I opened the interface list in winbox and saw 5+mb traffic flowing through the router on 2 interfaces.
Hmm, so I opened torch on one of the interfaces and did not see any traffic of high rates.
So, I opened the packet sniffer and captured the traffic and found a lot of traffic of type IP Protocol 50(ipsec)
Back to torch, I selected 50(ipsec) in the protocol dropdown and started torch. It showed no traffic!
I tried ICMP in the protocol dropdown and ran continuous pings from another router through the suspect router and
still no traffic shows up in torch.
It seems that Torch only show TCP and UDP traffic in winbox.
Running torch in a terminal will show the real traffic rate.
I’ve seen this when I select to show port. Then torch shows only protocols
which have a port to show.
Stefan
Ok, seems the nut that holds the wheel is broken…
Yes, if you check the port checkbox it will only show tcp and udp traffic which , of course, is the only
relevant traffic if you’re checking ports.
I was checking all the boxes out of habit and not thinking, shees!
Yeah, the thought is correct. But it is really a filter. You’d think checking everything would show everything.