Solved

Wireshark Emergency Trouble

Posted on 2011-02-28
4
410 Views
Last Modified: 2012-05-11
My boss is asking me to use Wireshark to check why one of our sites is accessing the internet slowly within the last month, and why we are getting email alerts stating that the sites inbound traffiic on interface 'Serial 0/0 is to high at odd hours and even on the weekend when there's barely people at that site access the network.

I need a quick crash course on how to troubleshoot using wireshark....step by step if possible. I barely have 24 hours to get this right...I'm going to the site tomorrow and I'm lost.

I have it installed on my Windows XP laptop...
0
Comment
Question by:bernardb
4 Comments
 
LVL 3

Accepted Solution

by:
Rhyseh earned 300 total points
ID: 35003289
0
 
LVL 9

Assisted Solution

by:tjdabomb
tjdabomb earned 100 total points
ID: 35003315
its not too hard, start it on your NIC interface, let it run during a period in which you think there is "bad traffic" and then analyze the results  - it's pretty easy to use.
0
 
LVL 24

Assisted Solution

by:rfc1180
rfc1180 earned 100 total points
ID: 35003371
Wireshark will more than likely not give you much information you will need in a timely fasion.

You need an application that will be able to give you your top n talkers based on traffic, protocol, etc
Youcvould use an application such as ntop;

http://www.ntop.org/overview.html

Download  a livecd:
http://slampp.abangadek.com/info/

Or if this is a Cisco router, you can use IP accounting to give you an idea:

int ser0/0
ip accounting

show ip accounting

then if you are using nat, you will need to determine the IP address that is sending allot of packets and then cross reference via the NAT table.

Billy

0
 

Author Closing Comment

by:bernardb
ID: 35029758
Thanks
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Gmail Account risks 4 76
Account Lockouts 25 147
change password links 7 72
Creating and Connection two new domains 5 77
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now