WAMSINC
asked on
how to find the top talker on a subnet
this morning something on our core site network is sending out a large amount of traffic causing congestion. Multiple remote offices are complaining of poor response. We can see it on the mpls providers online tool that all available bandwidth outgoing to the remote sites has been maxed for a couple hours. A possible suspect, a windows update server was turned off but the problem persists. Whats the best way to find out what is generating all this traffic and why?
Just some background: we have multiple remote sites on an mpls with nothing filtered. There is a separate internet circuit that goes out from our core site that is not seeing any saturation. All the high utilization is going from the core site to the remote offices. Incoming traffic is low and normal. The internet circuit traffic is also low and normal. Not sure if I have provided enough info but Im trying to get another perspective on figuring out who is the top talker and why.
Just some background: we have multiple remote sites on an mpls with nothing filtered. There is a separate internet circuit that goes out from our core site that is not seeing any saturation. All the high utilization is going from the core site to the remote offices. Incoming traffic is low and normal. The internet circuit traffic is also low and normal. Not sure if I have provided enough info but Im trying to get another perspective on figuring out who is the top talker and why.
ASKER
unfortunately we do not have access to the routers. My workstation is plugged in to the same core switch, a cisco 6509. Looks like it was a kaspersky AV update server. This was causing congestion for almost 4 hours. I would like to still try this tool and be prepared for next time this happens. How can I mirror the mpls port on the core switch? or would that be another question/issue ?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Use the Real Time Netflow Analyzer from solar winds/free tools:
http://www.solarwinds.com/products/solarwinds_free_tools/
http://www.solarwinds.com/products/solarwinds_free_tools/
He needs to be able to access the router to actually use net flow.
You could mirror the port the router is on to a PC wrunning a Wireshark capture and then do a filter down to the subnet you want to look at.
Look in statistics/conversations and sort by the bps columns to see who is the heaviest hitters.
Look in statistics/conversations and sort by the bps columns to see who is the heaviest hitters.
If you do not own the main mpls router you can download ntop from ntop.org. Load up this tool and plug it into the same switch that the core mpls router is on. Then mirror the port the router is connected to to the port that the ntop machine is plugged into. Again, you will see the top talker in a matter of minutes.