Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 625
  • Last Modified:

Wireshark switch port / LAG

I am investigating some potential network issues (user base is blaming network so I'm attempting to prove it is not) and as a result have setup some basic bandwidth monitoring on a number of edge ports going to users PC's who appear to be frequently affected. I have also setup the same bandwidth monitoring on the LAG group and on the separate members of the LAG ports.

I have noticed that daily we experience a very odd heartbeat every 30 secs or so (obvious in the diagram attached) which I have no idea where it roots from. It's only present in one of the LAG members however. I've only just started placing times of the pattern appearing but it's very obvious when it is, as you'll see.

My question is how, without any formal monitoring SW in place at present, can I tell what the traffic is and where it's coming from? I've been told I can use wireshark but how to I go about setting that up to reflect what's going through a certain LAG or port?

Somebody mentioned connecting a laptop to the core and setup port mirroring. Our core is a Cisco 3750 stack and the edge is Cisco Small Business 500G stack.

Thanks,

Skijuice
Traffic-Stats.jpg
0
skijuice
Asked:
skijuice
2 Solutions
 
Bryant SchaperCommented:
not sure if the sb supports port mirroring, but that would capture the traffic, you can download a free trial of riverbed cascade pilot and see if it spots anything.  Netflow might me a better tool, cacti I think will analyze it.
0
 
giltjrCommented:
The 3750 definitely support port mirroring.    You can use Wireshark to capture and analyze the data.

The jpg file is a little fuzzy (maybe its my eyes), but it looks like your "heart beat" is 250Mbps every 30 seconds.  I would NOT call that a heart beat.  A heart beat should be a few bps, not a couple hundred Mbps a second.  That looks more like some type of file/folder/directory/system synchronization/replication.

I would assume the reason that member #1 shows nothing and member #2 shows the spike is that the traffic is a single TCP session between two hosts.  When you have a LAG group the traffic is balanced between the links based on various things, the configurable options on most Cisco devices are:

1) source/target MAC address
2) source/target IP address
3) source IP address+source port/target IP address+target port.

Once a link is picked based on the above, the traffic stays on that link until the link goes down, or in the case of #3, the TCP connection is torn down a new connection is established.
0

Featured Post

Get Certified for a Job in Cybersecurity

Want an exciting career in an emerging field? Earn your MS in Cybersecurity and get certified in ethical hacking or computer forensic investigation. WGU’s MSCSIA degree program was designed to meet the most recent U.S. Department of Homeland Security (DHS) and NSA guidelines.  

Tackle projects and never again get stuck behind a technical roadblock.
Join Now