Solved

Wireshark switch port / LAG

Posted on 2014-09-05
3
533 Views
Last Modified: 2014-09-17
I am investigating some potential network issues (user base is blaming network so I'm attempting to prove it is not) and as a result have setup some basic bandwidth monitoring on a number of edge ports going to users PC's who appear to be frequently affected. I have also setup the same bandwidth monitoring on the LAG group and on the separate members of the LAG ports.

I have noticed that daily we experience a very odd heartbeat every 30 secs or so (obvious in the diagram attached) which I have no idea where it roots from. It's only present in one of the LAG members however. I've only just started placing times of the pattern appearing but it's very obvious when it is, as you'll see.

My question is how, without any formal monitoring SW in place at present, can I tell what the traffic is and where it's coming from? I've been told I can use wireshark but how to I go about setting that up to reflect what's going through a certain LAG or port?

Somebody mentioned connecting a laptop to the core and setup port mirroring. Our core is a Cisco 3750 stack and the edge is Cisco Small Business 500G stack.

Thanks,

Skijuice
Traffic-Stats.jpg
0
Comment
Question by:skijuice
3 Comments
 
LVL 11

Assisted Solution

by:Bryant Schaper
Bryant Schaper earned 100 total points
ID: 40306342
not sure if the sb supports port mirroring, but that would capture the traffic, you can download a free trial of riverbed cascade pilot and see if it spots anything.  Netflow might me a better tool, cacti I think will analyze it.
0
 
LVL 11

Expert Comment

by:itguy565
ID: 40308509
0
 
LVL 57

Accepted Solution

by:
giltjr earned 400 total points
ID: 40309958
The 3750 definitely support port mirroring.    You can use Wireshark to capture and analyze the data.

The jpg file is a little fuzzy (maybe its my eyes), but it looks like your "heart beat" is 250Mbps every 30 seconds.  I would NOT call that a heart beat.  A heart beat should be a few bps, not a couple hundred Mbps a second.  That looks more like some type of file/folder/directory/system synchronization/replication.

I would assume the reason that member #1 shows nothing and member #2 shows the spike is that the traffic is a single TCP session between two hosts.  When you have a LAG group the traffic is balanced between the links based on various things, the configurable options on most Cisco devices are:

1) source/target MAC address
2) source/target IP address
3) source IP address+source port/target IP address+target port.

Once a link is picked based on the above, the traffic stays on that link until the link goes down, or in the case of #3, the TCP connection is torn down a new connection is established.
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Suggested Solutions

This is an article about my experiences with remote access to my clients (so that I may serve them) and eventually to my home office system via Radmin Remote Control. I have been using remote access for over 10 years and have been improving my metho…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now