the dashboard and Status > Traffic Graph

#4 Updated by Edivan Carneiro de castro 2 months ago

I use Vmware as network interface

#5 Updated by Edivan Carneiro de castro 2 months ago

I've been using pfsense 2.5 for a month now, worked normally. only after 2020-10-02 updates the traffic graphic stopped

#6 Updated by Bill Meeks 2 months ago

Edivan Carneiro de castro wrote:

I've been using pfsense 2.5 for a month now, worked normally. only after 2020-10-02 updates the traffic graphic stopped

Do you mean you were previously using Snort on pfSense-2.5 with Inline IPS Mode enabled? Or were you using Legacy Mode and switched to Inline IPS Mode after the last Snort package update?

One thing that changed in the latest Snort package update was a new version of the DAQ library was added (version 2.2.2_2). This new DAQ update implements the very latest netmap API 14 used in FreeBSD-12/STABLE. Also, FreeBSD-12 implements netmap functionality as part of the iflib framework. I believe continual "tweaking" is going on there with repect to various NIC drivers and even the netmap device itself.

So the first critical data point for troubleshooting is to determine if you were successfully using Inline IPS Mode with Snort on pfSense-2.5 prior to October 2nd (and also successfully using Traffic Graph). In the past, those two elements (netmap operation with Inline IPS Mode and Traffic Graph) have not been compatible.

Also available in: Atom PDF