Solved

Sniffer question

Posted on 2004-09-09
12
721 Views
Last Modified: 2008-02-01
Hello,
 i have a client that is complaining of slow network traffic. he thiks he has a bad line or a chatty nic. I am not familure with sniffers. what is a good one to download, and any help using would be great. Than kyou in advance
0
Comment
Question by:eberhardt2329
  • 3
  • 2
  • 2
  • +5
12 Comments
 
LVL 11

Expert Comment

by:PennGwyn
ID: 12020097
Ethereal!

You can get a little more features and ease of use -- for awhole lot of cash....

Note:  If it's only one user, try replacing his network cable.  CAT5 isn't as tolerant of abuse as many people seem to believe....

0
 

Author Comment

by:eberhardt2329
ID: 12020424
it seems to be the whole place web traffic moving files etc. the two I sent to the user are http://www.ethereal.com/, and
  http://www.networkchemistry.com/products/packetyzer/                and I want them to run for a hour each, and send me the files. Any ideas?
0
 
LVL 9

Expert Comment

by:fixnix
ID: 12020853
Unless you filter out a lot during the capture (which could be confusing to a new user of Ethereal, see http://home.insight.rr.com/procana/ for a good page on filtering syntax and examples) you definately don't want to capture for an hour.  On a 5 computer LAN segment here, a 5 minute promiscuous capture yields a log file that is painfully slow to sort, manipulate, poke around, and use on a (slow, 1GHz, 128ram) workstation.  On a decent machine 5 mins wouldn't be a problem, depending on your typical network activity and number of workstations, but an hour would just be too much to work with right off the bat.  Capture everything for about a minute or two and have a look.  Hopefully you'll see errors and can set up capture filters honing in on said errors for a longer duration capture if necessary.
0
 
LVL 10

Expert Comment

by:winzig
ID: 12021539
Microsoft network monitor isn't bad,  but is extremely difficult to make expert analysis with these tools. In general much better solution is to use managed Switches which are able detect problems on network layer, and sniffers can be used to solve problems L3 layer.
0
 
LVL 1

Expert Comment

by:AbstractAnger
ID: 12022385
It's the whole place?
This could be any number of issues... slow backbone (10 MBps on a heavily used network can hurt). It could also be slower at different times of the day of a lot of users are playing around, logging in, (morning, lunch) etc... What kind of pipe do you have coming into the area from the outside world?
0
 

Author Comment

by:eberhardt2329
ID: 12023536
I believe they have a t1. I have saved the log file from the sniffer, can I sent this to someone not sure how to put this on here I am using ethereal
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 

Expert Comment

by:rsburks
ID: 12023942
In order to address the real problem... "Why is network traffic SLOW",
I believe we need to know alittle more about the network.  

Do you know the network layout including hubs, switches, number of clients on each node, etc.

Is the traffic slow to the internet or to other clients within the network or both?

Did this problem happen over time or all at once.  over time could indicate too many clients connected thur too many hubs.  Too many hubs on a large network will slow traffic to a crawl.

Solution would be to replace hubs with switches in key places.
 
If it happened all at once, this means something may have broke.  ie, bad cable, chatty NIC, whatever.

If it is a chatty NIC it should only affect that particular node (clients connected directly thur hubs) and not the entire network.  

If it is a bad cable it will only affect either the internet access and not intranet traffic, or visa versa.

So the question is...
is it the entire network that is being affected or just a section?
When and how did the problem start?
Why does the customer believe it is a chatty nic, he may have more information about the problem than he has said.

oh, and btw, with a sniffer, it will only capture packets that it is directly connected to.  
in other words.  if you want to just sniff the packets from a single computer put the sniffer on that computer, if you want to see a section of the entire network, you have to connect the sniffer to a hub on that network(NOT a switch).  A Sniffer will not see traffic on another port of a switch except for broadcast traffic within a subnet.  

0
 
LVL 1

Expert Comment

by:AbstractAnger
ID: 12026768
Even if it's a t1, it could just be normal network traffic sucking the life out of the wires. My building is runnning on fiber and I'm connected to a gig backbone.... we have a 9 Mbps pipe to the outside world, but it's slow sometimes. Like I said before, any number of issues could come into play, even if things are working normally.
0
 
LVL 9

Accepted Solution

by:
fixnix earned 500 total points
ID: 12026894
eberhardt2329 :

You could send the ethereal log to me if you want, but I probably won't get the chance to look at it until the weekend.  Send to wedgenix at inebraska.com if you want me to take a look when I get the chance.
0
 

Expert Comment

by:darwin_panela
ID: 12033325
try to use packetyzer... its a freeware you can download at www.micronet.info
0
 
LVL 16

Expert Comment

by:The--Captain
ID: 12033590
Since everyone has already mentioned my favorite remote analysis tools, have you tried just going into the network closet, looking at the switch, and watching which port(s) are lit up all the time?

Cheers,
-Jon

0
 

Author Comment

by:eberhardt2329
ID: 12040337
I have not been on site, does anyone know where I can download sniffer plus I like the interface. thank you any other ideas woiudl also be great
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now