Solved

Packet monitoring on 2600

Posted on 2004-04-14
6
287 Views
Last Modified: 2010-04-17
We are wanting to monitor what type of packets are going through a Cisco 2600 router (http, smtp, etc) to verify what is slowing a router down if there are performance issues.  Normally, I would use debug commands, but we want to do this through HP OpenView.  What is the best way?  
0
Comment
Question by:neowolf219
6 Comments
 
LVL 27

Accepted Solution

by:
pseudocyber earned 500 total points
Comment Utility
Openview would only be able to report SNMP and possibly RMON data gathered from the router.  If the router doesn't have the info, neither will Openview.

I would recommend a tap to which a protocol analyzer could connect.  Is this only a temporary troubleshooting - in which case simply do a sniff - or more of a permanent monitoring and trending need?  

Permanent solutions -
http://www.netscout.com/products/probes_home.asp
http://www.flukenetworks.com/us/WAN/Monitoring+Analysis+Diagramming/OptiView+WAN+Analyzer/Overview.htm
0
 
LVL 1

Expert Comment

by:jajjones
Comment Utility
would netflow not help ?
0
 
LVL 3

Author Comment

by:neowolf219
Comment Utility
"Openview would only be able to report SNMP and possibly RMON data gathered from the router.  If the router doesn't have the info, neither will Openview"

RMON does not do any packet analyzing does it (it won't distinguish between http, icmp, smtp, etc.)?  We have SNMP working, but we have not done anything with RMON.  

It sounds like the only way to set up a permanent solution is another third-party package ... I just thought Cisco would have something built in for monitoring purposes.  

Yeah, if it was temporary, like you said, do a sniff, debug the the heck out of the router, etc.  But we are trying to find something that unknowledgable workers could use.  

Thanks for all you're help.  Let me know what you think.  
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 
LVL 27

Expert Comment

by:pseudocyber
Comment Utility
MAYBE CiscoWorks would do it - with an add on.

This is exactly what Fluke and Netscout were made to do.
0
 

Expert Comment

by:QuasiBoy
Comment Utility
I know you were asking about packet monitoring. But one easy check for an indication as to why the router is slowing down is put <ip accounting out> on the WAN side. See if there is predominantly one IP address inside your network creating a huge amount of traffic or scanning through IP's (Welchia or variants). Do <show ip accounting> once configured and <clear ip accounting> if there is just way too much to go through. If your not seeing anything obvious that way, take the <ip accounting> off the WAN and put it on your Ethernet side. Do the same check.
0
 
LVL 3

Author Comment

by:neowolf219
Comment Utility
Thanks Quasiboy.  I do know how to do a little bit of debugging, but I haven't used that specific technique.  Good advice!
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

New Server 172.16.200.2  was moved from behind Router R2 f0/1 to behind router R1 int f/01 and has now address 172.16.100.2. But we want users still to be able to connected to it by old IP. How to do it ? We can used destination NAT (DNAT).  In DNAT…
We've been using the Cisco/Linksys RV042 for years as: - an internet Gateway - a site-to-site VPN device - a leased line site-to-site subnet-to-subnet interface (And, here I'm assuming that any RV0xx behaves the same way as an RV042.  So that's …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now