Ah, I found if I SSH in rather than using the web interface I can see stats.
So, problem #2 is worked around, but it’s odd its not showing up in web interface, no?
Here are my stats for the past couple of hours:
> /interface ethernet print stats
name: ether1-gateway ether2-master ether3 ether4 ether5
driver-rx-byte: 152 066 596 12 890 844 0 0 0
driver-rx-packet: 128 616 106 349 0 0 0
driver-tx-byte: 10 825 881 160 147 720 0 0 0
driver-tx-packet: 88 221 137 119 0 0 0
rx-bytes: 152 581 060 3 232 890 10 849 285 2 655 669 30 682 838
rx-packet: 128 616 11 481 88 778 20 161 23 675
rx-too-short: 0 0 0 0 0
rx-64: 967 2 317 3 622 155 1 168
rx-65-127: 18 268 7 811 77 142 17 689 1 220
rx-128-255: 6 643 1 152 6 763 200 337
rx-256-511: 3 362 1 719 3 455 120 376
rx-512-1023: 2 421 1 356 1 274 2 168 2 094
rx-1024-1518: 96 955 562 819 0 19 856
rx-too-long: 0 0 0 0 0
rx-broadcast: 0 1 379 399 46 689
rx-pause: 0 0 0 0 0
rx-multicast: 0 2 057 3 898 125 687
rx-fcs-error: 0 0 0 0 0
rx-align-error: 0 0 0 0 0
rx-fragment: 0 0 0 0 0
rx-jabber: 0 0 0 0 0
rx-drop: 0 0 0 0 0
tx-bytes: 11 183 569 6 924 841 158 770 055 30 122 582 4 791 237
tx-packet: 88 056 11 146 127 832 22 047 21 708
tx-64: 212 2 139 4 773 3 871 2 602
tx-65-127: 78 059 5 489 15 488 1 994 19 516
tx-128-255: 5 102 4 931 4 538 4 059 4 097
tx-256-511: 2 062 2 382 4 947 2 200 2 602
tx-512-1023: 1 651 689 2 923 2 136 2 216
tx-1024-1518: 1 135 2 716 101 600 18 333 36
tx-broadcast: 87 2 156 3 166 3 513 2 877
tx-pause: 0 0 0 0 0
tx-multicast: 78 5 044 3 271 7 033 6 484
tx-collision: 0 0 0 0 0
tx-excessive-collision: 0 0 0 0 0
tx-multiple-collision: 0 0 0 0 0
tx-single-collision: 0 0 0 0 0
tx-deferred: 0 0 1 0 1
tx-late-collision: 0 0 0 0 0
tx-drop: 0 0 0 0 0
tx-fcs-error: 0 0 0 0 0
It doesn’t look like there are any errors.
I’ve also enabled logging in the firewall, dropping invalid connections on the input, output and forward chains for both ipv4 and ipv6, here is some sample output:
15:13:05 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33454->192.168.1.2:80, len 52
15:13:05 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33448->192.168.1.2:80, len 52
15:13:05 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33450->192.168.1.2:80, len 52
15:13:05 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33446->192.168.1.2:80, len 52
15:13:06 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33452->192.168.1.2:80, len 52
15:13:12 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34441->54.66.169.248:443, len 52
15:13:12 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,RST), 192.168.1.253:48342->52.65.8.9:443, len 52
15:13:12 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:58897->54.231.50.44:443, len 40
15:13:12 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:48343->52.65.8.9:443, len 52
15:13:12 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:37112->52.84.207.109:443, len 52
15:13:12 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34459->54.66.169.248:443, len 52
15:13:12 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34441->54.66.169.248:443, len 52
15:13:12 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:37112->52.84.207.109:443, len 52
15:13:12 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34459->54.66.169.248:443, len 52
15:13:13 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:58897->54.231.50.44:443, len 40
15:13:13 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34441->54.66.169.248:443, len 52
15:13:13 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34459->54.66.169.248:443, len 52
15:13:13 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:37112->52.84.207.109:443, len 52
15:13:14 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34441->54.66.169.248:443, len 52
15:13:14 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:58897->54.231.50.44:443, len 40
15:13:14 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34459->54.66.169.248:443, len 52
15:13:14 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:37112->52.84.207.109:443, len 52
15:13:15 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:48343->52.65.8.9:443, len 52
15:13:16 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34441->54.66.169.248:443, len 52
15:13:16 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34459->54.66.169.248:443, len 52
