Jump to content

Recommended Posts

Posted

Morning all,

 

Long story short - slowly getting around to getting VLANs in however it would be good to have some kind of benchmark.

 

Does anyone know what constitutes a large number of broadcasts in network traffic?

 

Thanks!

Posted

Get cacti monitoring your broadcast traffic, do it for a decent period of time ie 2 weeks to see what your traffic is like, then Wireshark your primary vlan broadcast traffic to see where it is coming from. It may not be as bad as you think! I monitor our Core switch with Cacti for this type of thing, it ensures that we have decent baseline data to compare on before we make changes, that way you know if they have been a success or failure!!

 

If you are getting excessive broadcasts its in someways better to find, and deal with, the source of these broadcasts rather than VLAN them off.

 

We have a network of 700 workstations (inc 250 laptops in a dif vlan). Cacti shows around 10 broadcasts per second with all units on. Not sure if thats good or bad compared to others mind!

Posted
If you are getting excessive broadcasts its in someways better to find, and deal with, the source of these broadcasts rather than VLAN them off.

 

We have a network of 700 workstations (inc 250 laptops in a dif vlan). Cacti shows around 10 broadcasts per second with all units on. Not sure if thats good or bad compared to others mind!

 

All part of the plan ;)

 

Thing is I need to know what 'a large number' means first :D

Posted (edited)
All part of the plan ;)

 

Thing is I need to know what 'a large number' means first :D

 

Unfortunately you're asking a "piece of string" question - excessive for one network (or port) is fine for another. Try benchmarking using the methodology described here, post 3:

 

https://supportforums.cisco.com/thread/142056 - it's Cisco specific but will give you something to work from.

 

and work through...

 

How many of your switches ports are reporting excessive broadcasts?

Are they getting error-disabled temporarily?

What's connected to those ports? (clients, inter-switch links, servers).

When does it trigger - is is bursty or ongoing? Now we're in the holidays, are you still getting excessive broadcasts?

How often does it trigger - a lot, or occasionally?

Are those ports Gigabit, 10GB or 100BaseT (thresholds should differ)?

 

and disable unnecessary protocols on your network printers - they're a common culprit.

Edited by pete
  • Thanks 1
Posted

As above, it depends on all the hardware on the network. If you have a bunch of old stations broadcasts can be more of a hassel. Every computer must crack open a broadcast, look at it and decide if it is something it needs to respond to which can chew CPU. Lots of little packets like this can also chew CPU on the switches. You also have to look at the impact of these on the port/switch buffers and memory to make sure they are not being filled up with trash.

 

Next up is the propogation of these packets across all the network types. If you have 0.5% broadcasts on a 1GB link (which is a lot) that is not too bad for that host but as every host recives them a printer or managment card with a 10 Mbit link could well be choked out by them. Wireless is another big culprit, if you have lots of broadcasts leaking onto the already shared media of wireless not only does it burn up the link speed but also the link time. As its shared the more packets puking out the more likely there will be collisions triggering more standdowns and less efficiency

 

It all depends on how long the string actually is.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...