Networking Forums

Networking Forums > Computer Networking > Windows Networking > How to start Ethereal capture at network usage threshold?

Reply
Thread Tools Display Modes

How to start Ethereal capture at network usage threshold?

 
 
ryanlink@gmail.com
Guest
Posts: n/a

 
      06-02-2006, 09:02 PM
Hi,

I am trying to sniff out the source of big spikes in our bandwidth
utilization on a private school LAN. XO is the ISP. The gateway is a
Cisco router, behind which is a Netscreen firewall. Two or three times
a day, we are seeing pretty massive network spikes, which occasionally
result in slowdowns or shutdowns of the LAN.

I would like to use Ethereal or some other tool to monitor the packet
flow above a certain bandwidth, but I'm not sure how to go about doing
this. I'm currently running it on a Win2K3 server which is doing DNS
and DHCP, as well as Active Directory. It's a mixed-platform network,
lots of Mac workstations and two Mac servers (one running secondary
DNS).

Main switch is a stack of 4 3Com #C17300 24-porters... I've
successfully used SwitchMonitor to connect to these, but am seeing
nothing unhealthy.

Key point: I'm outsourced IT for this school, so I'm not on-site all
the time. I do have remote access.

Any suggestions? Should I set a timer to capture all promiscuous
packets between 6:30-7am, perhaps, when we often see a spike? How
would I go about doing that?

Thanks,
Ryan

 
Reply With Quote
 
 
 
 
Mike Lowery
Guest
Posts: n/a

 
      06-05-2006, 03:25 PM
To monitor bandwidth you must capture ALL packets on the network. Ethereal will
allow you to do just that. You can then plot the bandwidth using built-in
charting.

If you want to monitor between certain times you may need to use Windows Task
Scheduler and write a script or two. Winpcap might be easier in this case.
Windows Server 2003 also comes with a packet sniffer app similar to Ethereal.

<(E-Mail Removed)> wrote in message
news:(E-Mail Removed) ups.com...
> Hi,
>
> I am trying to sniff out the source of big spikes in our bandwidth
> utilization on a private school LAN. XO is the ISP. The gateway is a
> Cisco router, behind which is a Netscreen firewall. Two or three times
> a day, we are seeing pretty massive network spikes, which occasionally
> result in slowdowns or shutdowns of the LAN.
>
> I would like to use Ethereal or some other tool to monitor the packet
> flow above a certain bandwidth, but I'm not sure how to go about doing
> this. I'm currently running it on a Win2K3 server which is doing DNS
> and DHCP, as well as Active Directory. It's a mixed-platform network,
> lots of Mac workstations and two Mac servers (one running secondary
> DNS).
>
> Main switch is a stack of 4 3Com #C17300 24-porters... I've
> successfully used SwitchMonitor to connect to these, but am seeing
> nothing unhealthy.
>
> Key point: I'm outsourced IT for this school, so I'm not on-site all
> the time. I do have remote access.
>
> Any suggestions? Should I set a timer to capture all promiscuous
> packets between 6:30-7am, perhaps, when we often see a spike? How
> would I go about doing that?
>
> Thanks,
> Ryan
>



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Network Monitor Capture TSAM Windows Networking 1 03-04-2008 05:30 PM
Can't launch ethereal--- bash: ethereal: command not found krakov@mailinator.com Linux Networking 1 06-20-2005 10:16 AM
Adjusting Ethereal's Capture-Filters for Web-Address filtering? Felix Eggbert Linux Networking 1 10-25-2004 03:19 PM
Network cable to capture data.. BWGames Linux Networking 2 04-30-2004 08:31 AM
Fragmentation threshold? Roderick Stewart Wireless Internet 3 02-09-2004 07:35 AM



1 2 3 4 5 6 7 8 9 10 11