Re: [DLC]help in investigating a possible packet storm

John Kristoff <[email protected]> Thu, 1 Apr 2010 23:34:46 -0500
Newsgroups gmane.org.user-groups.linux.depaul-lug
Message-ID <[email protected]>
On Thu, Apr 01, 2010 at 09:15:24PM -0700, Politik Durden wrote:
> Here's what I know:
> 
> - no recent changes (no new switch, NIC, changes to static routes, config changes, patches/upgrades, etc)
> 

Maybe, but never believe that until you've verified it for yourself.

> Theories: 

It could be a switch port duplex mismatch.  For instance, a server is
set to auto-detect 10/100/... speed and half versus full duplex setting
and maybe the switch port is to (but maybe not), but both ends of the
link are set to something different.  Like one side being full duplex
and the other being half duplex.  This is a very common problem and
things end up "kind of" working, but degraded severely.  If you see
lots of late collisions on one switch port or more, that would be
indicative of this sort of problem.

> - Somehow a loop got introduced ? 

The net would likely be completely down if that was the case.

> 
> What I really need is suggestions on a good free traffic tool, something we can install on two or three laptops and put each switch through its paces. Any ideas ? 
> 

tcpdump.  For Windows you can use Wireshark.  You also need to take
a look at all the switch ports.

Clear the switch stats and then look at them continuously for a bit
to see if you can pinpoint something odd.  Note, collisions are not
a bad thing.  Some people (including instructors) continue to
perpetuate the myth that 30% collisions is somehow a problem.  They
have no clue what they are talking about.  Most people can safely
ignore collisions.  However, if everything is switched, you shouldn't
see any anyway.  Late collisions would be bad though, they should
never happen.  Something, probably serious is wrong if you're seeing
those count up.  See above.

Is someone infected and spamming the net?  Maybe there is an ARP
storm because of that or something else?  Maybe some link is flapping?
Do pings between internal hosts using IP addresses (no DNS) work OK?
Maybe DNS is a problem?

Disconnect or divide the net in half if you're stuck.  Bring things back
until you find the problem.

Tough to say w/o seeing the problem for myself, but it sounds like
a relatively small net so it should be solvable without too much
trouble.

Good luck.

John
_______________________________________________
DLC mailing list
[email protected]
http://mailman.depaul.edu/mailman/listinfo/dlc
Use the Above Link to Unsubcribe!!
http://linux.depaul.edu/