Packet monitoring on 2600

We are wanting to monitor what type of packets are going through a Cisco 2600 router (http, smtp, etc) to verify what is slowing a router down if there are performance issues.  Normally, I would use debug commands, but we want to do this through HP OpenView.  What is the best way?  
LVL 3
neowolf219Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

pseudocyberCommented:
Openview would only be able to report SNMP and possibly RMON data gathered from the router.  If the router doesn't have the info, neither will Openview.

I would recommend a tap to which a protocol analyzer could connect.  Is this only a temporary troubleshooting - in which case simply do a sniff - or more of a permanent monitoring and trending need?  

Permanent solutions -
http://www.netscout.com/products/probes_home.asp
http://www.flukenetworks.com/us/WAN/Monitoring+Analysis+Diagramming/OptiView+WAN+Analyzer/Overview.htm
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
jajjonesCommented:
would netflow not help ?
0
neowolf219Author Commented:
"Openview would only be able to report SNMP and possibly RMON data gathered from the router.  If the router doesn't have the info, neither will Openview"

RMON does not do any packet analyzing does it (it won't distinguish between http, icmp, smtp, etc.)?  We have SNMP working, but we have not done anything with RMON.  

It sounds like the only way to set up a permanent solution is another third-party package ... I just thought Cisco would have something built in for monitoring purposes.  

Yeah, if it was temporary, like you said, do a sniff, debug the the heck out of the router, etc.  But we are trying to find something that unknowledgable workers could use.  

Thanks for all you're help.  Let me know what you think.  
0
The Ultimate Tool Kit for Technolgy Solution Provi

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy for valuable how-to assets including sample agreements, checklists, flowcharts, and more!

pseudocyberCommented:
MAYBE CiscoWorks would do it - with an add on.

This is exactly what Fluke and Netscout were made to do.
0
QuasiBoyCommented:
I know you were asking about packet monitoring. But one easy check for an indication as to why the router is slowing down is put <ip accounting out> on the WAN side. See if there is predominantly one IP address inside your network creating a huge amount of traffic or scanning through IP's (Welchia or variants). Do <show ip accounting> once configured and <clear ip accounting> if there is just way too much to go through. If your not seeing anything obvious that way, take the <ip accounting> off the WAN and put it on your Ethernet side. Do the same check.
0
neowolf219Author Commented:
Thanks Quasiboy.  I do know how to do a little bit of debugging, but I haven't used that specific technique.  Good advice!
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Routers

From novice to tech pro — start learning today.