Solved

How to determine which device is sending bad packets to server?

Posted on 2014-12-09
3
198 Views
Last Modified: 2014-12-19
We have an older version of Microsoft Dynamics Navision on our network. Over the past few weeks it's been reporting an error - error 18 in module 244, multiple times/day, in the Windows 2003 server event log. Research on this error points to a network issue, possibly CRC, or some other related situation where bad packets are sent to the Navision server.

However, I haven't found a good way to determine which device (we have 100+ users) is sending the bad packets. I've replaced the NIC and cable on the server, and that didn't help. I've installed Wireshark, and I've tried looking for anything odd around the time the log entries are recorded, but I'm new to it and I don't know what to look for specifically, as nothing stood out.

Thanks.
0
Comment
Question by:ruhkus
3 Comments
 
LVL 35

Accepted Solution

by:
Kimputer earned 300 total points
ID: 40489062
You have more problems here. Mainly because you don't know what you're looking for. I actually, highly doubt you would find it even IF you knew the problem with more details.
That's because right now, you think it's about "sending bad packets". This alone will help absolutely no one. Are those TCP packets ? On which port do they arrive. Even then the next question would be, how do you detect a bad packet from a good packet. I highly doubt you would find it in Wireshark with any filter you write.
A better solution would be to update your software. Proper software should not error when bad packets are sent. And proper software shouldn't send packets (so update both server and clients).
If you can't, there's nothing more you can do then methodically disconnect groups of PC's and see how it behaves, and continue untill you have positive results (and then divide that group again until you have the "culprit").
0
 

Author Comment

by:ruhkus
ID: 40489091
We're actually moving to a new server with a new version of Navision software in a few months (data cleanup alone will take awhile). However, this means nothing to the 80 or so staff that rely on this program daily until then.

But yeah, I have no real idea what can best help track down this issue, and there doesn't seem to be a really viable way, since the rest of the network is running fine.
0
 
LVL 8

Assisted Solution

by:nader alkahtani
nader alkahtani earned 200 total points
ID: 40489355
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

On Sep 22nd 2014 Microsoft released Update Rollup 1 for Microsoft Dynamics CRM 2013 Service Pack 1 and back in July Update Rollup 3 was released.  So we now have:   Update Rollup 1Update Rollup 2Update Rollup 3Service Pack 1Update Rollup 1 for S…
Load balancing is the method of dividing the total amount of work performed by one computer between two or more computers. Its aim is to get more work done in the same amount of time, ensuring that all the users get served faster.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now