Solved

broadcast traffic

Posted on 2014-02-22
8
365 Views
Last Modified: 2014-04-08
I am trying to see how much traffic is generating in my vlan. When I did the sh int vlan 10, I see no broadcast but there are multicast. Is there a command to look at the broadcast for the vlan? Thanks
0
Comment
Question by:leblanc
8 Comments
 
LVL 57

Accepted Solution

by:
giltjr earned 500 total points
ID: 39879887
No command.  You will need to do a packet capture.

If you can get a computer on the VLAN/IP Subnet in question it would probably be easier than the other option.

The other option is to use port mirroring.  You either need physical access to a switch that is on the VLAN/IP subnet you want to monitor or you need switches that support RSPAN.  The only issue with RSPAN is if the VLAN generates a lot of traffic you could flood a link between switches.
0
 
LVL 20

Expert Comment

by:masnrock
ID: 39880609
Giltjr is 100% correct. As part of the capture, you will need to use tools such as Wireshark. But without doing what has already been mentioned, you will not be able to do it.
0
 
LVL 16

Expert Comment

by:SteveJ
ID: 39912783
What kind of device are you looking at (sh int vlan 10 sounds like Cisco) because Cisco absolutely shows broadcasts:

  L2 Switched: ucast: 15779125210 pkt, 18823193060427 bytes - mcast: 13524425 pkt, 1275607608 bytes
  L3 in Switched: ucast: 31588733531 pkt, 41521487754788 bytes - mcast: 0 pkt, 0 bytes mcast
  L3 out Switched: ucast: 31121695300 pkt, 18523037712040 bytes mcast: 0 pkt, 0 bytes
     31619970443 packets input, 41526015931352 bytes, 0 no buffer
     Received 13523539 broadcasts (0 IP multicasts)
     0 runts, 0 giants, 67 throttles

That's partial output from a VLAN on a Cisco 65xx

Good luck,
Steve
0
 
LVL 1

Author Comment

by:leblanc
ID: 39914172
Yes. It shows you the broadcast from the interface level. I am curious if I can get the number of broadcast for the whole vlan.
0
Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 57

Assisted Solution

by:giltjr
giltjr earned 500 total points
ID: 39914195
The SVI for the VLAN will receive all broadcasts on the VLAN.  So doing the show for the VLAN interface show all broadcasts.
0
 
LVL 1

Author Comment

by:leblanc
ID: 39914236
So if I have 2 switches each with interface vlan10. The number of broadcast will be the total of the two. Does it sound correct?
0
 
LVL 57

Assisted Solution

by:giltjr
giltjr earned 500 total points
ID: 39914651
No, all you need to do is look at one of them.  Rember a broadcast goes to ALL devices on that same VLAN (a.k.a layer 2 network).

Every device that is in the same layer 2 network will see ALL broadcasts.  So both of those interfaces will see all broadcasts.  There will be a slight difference in the number each of those SVI's will report, because they don't count the broadcasts they send out.

Say you have 100 PC's, and two SVI's.  If the 100 PC send out 500 broadcasts combined, SVI#1 sends out 10 and SVI #2 sends out 15, the SVI#1 will see 515 (the 500 from the PC's and the 15 from SVI#2) broadcasts  and SVI#2 will see 510  (the 500 from the PC and the 10 from SVI#1).

If you were to combine the two SVI counts, then you would be counting the 500 broadcasts from the PC's twice because each SVI would see all 500.
0
 
LVL 1

Author Comment

by:leblanc
ID: 39914975
Got it. Thx
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now