Network Issue Troubleshooting Tools

Greetings Experts,

I'm currently hearing the complaint that we all dread hearing..."the network is slow."  I know there can be multiple culprits in this scenario, and I have been digging for 3 days.  So far, there is nothing remarkable with respects to port errors, speed/duplex, etc.  It's a pretty simple network in a small school, with 5 switches in the main MDF, and 2 switches in each of the 2 IDF's. It connects via WAN back to the main Data Center in a separate building a few miles across town for all server based services except for client imaging.  There are 18 other schools in this area with practically the same setup, but this is the only one that's slow.  And it's not only slow for external data retrieval like Internet, Hosted applications (in centralized Data Center) but for internal traffic as well.  I know this, because when I image computers with the local imaging server that is on the same LAN, it takes 4 times as long as any other site.  All sites have pretty much the same makes/models of LAN switching.  

So, the reason for this post, is I am looking for a good tool that can identify issues at a very granular level on a network. I don't care if I have to let it sit there and run for a week or two.  Obviously sooner is better, but I really need to be able to test everything from in layers 1-4 and identify the contributing factor(s).

Thanks in advance for your insight.
James FryEnterprise Solutions ArchitectAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Chris HInfrastructure ManagerCommented:
Have you used wireshark before?

You could install it on a workstation on your lan and investigate to see if you have some kind of broadcast or spanning tree.  

All the link lights are indicating full speed?  
Is there an excessive amount of blinking on or off hours?
Have you replaced your switches?  (they go bad from time to time.  Usually capacitors which cause sludgy performance)
Are you sure you don't have an issue with a domain controller and DNS requests and authentication attempts are just painfully slow?
Pizza ITSupport EngineerCommented:
I would recommend a very good tool called PRTG.  The free version allows you 100 sensors to help you gain some much needed insight into what is going on within your switches and firewalls.  There are hardware vendor specific sensors that employ snmp, Netflow, etc.  You will be able to measure latency, network gear CPU utilization etc.  

For what it is worth I would focus on your LAN switches since you are experiencing LAN imaging performance degradation.

https://www.paessler.com/prtg/download

-Pizza

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
James FryEnterprise Solutions ArchitectAuthor Commented:
At choward16980.

I appreciate your feedback.  Truth be told, I did a packet capture, but I really don't work with enough of them to be able to differentiate normal from abnormal, or really be able to accurately identify something as an issue.

I did check all of the usual metrics like lights, port counters, etc.  But still seeing issues.  All uplinks and access ports are properly negotiating speed and duplex.

I haven't tried replacing switches, obviously it's crossed my mind, but It's not much of an option right now due to fiscal limitations and the inability to go grab them from somewhere else without leaing them down.

DNS all checks out, like I said, this school sends it's queries to the same place all of the others do, but they are having no issues.  Same DNS servers in DHCP allocations as the other buildings, etc.

Any other thoughts?
nader alkahtaniInformation security consultantCommented:
I would use the free great tool like  iperf3.1.2,  test with UDP port to find packet lose.
Wireshark is great so,  but capture in when the network running smoothly and with slowness,  then  compare.
James FryEnterprise Solutions ArchitectAuthor Commented:
Thanks all for your input.  I appreciate it!
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Network Architecture

From novice to tech pro — start learning today.