Dragon0x40
asked on
Create a baseline with Wireshark
Has anyone ideas on how to baseline a network with wireshark?
Span the port a workstation is on and then start capturing? Get the boot up, dhcp, start applications?
How about the network itself? With switches you only get broadcast and traffic to your computer.
How long should the capture last?
Do you need a capture for each model of workstation, laptop and server?
Span the port a workstation is on and then start capturing? Get the boot up, dhcp, start applications?
How about the network itself? With switches you only get broadcast and traffic to your computer.
How long should the capture last?
Do you need a capture for each model of workstation, laptop and server?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Do I need to take one every day, week, etc.?
How long should I capture the traffic for?
I don't have huge amounts of disk space to play with and spanning on a core router would need authorization because of the possibility of an increased load or affecting traffic flow.
Capture everything?