LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 06-11-2022, 11:32 AM   #1
Noob-Tech-Ninja
Member
 
Registered: Jan 2022
Posts: 31

Rep: Reputation: 2
Question Unexplained data usage > Wireshark > Ethernet / NIC config >


Hi there.

I was hoping that you could help me with a couple of issues that I'm trying to
get resolved.


Background:
I'm helping out a friend who has a pretty complex home network set-up

Basic network overview:

Enterprise wireless modem/router (using a SIM card and mobile network, for network access) >
Swich 1 >
Switch 2
Switch 3
Swtich 4

Switch / network 2 = security cameras
Switch / network 3 = office / work PCs
Switch / network 4 = guest Wi-Fi

Issue:
They are experiencing very large and (unexplained) spikes in data usage
We are trying to establlish what is causing this.

We have done a veriety of testing and the issue is definately being caused from something
within this interal network infrastructure.

They have a spare PC which they are going to install Wireshark onto
(it currently only has x1 NIC card, and ethernet port)

This PC is going to be connected directly betwen the modem/router and the
1st Switch on the network (to capture as much traffic and throughput as possible).

Enterprise modem/router > Spare PC with wireshark > Switch 1 > Rest of
network


Questions:

1. Do we need a 2nd NIC card installed into the PC, to feed out from the
PC back into the 1st Switch, so that we can capture all of the traffic
on the network ?

2. Or could we instead, use an ethernet splitter with the original NIC card
to give us 2 ethernet ports, and use one of them to connect back into the
1st swtich. Again - to capture all of the network traffic ?

3. Is there anything else that I'm missing to be able to achive this ?

TIA for any help or advice !
 
Old 06-12-2022, 08:05 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,403
Blog Entries: 28

Rep: Reputation: 6166Reputation: 6166Reputation: 6166Reputation: 6166Reputation: 6166Reputation: 6166Reputation: 6166Reputation: 6166Reputation: 6166Reputation: 6166Reputation: 6166
Precisely what do you mean by "data usage" and what metric are you using the measure it?

Have you tried top or htop? If so, what applications did they show as top users of memory?
 
Old 06-14-2022, 06:45 AM   #3
ppeatman
LQ Newbie
 
Registered: Jun 2022
Distribution: RHEL, Centos, AlmaLinux
Posts: 2

Rep: Reputation: 0
Passive Ethernet tap

If you can live with a (temporary) downgrade of the Ethernet speed to 100 Mbps and you're willing to do a bit of DIY hacking, you could build yourself a passive Ethernet tap device. Just Google for "Passive Ethernet Tap DIY". With that, you don't have to mess with exotic network configurations, you just insert it at a spot where you expect the unknown traffic to be present. But it allows you to monitor only one direction at a time with Wireshark (half duplex).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Unexplained ping delay with "USB to Ethernet" adapter MagicSpark Linux - Kernel 11 02-17-2021 04:25 PM
Unexplained high memory usage noob189 Solaris / OpenSolaris 11 05-31-2012 10:51 AM
please help: unexplained spike in load average & drive usage beardo265 Linux - Server 1 12-07-2009 10:05 PM
Unexplained Disk and CPU Usage Soon After Startup spaaarky21 Fedora 2 11-20-2005 11:34 AM
how to determine cpu usage, memory usage, I/O usage by a particular user logged on li rags2k Programming 4 08-21-2004 04:45 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 03:25 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration