  psy-q

    psy-q

    Is it possible to have SSH traffic show in web monitor/bandwidth/ip traffic? Doesn't look like anything transferred over an SSH tunnel is being taken into account for bandwidth usage. Shibby 117 AIO RT-N66U
  jerrm

    jerrm

    The tracking rules using the account module are only applied to the FORWARD chain. Traffic destined to the router itself wouldn't be caught. You inserting can try duplicate account rules at the top of the INPUT chain. Not sure if that would cause any issues or not, but I think it would work.
  psy-q

    psy-q

    ugh, does that require manipulating iptables? Every time I go near that I cause more problems then it's worth.

    While we're at it, can OpenVPN traffic be pulled as well. I would think any VPN subnets should be added to the device list automatically. Not sure why that's not default behavior
  EOC_Jason

    EOC_Jason

    OpenVPN traffic shows up on the TUNxx tab in the bandwidth monitoring graph... (at least it does for toastman).
  psy-q

    psy-q

    Not in Shibby's build. For all intents and purposes traffic received outside the configured LAN is completely invisible. Probably to QOS as well.
  RMerlin

    RMerlin

    Check in the FORWARD chain - it's possible that the tun rule is before the ipt_account rule, which would cause VPN traffic to never hit the accounting rule.
  psy-q

    psy-q

    Good call Merlin, looks like that is the case. How do I move that down? Admin scripts (Firewall)?

    Looks like I'll probably have to remove the rule then recreate it at a specific line. Is that the best way to do it?

    Chain FORWARD (policy DROP 0 packets, 0 bytes)
    pkts bytes target prot opt in out source destination
    0 0 ACCEPT all -- tun21 *
    822K 683M all -- * * account: network/netmask: name: lan
    96413 103M all -- * * account: network/netmask: name: lan1
    0 0 all -- * * account: network/netmask: name: lan2
  RMerlin

    RMerlin

  psy-q

    psy-q

    Thanks Merlin, I'll try and pass that on to Shibby. Seems like a pretty important thing for anyone running a VPN.

    Looks like it works fine on my Asuswrt-Merlin powered RT-AC68U ;)
