Find White Papers
Home
About Us
List Your Papers
    
> Global Knowledge > Troubleshooting Slow Networks with Wireshark

Troubleshooting Slow Networks with Wireshark

White Paper Published By: Global Knowledge

This white paper examines how to use Wireshark, the world's most popular open-source network analyzer, to troubleshoot some of the top causes of poor network performance.



Tags : 
troubleshooting, troubleshoot, slow, network, wireshark, certification program, tcp/ip, network analyzer

Global Knowledge
Published:  Jun 16, 2009
Type:  White Paper
Length:  11 pages

Expert Reference Series of White Papers
Troubleshooting
Slow Networks with
Wireshark
1-800-COURSES www.globalknowledge.comTroubleshooting Slow Networks with
Wireshark
Laura Chappell, Founder, Wireshark University and Chappell University
IntroductionYour phone begins ringing before you find a suitable spot to put down your first comforting cup of coffee in the morning. Users are complaining that the network is slow - web browsing sessions are painfully sluggish and email takes forever to download. They state that they simply can't work this way.
The problem appears to be widespread as your coffee cools faster than the users' tempers. A lack of error mes-sages or network alarms makes the problem more elusive and guarantees you'll be hunting down the problem well through lunchtime - at least.
Could the problem be related to the infrastructure devices? Is a rogue switch dropping packets periodically? What about the servers? Could the email server finally be giving in to the pressure of handling all those email chain letters the users pass amongst themselves? What is the chance that the users' systems have been compro-mised with a virus or bot that is spreading stealthily through the shadows of the network like the plague?
In this white paper, we examine how to use Wireshark, the world's most popular open-source network analyzer, to troubleshoot some of the top causes of poor network performance, including. High latency. Packet loss. Inefficient window sizes. Intercepting devices. Application dependencies
First, we'll look at Wireshark and examine methods used to "see" network communications.
Wireshark: The Open-Source Network SaviorWireshark, formerly Ethereal, is the world's most popular open-source network analyzer and the ideal first-re-sponder tool on a troubled network. Wireshark enables you to "see" the network communications and defini-tively point to where the problem lies. Although it cannot tell you why the problem exists, Wireshark reduces the troubleshooting time and effort drastically by providing a definitive answer to the location of the problem - removing the guesswork that typically consumes the IT professional's time while users impatiently wait for their network services to be restored.
Copyright ©2009 Global Knowledge Training LLC. All rights reserved. 2A system loaded with Wireshark is connected to the network using one of the methods defined below. Network traffic is captured and decoded by Wireshark's dissectors, predefined code that breaks apart the packets into their fields and field contents. Wireshark also contains an Expert system that identifies possible problems in network communications, thereby shortening the problem isolation process further. For more information on Wireshark, visit www.wireshark.org.
The Naked NetworkThe first step in analyzing network performance is to capture the network traffic. Ideally, you'll capture the traf-fic to and from a complaining host system from a location as close to that user as possible. You want to experi-ence the slow performance from their perspective and their location on the network.
There are four basic options available to capture network traffic.. Load Wireshark directly on one of the host systems.. Insert a network hub between a host and a switch (half-duplex).. Insert a network tap between a host and a switch (full-duplex).. Span the switch port of a user to an analyzer port.
Loading Wireshark on the User's SystemThis option makes my skin crawl a bit. I detest the idea of being so invasive and have nightmares imagining the users running Wireshark on their systems with little or no knowledge of network communications. This would be my least-favorite recommendation.
Hubbing OutThis is a great option for half-duplex networks. Simply remove the cable from the user's system and connect it to a hub. With another cable, connect the user's system and your analyzer to the hub as shown in the diagram below. Hubs are stupid - they only know 1s and 0s, and forward all bits down all active ports. All traffic to or from your user's system will be copied to your analyzer as well.
Tapping OutHubs work great on half-duplex networks, but most of us have migrated to full-duplex networks. Hubs can't handle these full duplex communications; this is the job for a full-duplex tap. The connection process would be the same as shown... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search