[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 424
  • Last Modified:

Wireshark Emergency Trouble

My boss is asking me to use Wireshark to check why one of our sites is accessing the internet slowly within the last month, and why we are getting email alerts stating that the sites inbound traffiic on interface 'Serial 0/0 is to high at odd hours and even on the weekend when there's barely people at that site access the network.

I need a quick crash course on how to troubleshoot using wireshark....step by step if possible. I barely have 24 hours to get this right...I'm going to the site tomorrow and I'm lost.

I have it installed on my Windows XP laptop...
0
bernardb
Asked:
bernardb
3 Solutions
 
RhysehCommented:
0
 
tjdabombCommented:
its not too hard, start it on your NIC interface, let it run during a period in which you think there is "bad traffic" and then analyze the results  - it's pretty easy to use.
0
 
rfc1180Commented:
Wireshark will more than likely not give you much information you will need in a timely fasion.

You need an application that will be able to give you your top n talkers based on traffic, protocol, etc
Youcvould use an application such as ntop;

http://www.ntop.org/overview.html

Download  a livecd:
http://slampp.abangadek.com/info/

Or if this is a Cisco router, you can use IP accounting to give you an idea:

int ser0/0
ip accounting

show ip accounting

then if you are using nat, you will need to determine the IP address that is sending allot of packets and then cross reference via the NAT table.

Billy

0
 
bernardbAuthor Commented:
Thanks
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now