Solved

Wireshark Emergency Trouble

Posted on 2011-02-28
4
411 Views
Last Modified: 2012-05-11
My boss is asking me to use Wireshark to check why one of our sites is accessing the internet slowly within the last month, and why we are getting email alerts stating that the sites inbound traffiic on interface 'Serial 0/0 is to high at odd hours and even on the weekend when there's barely people at that site access the network.

I need a quick crash course on how to troubleshoot using wireshark....step by step if possible. I barely have 24 hours to get this right...I'm going to the site tomorrow and I'm lost.

I have it installed on my Windows XP laptop...
0
Comment
Question by:bernardb
4 Comments
 
LVL 3

Accepted Solution

by:
Rhyseh earned 300 total points
ID: 35003289
0
 
LVL 9

Assisted Solution

by:tjdabomb
tjdabomb earned 100 total points
ID: 35003315
its not too hard, start it on your NIC interface, let it run during a period in which you think there is "bad traffic" and then analyze the results  - it's pretty easy to use.
0
 
LVL 24

Assisted Solution

by:rfc1180
rfc1180 earned 100 total points
ID: 35003371
Wireshark will more than likely not give you much information you will need in a timely fasion.

You need an application that will be able to give you your top n talkers based on traffic, protocol, etc
Youcvould use an application such as ntop;

http://www.ntop.org/overview.html

Download  a livecd:
http://slampp.abangadek.com/info/

Or if this is a Cisco router, you can use IP accounting to give you an idea:

int ser0/0
ip accounting

show ip accounting

then if you are using nat, you will need to determine the IP address that is sending allot of packets and then cross reference via the NAT table.

Billy

0
 

Author Closing Comment

by:bernardb
ID: 35029758
Thanks
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
WLC 5508 controller configuration 4 75
Why does my public IP keep changing? 6 63
Creating a Vendor Admin user 23 51
CSS: Making Pure CSS read more boxes thinner 5 30
Worried about if Apple can protect your documents, photos, and everything else that gets stored in iCloud? Read on to find out what Apple really uses to make things secure.
Ensuring effective and secure communication in the age of healthcare BYOD.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question