dslreports logo
 
    All Forums Hot Topics Gallery
spc
uniqs
26

Brano
I hate Vogons
MVM
join:2002-06-25
Burlington, ON
(Software) OPNsense
Ubiquiti UniFi UAP-AC-PRO
Ubiquiti NanoBeam M5 16

Brano to t10

MVM

to t10

Re: Rogue/faulty device eating all bandwidth. Need to find it.

What Cisco router you have there? Model?
Do you have managed switch(es) there?

You need to deploy sniffer on LAN side and see where's the problem.
Alternatively, if the Cisco router supports SNMP and some nice stats you may be able to get info you need that way.

But managed switch with monitoring (sniffing, mirroring) port is what you need. You route all LAN through the switch, hook up wireshark to your monitoring port and examine all the traffic.
t10
join:2003-05-25
Woodbridge, ON

t10

Member

Thanks Brano! Total DUH on my part re Wireshark (tried SolarWinds NTA, and that didnt tell me anything unfortunately).

The Cisco is RV042.
No managed switches on the premises. Would need to buy one, any recommendations (unfortunately in our case the cheaper the better).

Brano
I hate Vogons
MVM
join:2002-06-25
Burlington, ON
(Software) OPNsense
Ubiquiti UniFi UAP-AC-PRO
Ubiquiti NanoBeam M5 16

1 edit

Brano

MVM

I have this one (and am very happy with it) »www.ncix.ca/products/?sk ··· oid=1448 ... it's one of the cheapest gigabit out there and will do what you need.
Manual here »ftp://ftp.dlink.com/Switch/dgs110016/

Plug your RV042 to it, all other LAN connections (direct or from other switches) as well.
Then designate one port as monitoring and connect to it from your sniffer machine running wireshark.

The switch has per-port stats, bandwidth management and more features that you can utilize to manage your issue.

There are more port versions available too (more expensive).

EDIT: There's a deal on this one now »www.ncix.ca/products/?sk ··· P%20Link ...mind this is 100meg and only 2 Gb ports. ...I've never used this one so can't provide recommendations.
cramer
Premium Member
join:2007-04-10
Raleigh, NC
Westell 6100
Cisco PIX 501

1 recommendation

cramer to t10

Premium Member

to t10
That's a Linksys. If you had a Real Cisco(tm) (IOS, Pix, ASA) this would take seconds to track down... "sh ip nat tr" Why does Bob's computer have 8000 translations?

Also, with a managed switched and MRTG, you could see where all the traffic is going in an instant. (I also use netflow, so I know what you did last week.)