Solved

Wireshark Emergency Trouble

Posted on 2011-02-28
4
409 Views
Last Modified: 2012-05-11
My boss is asking me to use Wireshark to check why one of our sites is accessing the internet slowly within the last month, and why we are getting email alerts stating that the sites inbound traffiic on interface 'Serial 0/0 is to high at odd hours and even on the weekend when there's barely people at that site access the network.

I need a quick crash course on how to troubleshoot using wireshark....step by step if possible. I barely have 24 hours to get this right...I'm going to the site tomorrow and I'm lost.

I have it installed on my Windows XP laptop...
0
Comment
Question by:bernardb
4 Comments
 
LVL 3

Accepted Solution

by:
Rhyseh earned 300 total points
ID: 35003289
0
 
LVL 9

Assisted Solution

by:tjdabomb
tjdabomb earned 100 total points
ID: 35003315
its not too hard, start it on your NIC interface, let it run during a period in which you think there is "bad traffic" and then analyze the results  - it's pretty easy to use.
0
 
LVL 24

Assisted Solution

by:rfc1180
rfc1180 earned 100 total points
ID: 35003371
Wireshark will more than likely not give you much information you will need in a timely fasion.

You need an application that will be able to give you your top n talkers based on traffic, protocol, etc
Youcvould use an application such as ntop;

http://www.ntop.org/overview.html

Download  a livecd:
http://slampp.abangadek.com/info/

Or if this is a Cisco router, you can use IP accounting to give you an idea:

int ser0/0
ip accounting

show ip accounting

then if you are using nat, you will need to determine the IP address that is sending allot of packets and then cross reference via the NAT table.

Billy

0
 

Author Closing Comment

by:bernardb
ID: 35029758
Thanks
0

Featured Post

Free camera licenses with purchase of My Cloud NAS

Milestone Arcus software is compatible with thousands of industry-leading cameras for added flexibility. Upon installation on your My Cloud NAS, you will receive two (2) camera licenses already enabled in the software. And for a limited time, get additional camera licenses FREE.

Join & Write a Comment

Big data transfers via information superhighways require special attention and protection. Learn more about the IT-regulations of the country where your server is located. Analyze cloud providers and their encryption systems for safe data transit. S…
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now