Analyze what is going through my ethernet connection at start up

When my notebook boots, it seems to take a long time. I've notice the CPU use is pegged at 100% for quite a long time, and there seems to be a lot of activity on the Ethernet connection. I tried googling monitoring Ethernet traffic. It quickly became apparent to me that there are numerous programs to do this, but the wealth of information was overwhelming.

What simple to use, ideally free program can I use to monitor what is going through my Ethernet connection?

Windows XP 32bit, ThinkPad T61p, 2.4ghz C2D
montana4meAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

FrabbleCommented:
The LAN monitor of choice is Wireshark:
http://www.wireshark.org/

To monitor your machine during boot up, you'll need another machine to do the oacket capture, connected to either a spanned switch port if your machine is connected to a switch, or insert a hub between your machine and its network port and monitor one of the other hub ports.
0
FrabbleCommented:
That should be "packet capture".
0
montana4meAuthor Commented:
Frabble: I think I understand what you write above.

If I wanted to monitor what my machine is doing after boot-up. What would I use then? The 100% CPU load occurs after booting into XP for maybe a minute or two. CPU load then returns to 5 to 10%. Can I use a program on my own machine? Would it still be wireshark?
0
Cloud Class® Course: CompTIA Healthcare IT Tech

This course will help prep you to earn the CompTIA Healthcare IT Technician certification showing that you have the knowledge and skills needed to succeed in installing, managing, and troubleshooting IT systems in medical and clinical settings.

FrabbleCommented:
It is possible to run Wireshark on your own machine but I would still use another machine.

There's two components to Wireshark, a packet capture driver and the analyzer itself. Normally the packet driver isn't loaded until the analyzer program is run though it is possible to have the driver run as a service. Either way, you still need to run the analyzer part and select the interface to monitor and tell it to start. Trying to capture on your own machine at startup will involve some delay, especially with what you are experiencing, and may miss some traffic.
Best to have a monitor already running and capturing while your machine is starting up, which is why you need to mirror your machines switch port traffic or use a hub.

You will then capture all the traffic involved after which you can save the trace and use the decoding/filtering features of Wireshark to look at the network activity.
0
montana4meAuthor Commented:
OK. All my machines operate in a domain controlled by an SBS 2003 server. Every machine is plugged into a 48 port switch. All machines have fixed IPs.

Can I install wireshark on any machine in the domain and set it to watch what is coming and going through the Ethernet port of the machine that I have a concern over?
0
FrabbleCommented:
"Can I install wireshark on any machine in the domain and set it to watch what is coming and going through the Ethernet port of the machine that I have a concern over?". In theory yes, assuming a managed switch and it supports port spanning/mirroring - you configure to have incoming and outgoing traffic on monitored ports to be spanned to a monitor port.
Note that some switches may block incoming traffic on the monitor port unless allowed.

To limit the traffic captured, in Capture Options, you enter a Capture Filter "host x.x.x.x" where x.x.x.x is the IP address of the machine concerned. Note that this will filter out broadcasts.

What we have is a second NIC on a Wireshark machine, with all the connection items except the Network Monitor Driver disabled and connect this to the monitor port when required.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Network Analysis

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.