15:13:16 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:37112->52.84.207.109:443, len 52
15:13:16 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:58897->54.231.50.44:443, len 40
15:13:18 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33490->192.168.1.2:80, len 52
15:13:19 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33490->192.168.1.2:80, len 52
15:13:19 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33490->192.168.1.2:80, len 52
15:13:19 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33490->192.168.1.2:80, len 52
15:13:20 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34441->54.66.169.248:443, len 52
15:13:20 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33490->192.168.1.2:80, len 52
15:13:20 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34459->54.66.169.248:443, len 52
15:13:20 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:37112->52.84.207.109:443, len 52
15:13:21 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:58897->54.231.50.44:443, len 40
15:13:22 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33490->192.168.1.2:80, len 52
15:13:22 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:48343->52.65.8.9:443, len 52
15:13:25 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33490->192.168.1.2:80, len 52
15:13:28 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34441->54.66.169.248:443, len 52
15:13:28 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:37112->52.84.207.109:443, len 52
15:13:28 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34459->54.66.169.248:443, len 52
15:13:30 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:58897->54.231.50.44:443, len 40
15:13:31 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33454->192.168.1.2:80, len 52
15:13:31 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33448->192.168.1.2:80, len 52
15:13:32 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33490->192.168.1.2:80, len 52
15:13:32 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33450->192.168.1.2:80, len 52
15:13:32 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33446->192.168.1.2:80, len 52
15:13:33 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33452->192.168.1.2:80, len 52
15:13:35 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:48343->52.65.8.9:443, len 52
15:13:44 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34441->54.66.169.248:443, len 52
15:13:45 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33490->192.168.1.2:80, len 52
15:13:45 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:37112->52.84.207.109:443, len 52
15:13:45 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34459->54.66.169.248:443, len 52
15:13:49 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:58897->54.231.50.44:443, len 40
15:14:00 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33492->192.168.1.2:80, len 52
15:14:00 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33492->192.168.1.2:80, len 52
15:14:00 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33492->192.168.1.2:80, len 52
15:14:00 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33492->192.168.1.2:80, len 52
15:14:01 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33492->192.168.1.2:80, len 52
15:14:02 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:48343->52.65.8.9:443, len 52
15:14:03 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33492->192.168.1.2:80, len 52
15:14:06 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33492->192.168.1.2:80, len 52
15:14:11 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33490->192.168.1.2:80, len 52
15:14:13 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33492->192.168.1.2:80, len 52
15:14:16 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34441->54.66.169.248:443, len 52
15:14:18 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:34459->54.66.169.248:443, len 52
15:14:18 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:37112->52.84.207.109:443, len 52
15:14:26 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33492->192.168.1.2:80, len 52
15:14:27 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:58897->54.231.50.44:443, len 40
15:14:52 firewall,info invalid input: in:ether2-master out:(none), src-mac 7c:5c:f8:50:17:9d, proto TCP (ACK,FIN), 192.168.1.15:33492->192.168.1.2:80, len 52
