LinuxQuestions.org
Support LQ: Use code LQ3 and save $3 on Domain Registration
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
LinkBack Search this Thread
Old 12-21-2007, 02:23 AM   #1
hocheetiong
Member
 
Registered: Jul 2007
Location: Penang , Malaysia.
Distribution: red hat linux
Posts: 129

Rep: Reputation: 15
Smile how to check the network activity status on LAN.


hi, there have 10 winxp pc and 1 linux pc, all 11 pc are connect together with a switch and all have internet connection. Now i found the LAN network is ok(normal),but the internet speed very slow(ping command reply around 2k-3k milisecond)normally i ping the www.linuxquestions.org reply is around 300-400milisecond), i am a administrator, now using 1winxp pc which also connected to same network and install wireshark to is and check my network which pc occupy the internet bandwidth,maybe have 1 or more pc using p2p(bittorent... to download...)but i fail, bacause i not really understand to using wireshark to check this kind of problem,may i know is it wireshark can solve this kind of problem? ok, want i need is i really need to know which pc is occupy many2 internet bandwidth, using what software or what method to check on this kind of problem. I hope the software can check the network in LAN(all pc or apply filter to 1PC) activity status like command "netstat" or is better combine function with captures packets.

Thank you.
 
Old 12-21-2007, 02:43 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 39,835

Rep: Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118
what kind of router do you have? from the architecture you allude to, wireshark is actually useless, as if all machiens are connected to a switch, the traffic from each PC will only be sent to the destination, i.e. the net, and will not be visible to a sniffer on another machine. this is as opposed to using and older hub, which does copy all traffic everywhere in a very innefficient, but useful, manner. so the only point that will see all the traffic is the router itself (assuming the switch is totally unmanaged dumb layer 2 switch.) if the router itself has no capactiy to provide information, then you could look to obtain a hub elsewhere and insert that between the switch and the router and then connect your sniffer PC to that hub. then you could see all the traffic.
 
Old 12-21-2007, 06:03 AM   #3
jlinkels
Senior Member
 
Registered: Oct 2003
Location: Bonaire
Distribution: Debian Etch/Lenny/Squeeze
Posts: 3,483

Rep: Reputation: 308Reputation: 308Reputation: 308Reputation: 308
The only way is to set up a machine as a gateway thru which all traffic passes. So this machine would be set up between your switch and the internet.

Only then you can monitor all traffic, for example using jnettop. I use that tool all the time to pick out bandwidth hogging users. As an additional benefit you can install traffic shaping on that Linux machine to limit those users.

You can continue to use that Linux machine for other purposes, you'd only need 2 NIC's. (To keep it simple, theoretically, 1 NIC would do as well)

The long ping times are caused by a continuously full output buffer in your (perhaps ADSL) modem.It is kept full all the time by outgoing traffic, and your ping packet is put at the end of that que.

Traffic shaping in the gateway machine does away with that, and takes care that the output buffer does not fill up.

www.lartc.org

jlinkels
 
Old 12-21-2007, 06:21 AM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 39,835

Rep: Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118
sorry, but that's jus tnot true... that's *one* way but by no means the only way...
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Setting up simple file/print server to notify me of log activity across the LAN adamsjw2 Linux - Networking 1 04-10-2006 03:59 PM
Check disk status diezjc Linux - Hardware 2 04-06-2006 03:58 PM
Realtime Status/Activity View mrlucio79 Linux - Software 0 03-11-2004 07:43 PM
Check for status of Serial ports in any language? BongFish Programming 11 09-11-2003 01:46 AM
Check Printer Status Debby Linux - General 5 02-08-2002 08:52 PM


All times are GMT -5. The time now is 01:20 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration