Networking Forums

Networking Forums > Computer Networking > Windows Networking > What's causing my high ARP traffic???

Reply
Thread Tools Display Modes

What's causing my high ARP traffic???

 
 
Ed Flecko
Guest
Posts: n/a

 
      12-13-2005, 10:40 PM
Hi folks,
I have a small 2003 domain of 3 servers and about 35 PCs, with 2 sites
connected via T-1. All 3 servers have 2003 standard, and are fully patched &
updated. All 3 servers are DCs, run DNS and DFS (which I have had problems
with), and 1 server on each site is a DHCP server. I use McAfee corporate
anti-virus. Every day, predictably between appx. 4-8 am my T-1 is saturated
with traffic. I've used ethereal and captured traffic during this time, and
appx. 31% of the traffic is ARP, 24% is TCP, etc. Of the ARP traffic only,
49% is from one of my servers! Isn't this unusual (it seems really high to
me)?

I welcome any suggestions and comments. This predictably high bandwidth
saturation is driving me crazy! Comments...suggestions???

Thank you,
Ed
 
Reply With Quote
 
 
 
 
Bill Grant
Guest
Posts: n/a

 
      12-14-2005, 12:28 AM
I wouldn't expect to see any ARP traffic on a WAN link. Are the two
sites in the same IP subnet? Are you using some sort of bridge?

Ed Flecko wrote:
> Hi folks,
> I have a small 2003 domain of 3 servers and about 35 PCs, with 2 sites
> connected via T-1. All 3 servers have 2003 standard, and are fully
> patched & updated. All 3 servers are DCs, run DNS and DFS (which I
> have had problems with), and 1 server on each site is a DHCP server.
> I use McAfee corporate anti-virus. Every day, predictably between
> appx. 4-8 am my T-1 is saturated with traffic. I've used ethereal and
> captured traffic during this time, and appx. 31% of the traffic is
> ARP, 24% is TCP, etc. Of the ARP traffic only, 49% is from one of my
> servers! Isn't this unusual (it seems really high to me)?
>
> I welcome any suggestions and comments. This predictably high
> bandwidth saturation is driving me crazy! Comments...suggestions???
>
> Thank you,
> Ed



 
Reply With Quote
 
Neteng
Guest
Posts: n/a

 
      12-14-2005, 01:45 PM
How do you know the T1 is saturated? What are you using for routers?
Remember that the 49% is of traffic ethereal has seen, not 49% of the line.
How long did you let ethereal run?

"Ed Flecko" <(E-Mail Removed)> wrote in message
news:071C6E98-7189-4C21-B744-(E-Mail Removed)...
> Hi folks,
> I have a small 2003 domain of 3 servers and about 35 PCs, with 2 sites
> connected via T-1. All 3 servers have 2003 standard, and are fully patched

&
> updated. All 3 servers are DCs, run DNS and DFS (which I have had problems
> with), and 1 server on each site is a DHCP server. I use McAfee corporate
> anti-virus. Every day, predictably between appx. 4-8 am my T-1 is

saturated
> with traffic. I've used ethereal and captured traffic during this time,

and
> appx. 31% of the traffic is ARP, 24% is TCP, etc. Of the ARP traffic only,
> 49% is from one of my servers! Isn't this unusual (it seems really high to
> me)?
>
> I welcome any suggestions and comments. This predictably high bandwidth
> saturation is driving me crazy! Comments...suggestions???
>
> Thank you,
> Ed



 
Reply With Quote
 
Ed Flecko
Guest
Posts: n/a

 
      12-14-2005, 05:40 PM
Hey, thanks for the response guys. Let me see if I can answer all of the
questions:

The two sites are their own subnets. I have a Netgear switch, and I have the
T-1 port on the switch mirroring its traffic to the port that I have ethereal
listening on. I let the ethereal capture run for about a week. The sole
purpose of the T-1 is to connect the two sites (subnets). I use PRTG
(Paessler Router Traffic Grapher) to monitor the traffic. Suggestions? Thank
you for your help.

Ed

"Bill Grant" wrote:

> I wouldn't expect to see any ARP traffic on a WAN link. Are the two
> sites in the same IP subnet? Are you using some sort of bridge?
>
> Ed Flecko wrote:
> > Hi folks,
> > I have a small 2003 domain of 3 servers and about 35 PCs, with 2 sites
> > connected via T-1. All 3 servers have 2003 standard, and are fully
> > patched & updated. All 3 servers are DCs, run DNS and DFS (which I
> > have had problems with), and 1 server on each site is a DHCP server.
> > I use McAfee corporate anti-virus. Every day, predictably between
> > appx. 4-8 am my T-1 is saturated with traffic. I've used ethereal and
> > captured traffic during this time, and appx. 31% of the traffic is
> > ARP, 24% is TCP, etc. Of the ARP traffic only, 49% is from one of my
> > servers! Isn't this unusual (it seems really high to me)?
> >
> > I welcome any suggestions and comments. This predictably high
> > bandwidth saturation is driving me crazy! Comments...suggestions???
> >
> > Thank you,
> > Ed

>
>
>

 
Reply With Quote
 
Neteng
Guest
Posts: n/a

 
      12-14-2005, 07:21 PM
If your running Cisco routers, turn on nbar and you can graph (with PRTG) by
protocol. That should help narrow it down. What is your one server that's
arping looking for? Local addresses?

"Ed Flecko" <(E-Mail Removed)> wrote in message
news:F914EC6E-224B-453F-B7AB-(E-Mail Removed)...
> Hey, thanks for the response guys. Let me see if I can answer all of the
> questions:
>
> The two sites are their own subnets. I have a Netgear switch, and I have

the
> T-1 port on the switch mirroring its traffic to the port that I have

ethereal
> listening on. I let the ethereal capture run for about a week. The sole
> purpose of the T-1 is to connect the two sites (subnets). I use PRTG
> (Paessler Router Traffic Grapher) to monitor the traffic. Suggestions?

Thank
> you for your help.
>
> Ed
>
> "Bill Grant" wrote:
>
> > I wouldn't expect to see any ARP traffic on a WAN link. Are the two
> > sites in the same IP subnet? Are you using some sort of bridge?
> >
> > Ed Flecko wrote:
> > > Hi folks,
> > > I have a small 2003 domain of 3 servers and about 35 PCs, with 2 sites
> > > connected via T-1. All 3 servers have 2003 standard, and are fully
> > > patched & updated. All 3 servers are DCs, run DNS and DFS (which I
> > > have had problems with), and 1 server on each site is a DHCP server.
> > > I use McAfee corporate anti-virus. Every day, predictably between
> > > appx. 4-8 am my T-1 is saturated with traffic. I've used ethereal and
> > > captured traffic during this time, and appx. 31% of the traffic is
> > > ARP, 24% is TCP, etc. Of the ARP traffic only, 49% is from one of my
> > > servers! Isn't this unusual (it seems really high to me)?
> > >
> > > I welcome any suggestions and comments. This predictably high
> > > bandwidth saturation is driving me crazy! Comments...suggestions???
> > >
> > > Thank you,
> > > Ed

> >
> >
> >



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
router connection causing high cpu usage J L Williams Network Routers 4 12-06-2006 08:14 AM
Tuning for high volume web traffic Rodrick Brown Linux Networking 2 11-13-2005 05:24 PM
High traffic on one AP hurts another Kevin Brown Wireless Internet 0 11-08-2005 02:25 AM
High network traffic every few days, reset required proph3t Network Routers 0 03-26-2005 07:38 AM
Network card gets stuck after some time of high traffic load Paul Wilhelm Elsinghorst Linux Networking 0 03-07-2005 11:31 AM



1 2 3 4 5 6 7 8 9 10 11