15:14:54 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac f0:25:b7:d1:0f:31, proto TCP (ACK,FIN), 192.168.1.253:48343->52.65.8.9:443, len 52
15:15:44 firewall,info invalid input: in:pppoe-snap out:(none), src-mac 3c:61:04:4d:bc:a5, proto TCP (SYN,ACK), 202.124.127.230:443->111.69.177.47:55310, len 60
15:15:45 firewall,info invalid input: in:pppoe-snap out:(none), src-mac 3c:61:04:4d:bc:a5, proto TCP (SYN,ACK), 202.124.127.249:443->111.69.177.47:55311, len 60
15:15:45 firewall,info invalid input: in:pppoe-snap out:(none), src-mac 3c:61:04:4d:bc:a5, proto TCP (SYN,ACK), 202.124.127.251:443->111.69.177.47:55312, len 60
15:15:46 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac 60:03:08:8d:7d:00, proto TCP (RST), 192.168.1.20:55311->202.124.127.249:443, len 40
15:15:46 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac 60:03:08:8d:7d:00, proto TCP (RST), 192.168.1.20:55310->202.124.127.230:443, len 40
15:15:46 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac 60:03:08:8d:7d:00, proto TCP (RST), 192.168.1.20:55310->202.124.127.230:443, len 40
15:15:48 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac 60:03:08:8d:7d:00, proto TCP (RST), 192.168.1.20:55310->202.124.127.230:443, len 40
15:15:48 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac 60:03:08:8d:7d:00, proto TCP (RST), 192.168.1.20:55311->202.124.127.249:443, len 40
15:15:48 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac 60:03:08:8d:7d:00, proto TCP (RST), 192.168.1.20:55310->202.124.127.230:443, len 40
15:15:48 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac 60:03:08:8d:7d:00, proto TCP (RST), 192.168.1.20:55311->202.124.127.249:443, len 40
15:15:48 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac 60:03:08:8d:7d:00, proto TCP (RST), 192.168.1.20:55312->202.124.127.251:443, len 40
15:15:48 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac 60:03:08:8d:7d:00, proto TCP (RST), 192.168.1.20:55312->202.124.127.251:443, len 40
15:15:48 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac 60:03:08:8d:7d:00, proto TCP (RST), 192.168.1.20:55311->202.124.127.249:443, len 40
15:15:48 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac 60:03:08:8d:7d:00, proto TCP (RST), 192.168.1.20:55310->202.124.127.230:443, len 40
15:15:48 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac 60:03:08:8d:7d:00, proto TCP (RST), 192.168.1.20:55310->202.124.127.230:443, len 40
15:15:48 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac 60:03:08:8d:7d:00, proto TCP (RST), 192.168.1.20:55310->202.124.127.230:443, len 40
15:15:48 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac 60:03:08:8d:7d:00, proto TCP (RST), 192.168.1.20:55311->202.124.127.249:443, len 40
15:15:48 firewall,info invalid forward: in:ether2-master out:pppoe-snap, src-mac 60:03:08:8d:7d:00, proto TCP (RST), 192.168.1.20:55312->202.124.127.251:443, len 40
15:15:52 firewall,info invalid input: in:pppoe-snap out:(none), src-mac 3c:61:04:4d:bc:a5, proto TCP (SYN,ACK), 202.124.127.230:443->111.69.177.47:55310, len 60
15:15:53 firewall,info invalid input: in:pppoe-snap out:(none), src-mac 3c:61:04:4d:bc:a5, proto TCP (SYN,ACK), 202.124.127.249:443->111.69.177.47:55311, len 60
15:15:53 firewall,info invalid input: in:pppoe-snap out:(none), src-mac 3c:61:04:4d:bc:a5, proto TCP (SYN,ACK), 202.124.127.251:443->111.69.177.47:55312, len 60
15:16:08 firewall,info invalid input: in:pppoe-snap out:(none), src-mac 3c:61:04:4d:bc:a5, proto TCP (SYN,ACK), 202.124.127.230:443->111.69.177.47:55310, len 60
15:16:09 firewall,info invalid input: in:pppoe-snap out:(none), src-mac 3c:61:04:4d:bc:a5, proto TCP (SYN,ACK), 202.124.127.249:443->111.69.177.47:55311, len 60
15:16:09 firewall,info invalid input: in:pppoe-snap out:(none), src-mac 3c:61:04:4d:bc:a5, proto TCP (SYN,ACK), 202.124.127.251:443->111.69.177.47:55312, len 60
15:16:58 firewall,info invalid output: in:(none) out:pppoe-snap, proto TCP (SYN,ACK), 111.69.177.47:23->115.77.107.103:48313, len 52
15:16:58 firewall,info invalid output: in:(none) out:pppoe-snap, proto TCP (SYN,ACK), 111.69.177.47:23->115.77.107.103:17690, len 44
It seems odd that there are packets going on the output chain which are invalid. Any advice or ideas would be appreciated. Thanks.