How would you do it?

You have a medium-sized network, say 350 machines spread over 3 locations. You’ve suddenly, in the last week or so, noticed that your Internet connection has gotten a whole lot slower! Where would you start to look for what’s causing the bottleneck? In the last week we’ve found one machine with a trojan, gotten it off the network and cleaned up, with no real improvement in Internet speed. We’ve talked people into cutting down their use of streaming radio, etc. again with no real improvement.

My next suggestion is to start capturing traffic at the firewall, to tell us which computers are using the most bandwidth and then go from there, but I’m not the Network Admin or Network Engineer, so we’ll have to see where my suggestion goes.

I am, however, curious as to what you would do in this situation? Where do you start in order to narrow down what the problem might be? (And yes, I’m totally looking for suggestions to take to my boss at this point from networking folks who know more than me.)

Tags: Bottlenecks

Similar Posts

  • History Lessons

    We spent the weekend visiting with Angela’s parents, but also got to spend quite a bit of time getting history lessons. On Saturday, despite the 90 plus degree heat, I spent part of the afternoon watching a Civil War skirmish re-enactment. (Yeah, I have the sunburn to show for it.) It was quite fascinating to…

  • It’s a worm

    Gee you know it’s pretty serious business when a worm shows as the headline on the Drudge Report, eh? For the record, after reading through the SlashDot synopsis and following the various links it appears to be a worm using an old MS SQL vulnerability that Microsoft released a patch for back in June and…

  • Thanks!

    Thanks go out to Shannon who had the answer to my IE title bar question. As soon as I read the solution I thought to myself, “Group Policy Editor! I knew there was a simple place to set that!” Thanks Shannon! Follow these topics: Uncategorized

  • More aggregator stuff

    Yes, there is now a Freeware News Aggregator Showdown Part 3- Morbus responds! page, where he responds to some of my observations about features that I felt Amphetadesk was lacking on. If the release version is as powerful as he claims, and he can get some 5-minute tweaking instructions written up, this is going to…

  • Lit Support Links (weekly)

    The Importance of People and Process in Electronic Discovery tags: LitSupport MM Ethics of Electronic Discovery – Part Two tags: LitSupport MM What do the new iPad 3 and the new National Geographic show “Doomsday Preppers” have in common? Mobile devices and eDiscovery = Doomsday? tags: LitSupport MM A Day in the Internet is a…

  • In the news today

    Library Filtering Law overturned. -the thing missing from this story, of course, is that filters don’t work and block quite a bit of legitimate information from being available to library patrons. Let’s hope the Supreme Court agrees with this ruling. Look, someone who gets it on airport security! I was beginning to think that no…

4 Comments

  1. The quickest way would be to run wireshark or other sniffer on the network to find out whats going on. If you had a proxy it would be very easy to find out 😉
    Also, what sort of firewall rules do you have on the network? Do you allow anything going out (which it sounds like) – if so then you could change this to only allow port 80,25,110 and drop all outbound traffic, but this would not affect traffic on your internal lan though…

    AV traffic can sometimes flood the network if you have a bad dat file – I had our mainframe taken down for about 2 days once because sophos was doing a broadcast to update the clients and flooded the 128k line to the mainframe.

    Another culprit we once had was a jetdirect card that overheated – it flooded the network with packets until we tracked it down. The only way we did this was to look at the switches on the network to work out which one had the traffic on permanently as opposed to the normal flickering.
    hth

  2. Is it just Internet browsing or all network traffic?

    I had this very problem and it wasn’t the network that was slow it was just the name resolution. I cleared the DNS cache on the server amd it was instantly fixed. Might work for you, wouldn’t hurt.

    It could also be your provider. You can place a call to them and have them check things from there side.

    Also double check your phsical wiring at the switches\hub. I’ve also had a problem where we had a loop between ports on an older hub cause network slow down.

    Those are the easy ones. Otherwise you have to sniff to find a problem PC or server. I’ve seen PC nic cards with bad drivers flood the network. Also seen some guy flood the network with video streaming setup on his PC with VLC.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)