danfra
Member
OP
- Joined:
- Jun 2024
- Posts:
- 159
- From:
- Frankfurt, DE
Contabo claims 24TB outbound for March. My vnstat shows 18.2TB. That's 6TB difference, and they're billing $90 overage.
My setup:
- Single Debian 12 box, bridge interface
- vnstat on eth0, rebooted once on March 3
- No other interfaces active
- No Docker, no VMs, bare metal
Contabo's response: "our switch port counters are authoritative." They sent a CSV of 5-minute samples. Summing their numbers gives 24TB. But their sampling is 300-second intervals, and I see negative values in some rows where counter wrapped.
I asked about counter wrap handling. They said "our system accounts for this." No details.
My vnstat database shows no wraps, clean increment. I've run vnstat for 4 years on multiple boxes, never seen 30% error.
What measurement methodology do providers typically use for billing? Is 300-second polling standard? Should I be running independent MRTG or similar as evidence?
Not paying $90 on principle if their meter is broken.
mitigated 800Gbps before breakfast
armstrongvds
Member
ARM Enjoyer
- Joined:
- Jun 2024
- Posts:
- 199
- From:
- Seoul, KR
Insane value that you're fighting this!
But honestly their meter is probably just standard SNMP polling with rrdtool defaults. 300s is standard, yes. The counter wrap bug is real though, especially on 32-bit SNMP counters at 1Gbps+
What NIC do you have? Some Intel cards have known counter issues where they reset on certain power states. Not saying that's it, but could explain a gap if vnstat missed it
If it were me I'd set up independent MRTG with 64-bit counters and log everything. Runs circles around "trust the provider" as a strategy
one small ping for man...
danfra
Member
OP
- Joined:
- Jun 2024
- Posts:
- 159
- From:
- Frankfurt, DE
It's an Intel X710, not i340. Kernel is 6.1.0-18-amd64 from Debian 12 backports.
Some Intel cards have known counter issues
X710 does have the EEE power-down reset bug on older firmware, but I'm on 23.0.12 which supposedly fixed it. vnstat would show a drop though, not a gap. My graphs are clean.
I set up MRTG on a spare Pi 4 last night, SNMP v2c 64-bit counters polling every 60s. Will run parallel for a week and see. The Pi is on a dedicated switch port mirroring eth0, so completely independent path.
Still annoyed they won't explain the wrap math. "Our system accounts for this" is not an algorithm.
mitigated 800Gbps before breakfast