Solved

Need to see traffic across WAN

Posted on 2010-08-25
4
264 Views
Last Modified: 2012-05-10
We have a Point-2-Point T1 that supplies a 1MB connection between two LANs.  The T1 is wide open for both networks so traffic can come across the T1 at any time for any reason.  DHCP helps to control access by passing out local gateway, DNS and other domain traffic.  However there are times when we have a wild node that gets relocated to the opposite office or maybe a wrong DHCP entry.  Either way, we end up with 3000ms response time across the T1 when you normally see 10ms.  The challenge is that I currently have no quick way to see what node is sending/receiving traffic across that link.  The T1 is terminated into a radio broadcast device that does nothing more than give it a switch port, so there is no monitoring on either end.

With all of that said, I would like to be able to install a computer at one end of the T1, maybe place a 10/100 HUB inline with the T1 before it hits the local switch.  The computer could sniff the traffic to see what IP is sending/receiving a large majority of traffic.

Is this the best and cheapeast solution and if so, what software is free that will do this for me?  
0
Comment
Question by:murryc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 8

Assisted Solution

by:jimmyray7
jimmyray7 earned 250 total points
ID: 33525976
Wireshark will let you see all of the traffic traversing the WAN.  It's pretty much the gold standard for this kind of stuff.

0
 
LVL 9

Accepted Solution

by:
asawatzki earned 250 total points
ID: 33526039
Here is what I would suggest.  Not sure what switch gear you have there, but if it is Cisco you can do the following:

1.  Plug in a desktop to the switch your WAN is plugged into on either site.
2.  Install wireshark's free Packet Sniffer.  http://www.wireshark.org/
3.  Find the switch interface that your WAN is plugged into on the remote network (or on your local network).  Turn on port mirroring on the interface your WAN is connected to so that it mirrors traffic over to the port your desktop is on.
4.  Turn on the packet capture for Wireshark on the desktop and you should be capturing all the traffic that is passing over the WAN.  You can use the Show IP Conversations view to see what end-to-end traffic is eating up all of your bandwidth.

If you don't have Cisco there may be another command like port mirroring for step 3.
0
 
LVL 3

Expert Comment

by:VBDotNetCoder
ID: 33526052
0
 
LVL 2

Expert Comment

by:texasjpm
ID: 33526240
If you have a Cisco router I think i would use Flow-top-talkers. Here is an example of the config i am using.

interface GigabitEthernet0/0
 ip flow ingress
 ip flow egress

ip flow-export source GigabitEthernet0/0
ip flow-top-talkers
 top 10
 sort-by bytes
 cache-timeout 1300
 match input-interface GigabitEthernet0/0


cap.jpg
0

Featured Post

Resolve Critical IT Incidents Fast

If your data, services or processes become compromised, your organization can suffer damage in just minutes and how fast you communicate during a major IT incident is everything. Learn how to immediately identify incidents & best practices to resolve them quickly and effectively.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Hello All, I have been training on Multicast for a while now and whenever I start the topic , I find out that my friends /  Colleagues mention that they do not know how to test Multicast Joins. As most of the multicast would be video traffic and …
An article on effective troubleshooting
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question