packet monitoring in high availability cluster

pulke13
pulke13 used Ask the Experts™
on
hello
I have a high availability Microsoft 2008 servers cluster.
I need to send tcp packets and monitor exactly how many packets are received on the servers while performing switch over.
Is there a tool that I can use ?

thank you
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Ryan McCauleySenior Data Architect

Commented:
Is there a reason you can't use ping? If you want to check a particular application or port (like if you've clustered SQL Server and want to see when it comes back up on port 1433), I'd recommend a tool called tcping:

http://www.elifulkerson.com/projects/tcping.php

If you've not used it before, it's an awesome tool that let's you perform ping functionality to any TCP port. Using this tool, you can repeatedly ping your application port, see it respond, see it unresponsive while you perform your failover, and then see it respond again once the service comes back up.

Author

Commented:
hello

thank you. I think I wasn't precise in my question.

We have a tcp packet sender that sends many tcp packets on the network , and we want to check that during the cluster switchover there are no packet loses.

So we need a tool that will monitor and give precise tcp packet traffic info on the cluster.

Thank you
Ryan McCauleySenior Data Architect

Commented:
Packets will be lost during the cluster failover - either because the service isn't currently online or during the new seconds it takes to switch ownership of the VIP from one server to the other. It should be brief, but it will definitely drop a few packets (unless you're trying to test the retry mechanics of your sending application).

However, you can use something like wireshark to capture the network traffic, if that's what you're after - you'll get a lot of noise as well from regular network chatter between the servers, but it will capture packets sent and their acknowledgement (or lack of) for you to analyze.
OWASP: Avoiding Hacker Tricks

Learn to build secure applications from the mindset of the hacker and avoid being exploited.

Author

Commented:
thank you
But if we want to count exactly how many packets were transferred\received- is there a way to do that?
Senior Data Architect
Commented:
Wireshark (or I actually prefer Netmon since you're using Windows and I find it easier to use) monitors traffic received by a server, so it can detect what packets are sent or received by a server at the network level. If the cluster is failing over, you'd have to monitor both nodes and track the aggregate of all the packets received, because they could go to either place. You'd have to compare that to a capture running on the server sending the packets, so you can be sure that you account for any packets dropped during the clustered IP ownership handoff.

Second to that, you'd have to have your clustered service log the packets or messages somehow (which is may already do) and compare that to the list of packets received by the wireshark capture - during the time the clustered application is starting up, it will drop additional packets that may have been received by the server itself, but which no application was actually listening for.

You'd have to keep track of both situations to ensure that you know what's being dropped by cluster failover time and what's being dropped by service startup time.

Author

Commented:
thank you very much

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial