Disease Posted June 30, 2015 Posted June 30, 2015 Hi all, I have strange ping fluctuations across my curriculum network (image attached), I have no idea what is causing it, but there seems to be a pattern to it. Any pointers in a direction to what could be causing it and finding the root cause? It's almost like some service that runs every my that chews all my network bandwidth or maybe I am clutching at straws.
Steve21 Posted June 30, 2015 Posted June 30, 2015 You stuck a tracert on it a few times? Found one before that had a spanning tree that keeps flicking etc Steve
geekgirl Posted June 30, 2015 Posted June 30, 2015 I noticed my machine was pinging out over 4000 requests a day after the network. I was recommended Wireshark (https://www.wireshark.org/) by a colleague of mine. It monitors packets being sent over the network and can tell you what program is using for which ports. You can filter the requests and find what is pinging across the network. I'd check your anti-virus to make sure you haven't got anything that could be pushing packets out - I know the annoying "Conduit Search" program does this. Mine was LanSchool Tech Console that was broadcasting these packets, spoke to LanSchool but they said it shouldn't be broadcasting that much so I'm going to re-build my machine when I have time so see if that helps.
Oaktech Posted June 30, 2015 Posted June 30, 2015 Is Impero running on your network? I've had Impero have a hissy fit and spam the network with enough traffic to make a noticeable slowdown until the server services were restarted...
CHR1S Posted June 30, 2015 Posted June 30, 2015 What are you pinging and where from, broadcom NIC's have issues on virtualised environments.
pantscat Posted June 30, 2015 Posted June 30, 2015 Do you get similar ping results from all (well, you know what I mean...) machines on the curriculum network?
sted Posted June 30, 2015 Posted June 30, 2015 What are you pinging and where from, broadcom NIC's have issues on virtualised environments. you mean they turn to tortoise speed in vms if virtual machine queues is enabled (which is the default) and copy speed can be measured in bytes per second rather than mbs 1
Duranis Posted June 30, 2015 Posted June 30, 2015 We have smart response "clickers". The software for them is constantly flooding the network with traffic even when it isn't being used.
Disease Posted June 30, 2015 Author Posted June 30, 2015 Do you get similar ping results from all (well, you know what I mean...) machines on the curriculum network? Yes, same results regardless of machine or server. No impero running, tracert only shows one hop, we run lanschool but no tech console, SCCM runs on the network.
CHR1S Posted June 30, 2015 Posted June 30, 2015 you mean they turn to tortoise speed in vms if virtual machine queues is enabled (which is the default) and copy speed can be measured in bytes per second rather than mbs Thats the one.....
pantscat Posted June 30, 2015 Posted June 30, 2015 Have you got decent switches? can you check the port stats? There might something that's chucking out a load of traffic. 1
Disease Posted June 30, 2015 Author Posted June 30, 2015 Will take a look, we have mostly HP procurve with a few odds and sods linksys non managed left over.
pantscat Posted June 30, 2015 Posted June 30, 2015 The procurve kit should definitely be able to give you some clues.
chazzy2501 Posted June 30, 2015 Posted June 30, 2015 what happens when you ping your own ip address (not 127) then ping something on the same switch then things on other switches. EDIT: oh and ping the switch it's self and the gateway.
IanT Posted June 30, 2015 Posted June 30, 2015 Couple of things... 1. HP ProCurve Manager should spot the issue 2. Have you had any new devices installed (i.e. PC's) last summer we had over 100 desktops which has a software bug in the NIC driver which flooded the network, driver updated and sloved the problem, we managed to find the issue running wireshark. 3. Use wireshark to capture the data 4. If you dont have hp procurve manager, log onto your switches and check for packet drops etc 5. anything reported on your core, is it a HP core? 6. do you have loop-protect enabled on your hp switches? 1
Disease Posted July 1, 2015 Author Posted July 1, 2015 After a bit of investigation it might look like that my problem is STP, in the fact that I have enabled it but never configured it on any of my switches past the defaults. Everything looks like they are set to edge ports (apart from the switches that auto sense edge)and I have a load of TCNs on certain ports. The cisco switch (internet/WAN)supplied by the council connects to my core on port 37 and in the last 2 hours has sent 73 BPDU and received 3312 BPDU, does this sound normal? Many thanks for all the advice so far.
Muz Posted July 24, 2015 Posted July 24, 2015 Not sure if resolved already but I don't think STP is the issue here. There are 2 main types of BPDU, ones for sharing switch information and another for notifying the other switches of changes. If you have cisco edge switches with portfast enabled on the edge ports then a TCN shouldn't be generated each time the port goes up or down.
simonm Posted July 27, 2015 Posted July 27, 2015 I would put a dedicated computer with minimal software on it as the ping responder, and try to ping that. At the end of the day if whatever you're pinging is stressed, then it might not respond ( as a priority compared to other stuff ). At the same time as pinging the computer you could monitor the network with the likes of wireshark, as suggested. rgds Simon
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now