In this slide, I review some of the basic reasons provided to Fluke Networks Research as to why customers state Performance Problems take longer to address.
Broadcast Analysis – UPNP
I’ve written many articles on how broadcasts or multicasts can affect performance. I’ve seen as little as 10% broadcast rate cause issues on wireless networks as well as lock up network attached devices.
One of the broadcasts I try to minimize are UPNP and SSDP packets. The methodology used is quite simple, I perform a pc boot up and login baseline. Then I disable UPNP and SSDP and retest the computer. When I’m sure it is not needed, then I start a capture with the following capture filter ‘udp port 1900’. The list of addresses
...
https://www.youtube.com/watch?v=HZHdfYDhxEQ
Analyzing Multiple Trace Files- Setup
I get many emails asking for assistance when you have multiple trace files. Lets start with a quick review of the benefits of having multiple trace files:
- Determine the source of lost packets
- Determine network latency
- Determine the source of out of sequence packets
The hardest part of this process is the setup or preparing your trace files. I try to keep the capture points as consistent as possible. For example, if you have Wireshark installed on your server, I would prefer that you have Wireshark installed on the client computer. If you span the server port, I would prefer we span the client port, that sort of thing.
If you use Wireshark, use Wireshark for all your captures, don’t have a Wireshark capture from the client, but a capture from your router using its capture software. I’m sure you see where I’m going with this.
Next step is determine
read the full article at networkdatapedia.com when its posted
https://www.thetechfirm.com
Getting things to work better - bit by bit-
Linkedin Profile https://ca.linkedin.com/in/fortunat
Youtube Channel: https://www.youtube.com/user/thetechfirm
NetworkDataPedia Blog: https://www.networkdatapedia.com/blog/author/Tony-Fortunato
Network Computing Blog: https://www.networkcomputing.com/author/tony-fortunato
Linkedin Company URL: https://www.linkedin.com/company/the-tech-firm/
...
https://www.youtube.com/watch?v=cPZOnonkavU
In this video I explain some of the basic items we look for when we capture some Spanning Tree packets.
Enjoy
...
https://www.youtube.com/watch?v=yltiEqPQXJI
NMAP Baseline
I constantly say that you can baseline anything, anytime. it is a great to practice with your tools, keep your skills sharp and learn something new.
In this video I go over a simple NMAP command and what it does under the hood. Along the way I, share some Wireshark tips and tricks as well as a protocol review.
Nothing more to say, let's get at it.
...
https://www.youtube.com/watch?v=mT80YTJ-_NA
Funny how this video of me taken about 10+ years ago is still so relevant.
I cannot tell you how frustrating and surprising it is to run into technicians who are not willing to try new tools.
I find this to be more the case with tools or software that you have to pay for. Some technicians will try free software, but not give it a chance and quickly go back to their ‘old trusty tool’.
The problem is that as networks evolve, your methodology, tools and knowledge have to evolve with it. I personally think it should be every analyst to keep up with tools with the same degree of attention that they spend on routers, switches or server.
A great example for Windows users is good old ping. Many analysts are not aware that with every version of operating system, Microsoft is adding new options
...
https://www.youtube.com/watch?v=sRRlToh5hPc
I got a few emails from people checking up on me to be sure that all is well.
I'm doing just fine, just busy working on the coreitpros.com material.
Here's a quick one showing you how to create a display filter, mark, and then save those marked packets.
Enjoy
...
https://www.youtube.com/watch?v=fI4-MsW6Sqw
WIRESHARK IO Graphs And Filters
Its been over 20 years of installing, troubleshooting, training and writing and I still think the biggest issue in IT is the technician’s working knowledge of their everyday tools. It doesn’t matter if it’s a physical tool like a cable tester or software, you should not only be familiar with it, but with any changes with upgrades.
In this case I chose Wireshark and wanted to show you how display filters affect IO graphs. As I mentioned in the video, this can be ‘bad’ or ‘good’. Which one depends if you know about this new ‘feature’ or not.
I always suggest you ‘use your favorite tools one a regular basis so you can spot some of these changes when they appear so you aren’t caught off guard when you are in the middle of troubleshooting.
...
https://www.youtube.com/watch?v=M_8m-U-9YwQ
Looking Out for ip helper Related Issues
I always seem to get involved or end up in network clean ups. ‘Clean ups’ can involve physical equipment removal but also includes equipment configuration validation and optimization.
In this video I cover the typical Cisco ip helper-address command and how it can affect hosts. I would like to point out that this commonly used command forwards various UDP broadcast protocols to a specific device. I have actually seen ip helper-addresses configured with a broadcast address (not recommended) that has cause some pretty weird issues. With this specific topic, there are a few alternatives you can use to optimize this configuration from blocking unwanted protocols with an access control list, using the no ip forward-protocol udp, service command, dhcp relay and those are just off the top of my head.
The key here is that I used Wireshark to simply capture some packets of a Microsoft computer broadcasting its typical protocols and how the network equipment reacts to it. I term these exercises PC bootup baseline, PC idle baseline and of course PC login baseline. I can’t stress the importance of performing these baselines to get a true picture of how your network and equipment behaves before you have an issue.
I always sarcastically say to my clients that if you perform a baseline correctly, you will have some research to do. And in most cases, you will have some changes to make. I like using captures or anything quantitative so I can see what difference my changes make.
...
https://www.youtube.com/watch?v=Zb8n53jczM4
I’ve received a lot of feedback from my readers expressing their gratitude that my articles/videos are short and to the point. To those people who took the time to send their feedback, thank you.
One topic that I’ve been asked to cover lately is TCP sequence number analysis. There are many videos out there that are very good. I know, since I watched quite a few of them ;)
After watching 4 or 5 of these videos, I noticed that they weren’t geared towards analysts getting into this level of analysis for the first time and missed a few items that I would have added. So here you go.
In this video I briefly’ cover some of the TCP sequence tips and tricks that I use in the field. The important part is to remember that by default
...
https://www.youtube.com/watch?v=bQ9ZPkZ6ru4