Solved

internet slow

Posted on 2011-09-12
6
380 Views
Last Modified: 2012-06-21
Hi Experts,
the users in my network facing very slow network speed. when i obsreve it on monitoring tool i found that "HTTP TUNNEL"  consuming 80 to 90 percent bandwidth of my internet link.

on google i find that HTTP-TUNNEL traffic because  of users in network download softwares(hot spot shied and some others) to unblock the restricted websites.Is there any solution to block HTTP TUNNEL traffic. OR i should stop it on internet router  or on internal firewall.
or any-other soultion to get rid of this traffic.


Thanks,
0
Comment
Question by:osloboy
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 38

Expert Comment

by:Gerwin Jansen, EE MVE
ID: 36522828
Can you find out in your monitoring tool from what IP address the HTTP tunnel is originating? Trace down that user / workstation and uninstall it, informing the user of your company internet policy.
0
 
LVL 7

Assisted Solution

by:CSorg
CSorg earned 100 total points
ID: 36523439
could be regular traffic, for instance RDP over SSL connection(s)

RDP is aggressive when it comes to claiming network bandwidth.

like gerwinjansen said, try to isolate the source ip address first and start a local monitor (netstat -o would give you back information on the process and in what why that process is using network traffic)
(http://ss64.com/nt/netstat.html)
0
 

Author Comment

by:osloboy
ID: 36524871
monitoring tool doesnt show the source ip adress. it just show the top used websites.
how i can trace ?
monitoring tool is blue-coat packet shaper.
0
Defend Your Organization from The Greatest Threats

Looking to fill the gaps in your security? Bring together information from the network, endpoint and threat intelligence feeds to really see what's happening in your organization. Join the WatchGuardians in their adventures fighting cyber crime!

 
LVL 38

Expert Comment

by:Gerwin Jansen, EE MVE
ID: 36525568
You have a packet shaper, shape your HTTP Tunnel traffic down to 5% of your available bandwidth, that fixes your issue. And that's what your bluecoat box is for.
0
 

Author Comment

by:osloboy
ID: 36528556
hi gerwinjansen:
we have both boxes,
blue-coat and packet shaper as well.

can packet shaper can do this to mimize traffic for HTTP tunnel with out the inforamtion of source address ?
0
 
LVL 38

Accepted Solution

by:
Gerwin Jansen, EE MVE earned 400 total points
ID: 36528738
>>can packet shaper can do this to mimize traffic for HTTP tunnel with out the inforamtion of source address?
It should as it is a type of traffic. I don't know about the BlueCoat specific product but you could ask them, you are not completely familiar with your 2 boxes I understand? It's a main feature of their packet shaper.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VPN Tunnel Stops Working Cisco RV130W 18 77
TZ400 VPN Clients 5 42
VPN, Squid-  unable to log https requests 5 119
how to know if a router is connected to a certain port 9 49
A few customers have recently asked my thoughts on Password Managers.  As Security is a big part of our industry I was initially very hesitant and sceptical about giving a program all of my secret passwords.  But as I was getting asked about them mo…
Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question