Trying to understand graphs - mystery data
Posted: Sun Feb 15, 2015 10:58 pm
I observed something the other day which didn't make sense to me. I am collecting data from a pfSense firewall.
Here is a graph showing the top 5 talkers:
So the top two talkers are:
10.25.2.1 = DNS Server = 38% bytes
10.25.6.21 = vMA Server = 34% bytes
You can see my mouse hovering over a point where it says 7GB. Now I know these two servers are not generating 7GB of data.
So here's a report of that same time period for the top 5 talkers:
You can see the bytes:
10.25.2.1 = DNS Server = 7.13 MB
10.25.6.21 = vMA Server = 6.38 MB
So where's this mystery 7GB coming from and why isn't it in the top 5?
I know what that timeperiod reflects and I know the traffic is real but I don't know why the data is being collected. Let me explain.
I have a virtual Windows Home Server.
I also have a physical Intel NUC that has a USB3 drive connected and shared.
The Windows Home Server connects to this virtual USB3 drive on the NUC and it appears as a USB drive in the Windows Home Server.
The Windows Home Server uses this as it's backup drive.
What you are seeing in the graphs is the Sunday backup that happens from midnight to 9am.
HOWEVER the traffic between the two servers is in the SAME subnet.
The pfSense firewall is the default gateway for the network.
So my questions are:
Why is my source showing this traffic when it does not pass through the pfSense firewall?
Why is pfSense sending this in the flow data?
Even if pfSense is sending the data when it should not, why does the data exist but does not appear as a top 5 talker?
Here is a graph showing the top 5 talkers:
So the top two talkers are:
10.25.2.1 = DNS Server = 38% bytes
10.25.6.21 = vMA Server = 34% bytes
You can see my mouse hovering over a point where it says 7GB. Now I know these two servers are not generating 7GB of data.
So here's a report of that same time period for the top 5 talkers:
You can see the bytes:
10.25.2.1 = DNS Server = 7.13 MB
10.25.6.21 = vMA Server = 6.38 MB
So where's this mystery 7GB coming from and why isn't it in the top 5?
I know what that timeperiod reflects and I know the traffic is real but I don't know why the data is being collected. Let me explain.
I have a virtual Windows Home Server.
I also have a physical Intel NUC that has a USB3 drive connected and shared.
The Windows Home Server connects to this virtual USB3 drive on the NUC and it appears as a USB drive in the Windows Home Server.
The Windows Home Server uses this as it's backup drive.
What you are seeing in the graphs is the Sunday backup that happens from midnight to 9am.
HOWEVER the traffic between the two servers is in the SAME subnet.
The pfSense firewall is the default gateway for the network.
So my questions are:
Why is my source showing this traffic when it does not pass through the pfSense firewall?
Why is pfSense sending this in the flow data?
Even if pfSense is sending the data when it should not, why does the data exist but does not appear as a top 5 talker?