Community discussions

MikroTik App
 
kchris
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 62
Joined: Wed Oct 27, 2004 2:58 pm

traffic invisible for mikrotik-torch

Wed Jun 14, 2006 3:29 pm

hi!

I've a sector with much clients. the average uploading traffic is 2-300kbit/s. Sometimes it raises up to 5-6-700kbit/s - bringing the sector to an unstable state - PacketLoss/ping times are high, the net is unusable for the users.

The interesting is that this traffic is visible at the interface list, but when I'm torching to trace who's doing that upload, I don't see anything unusual (only the average 2-300kbit/s).

My opinion is that 2 clients are doing direct connectcions with each other, and this traffic is 'turning back on the wifi card', because no routing is needed, the wifi card is funcioning like a switch.

My question is how can I trace back in this case who's doing that traffic? Or, can I separate the clients from each other so they are not able to make 'intra-sector' connections?

thanx!!!
 
believewireless
Member Candidate
Member Candidate
Posts: 231
Joined: Wed Jul 06, 2005 6:30 pm

Wed Jun 14, 2006 3:42 pm

We are seeing the same thing and it's not traffic going from one customer to another. We are running MRTG on the public interface and it's showing full traffic. Running torch on either the public OR private interface doesn't show the same level of traffic. Mikrotik interface graphs also show the traffic.

It also seems to be off by a large margin. We are "missing" 1-2Mbps or more at times.
 
kchris
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 62
Joined: Wed Oct 27, 2004 2:58 pm

Wed Jun 14, 2006 3:50 pm

We are seeing the same thing and it's not traffic going from one customer to another. We are running MRTG on the public interface and it's showing full traffic. Running torch on either the public OR private interface doesn't show the same level of traffic. Mikrotik interface graphs also show the traffic.

It also seems to be off by a large margin. We are "missing" 1-2Mbps or more at times.
:?: :evil: :roll:
 
GotNet
Member
Member
Posts: 434
Joined: Fri May 28, 2004 7:52 pm
Location: Florida

Wed Jun 14, 2006 4:07 pm

Might be this issue; I found 500k of missing traffic.

http://forum.mikrotik.com//viewtopic.php?t=8970

Change was made to the torch output. Don't know when.

Mike
 
kchris
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 62
Joined: Wed Oct 27, 2004 2:58 pm

another news

Sat Jun 24, 2006 10:23 pm

we did some tests a few days ago:
the selected routerOS uses the ip address of 10.3.0.0/16. Unfortunately we use open network, so anyone can connect to the AP (of course net is not accessible with these IP zone).

The test was the following. Two laptops equipped with WiFi card - we set 192.168.0.1 and 2 to them. Connected to the AP. And it worked! They could connect to each other, and of course with full speed, thus making the AP unstable. This is not very suprising BUT: the WHOLE traffic is INVISIBLE. In torch tool, in the interface list. There isn't any correspondant entry in the ARP table... How is this possible? Does mikrotik work in this configuration like a switch and captures only higher level of traffic?? (traffic that needs routing, and passes through RB)

Is there any client separation option like in any 'normal' access point to block this 'intra-AP' traffic?

You could say I've to use authentication but, this is only a workaround, and when someone wants they can capture some valid MAC (mac filter) or crack the security key.
 
kenk
Frequent Visitor
Frequent Visitor
Posts: 62
Joined: Sat Jun 05, 2004 7:22 am
Location: Tumbi Umbi, Australia

Sun Jun 25, 2006 2:58 am

Do you have the forwarding option off on the wireless interface(s)?

Who is online

Users browsing this forum: seriosha and 13 guests