I really appreciate your detailed description ... Right now we are trying to find out what is using all our upload bandwidth, so I currently have the port in which the internet comes through mirrored to a PC running Wireshark... However I'm unsure what capture filters I should be applying as I only want to log the source and the destination using our upload bandwidth... Thanks in advance,.
Main Topics
Browse All Topics





by: uetian1707Posted on 2009-01-27 at 21:06:18ID: 23483664
Hi,
| LAN
Propriety
LAMP based NMS
How is your network setup? Suppose it is setup as below;
|
|
|
GatewayRouter ---------> CoreSwitch----------------
|
|
|
In the above scenario, you can enable port mirroring on the core switch and check which port is causing more traffic.
More easier way is to use some SNMP-enabled application to monitor your switch ports and you will be able to see which computer is causing more traffic. Popular NMS are;
SolarWinds Orion www.solarwinds.com Propriety
Adventnet OP Manager www.adventnet.com Propriety
WhatsupGold http://www.whatsupgold.com
Observer www.netinst.com Propriety
AutoNOC www.autonoc.com Propriety
CommView www.tamos.com Propriety
Open-Source
Ntop www.ntop.org LAMP based NMS
Bandwidthd bandwidthd.sourceforge.net
Etherape etherape.sourceforge.net LAMP based NMS
MRTG oss.oetiker.ch/mrtg RRDTool
Cacti www.cacti.net RRDTool
If your device supports Netflows, or Jflow;
Flow Analyzers
SolarWinds NetFlow Analyzer www.solarwinds.com NetFlow/SFlow
Scrutinizer NetFlow/Sflow Analyzer www.plixer.com NetFlow/SFlow
Caligare Flow Inspector www.caligare.com NetFlow/SFlow
StealthWatch® Xe www.lancope.com SFlow
Adventnet Netflow Analyzer www.adventnet.com NetFlow
PRTG www.paessler.com/prtg NetFlow/RRDTool
Explaining the above lists, the standard SNMP based NMS will allow you to monitor the bandwidth, have support for Syslogs and some of them also support VoIP monitoring support. The flow analyzers can be helpful to get the per protocol usage details. They can only be deployed if your network gear supports J-flow, Net-flow or S-Flow.
Personal recommendations are using Solarwinds Orion, Cacti or Ntop.