Solved

How to know if network traffic is OK or not ?

Posted on 2007-03-30
5
149 Views
Last Modified: 2010-03-18
Hi, now I'm in charge of the LAN where I work.... I know a little bit about protocols and packets, layers, etc... but we want to know if there is over-traffic on the network or lost packets... well i'm not sure, everything that is wrong.

I have read that I can do this with Ethereal.... and I downloaded it, but I have no idea what to do with the information that it captures.

Could you help me ? or at least give me some URLs to read about this.

Thanks!
0
Comment
Question by:blueshaolin
  • 2
  • 2
5 Comments
 
LVL 77

Accepted Solution

by:
Rob Williams earned 200 total points
ID: 18823425
Since you are not sure what you are looking for rather than creating filters you might be best to just make a capture and one by one remove the traffic you know is OK, then analyze what is left. To do so right click on a line with a known protocol, such as SMTP and choose "apply as a filter" and then "not selected".

There is a problem with using Ethereal. If you are connected to a switch, you will only see the traffic between you and the switch. If you have a managed switch you can mirror a selected port, or you can install an old basic hub between the switch and source (such as Internet) and plug into that. Hubs broadcast all traffic to all ports.
0
 
LVL 26

Assisted Solution

by:Fred Marshall
Fred Marshall earned 200 total points
ID: 18823456
Without doing a big study project, you might consider getting some empirical experience.
Hook up a couple of computers on a hub (a hub, not a switch, just to make sure you see all the traffic).  Run Ethereal on one of them and see what happens when you PING and so forth....
Try it with compatible IP addresses.  Try it with incompatible IP addresses.

If you see something you don't understand then direct a bit of research to that topic - like ARP perhaps.

You say "everything that is wrong" .... is there a specific problem?

One manifestation of over-traffic would be lots of messages coming out from a single source and with no apparent reason.  That might suggest a parasite.  Certainly if the messages are running through all likely IP addresses one after another!
0
 
LVL 22

Assisted Solution

by:Rick Hobbs
Rick Hobbs earned 100 total points
ID: 18825072
Before you start looking at the traffic I would recommend looking at the systems on the network.  Make sure you have a good Antivirus and Anti-spyware software package in place (like Symantec Antivirus Corporate V10.1.5.5000) and run a full scan on the servers and workstations.  Generally eliminating all viruses, spyware, and adware is a major benefit and eliminates excessive traffic.   Also, a Software Restriction Policy (SRP) can help eliminate traffics from games, streaming media and the like.
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 19276041
Thanks blueshaolin.
Cheers !
--Rob
0
 
LVL 22

Expert Comment

by:Rick Hobbs
ID: 19278700
Thanks!.  Hope I was of some help.
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question