Solved

internet slow

Posted on 2011-09-12
6
358 Views
Last Modified: 2012-06-21
Hi Experts,
the users in my network facing very slow network speed. when i obsreve it on monitoring tool i found that "HTTP TUNNEL"  consuming 80 to 90 percent bandwidth of my internet link.

on google i find that HTTP-TUNNEL traffic because  of users in network download softwares(hot spot shied and some others) to unblock the restricted websites.Is there any solution to block HTTP TUNNEL traffic. OR i should stop it on internet router  or on internal firewall.
or any-other soultion to get rid of this traffic.


Thanks,
0
Comment
Question by:osloboy
  • 3
  • 2
6 Comments
 
LVL 37

Expert Comment

by:Gerwin Jansen
ID: 36522828
Can you find out in your monitoring tool from what IP address the HTTP tunnel is originating? Trace down that user / workstation and uninstall it, informing the user of your company internet policy.
0
 
LVL 7

Assisted Solution

by:CSorg
CSorg earned 100 total points
ID: 36523439
could be regular traffic, for instance RDP over SSL connection(s)

RDP is aggressive when it comes to claiming network bandwidth.

like gerwinjansen said, try to isolate the source ip address first and start a local monitor (netstat -o would give you back information on the process and in what why that process is using network traffic)
(http://ss64.com/nt/netstat.html)
0
 

Author Comment

by:osloboy
ID: 36524871
monitoring tool doesnt show the source ip adress. it just show the top used websites.
how i can trace ?
monitoring tool is blue-coat packet shaper.
0
6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

 
LVL 37

Expert Comment

by:Gerwin Jansen
ID: 36525568
You have a packet shaper, shape your HTTP Tunnel traffic down to 5% of your available bandwidth, that fixes your issue. And that's what your bluecoat box is for.
0
 

Author Comment

by:osloboy
ID: 36528556
hi gerwinjansen:
we have both boxes,
blue-coat and packet shaper as well.

can packet shaper can do this to mimize traffic for HTTP tunnel with out the inforamtion of source address ?
0
 
LVL 37

Accepted Solution

by:
Gerwin Jansen earned 400 total points
ID: 36528738
>>can packet shaper can do this to mimize traffic for HTTP tunnel with out the inforamtion of source address?
It should as it is a type of traffic. I don't know about the BlueCoat specific product but you could ask them, you are not completely familiar with your 2 boxes I understand? It's a main feature of their packet shaper.
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Foreword In the years since this article was written, numerous hacking attacks have targeted password-protected web sites.  The storage of client passwords has become a subject of much discussion, some of it useful and some of it misguided.  Of cou…
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now