Solved

Wireshark switch port / LAG

Posted on 2014-09-05
3
577 Views
Last Modified: 2014-09-17
I am investigating some potential network issues (user base is blaming network so I'm attempting to prove it is not) and as a result have setup some basic bandwidth monitoring on a number of edge ports going to users PC's who appear to be frequently affected. I have also setup the same bandwidth monitoring on the LAG group and on the separate members of the LAG ports.

I have noticed that daily we experience a very odd heartbeat every 30 secs or so (obvious in the diagram attached) which I have no idea where it roots from. It's only present in one of the LAG members however. I've only just started placing times of the pattern appearing but it's very obvious when it is, as you'll see.

My question is how, without any formal monitoring SW in place at present, can I tell what the traffic is and where it's coming from? I've been told I can use wireshark but how to I go about setting that up to reflect what's going through a certain LAG or port?

Somebody mentioned connecting a laptop to the core and setup port mirroring. Our core is a Cisco 3750 stack and the edge is Cisco Small Business 500G stack.

Thanks,

Skijuice
Traffic-Stats.jpg
0
Comment
Question by:skijuice
3 Comments
 
LVL 12

Assisted Solution

by:Bryant Schaper
Bryant Schaper earned 100 total points
ID: 40306342
not sure if the sb supports port mirroring, but that would capture the traffic, you can download a free trial of riverbed cascade pilot and see if it spots anything.  Netflow might me a better tool, cacti I think will analyze it.
0
 
LVL 11

Expert Comment

by:itguy565
ID: 40308509
0
 
LVL 57

Accepted Solution

by:
giltjr earned 400 total points
ID: 40309958
The 3750 definitely support port mirroring.    You can use Wireshark to capture and analyze the data.

The jpg file is a little fuzzy (maybe its my eyes), but it looks like your "heart beat" is 250Mbps every 30 seconds.  I would NOT call that a heart beat.  A heart beat should be a few bps, not a couple hundred Mbps a second.  That looks more like some type of file/folder/directory/system synchronization/replication.

I would assume the reason that member #1 shows nothing and member #2 shows the spike is that the traffic is a single TCP session between two hosts.  When you have a LAG group the traffic is balanced between the links based on various things, the configurable options on most Cisco devices are:

1) source/target MAC address
2) source/target IP address
3) source IP address+source port/target IP address+target port.

Once a link is picked based on the above, the traffic stays on that link until the link goes down, or in the case of #3, the TCP connection is torn down a new connection is established.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
using BGP Attributes 2 87
Is it possible to send outbound mail (using SMTP) from EC2 Instance in Private Subnet? 1 31
Internet Protocol Security question 3 71
Dns issues 4 35
Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question