How To Detect Dropped Internet Connection Reason - With WireShark?
Posted on 2012-04-02
Good Afternoon All -
I've got a network I'm currently working on which is experiencing issues with their internet. About 3 times an hour, they loose connectivity to the internet. During these times, i cannot even RDP to their SBS server - even when trying to connect to it's IP.
After reviewing many different things, I decided to start WireShark on their server's NIC and capture traffic - hoping to have a captured session when the drop hit. Well, after 2 hours, the log file is already over 1 gig and there's tons of info to go through.
I'm no expert at WireShark, but wanted to know if anyone had suggestions of what to specifically look for or search for to find clues in this gig of data.
Any other ideas would be helpful, too. They recently changed ISPs and are still having drops, so know it must be something internal. All cables have been swapped out so my belief is that it's something with the server or primary router (WatchGuard)