Interpreting Network traffic???
Hi all,
I hav been trying to learn to interpret the network traffic. I have been taking traces with some sniffers including ethereal. I am looking for some related info. e.g
1. How many TCP retransmitts are normal on a network.
2. How much delay between the packets is acceptable.
3. Are there any common errors/problems which could be kept in mind?
4. How much response time in ping is acceptable.
Any related links/info. will be apreciated!
Thnaks in advance!
Re: Interpreting Network traffic???
Quote:
Originally posted here by doiexist
Hi all,
I hav been trying to learn to interpret the network traffic. I have been taking traces with some sniffers including ethereal. I am looking for some related info. e.g
1. How many TCP retransmitts are normal on a network.
None. A retransmit means the packet got lost 'on route' which can mean routing problems and/or hosts down and/or firewalls.
Quote:
2. How much delay between the packets is acceptable.
This depends on your network layout. The more switches/routers the packet has to travel through the bigger the delay. There's also a difference in latency on ethernet and i.e. ATM.
Quote:
3. Are there any common errors/problems which could be kept in mind?
Badly configured speed/duplex settings on the host and/or switch. Incorrect routing. IP address conflicts, bad subnetmasks etc. Just like Murphy said: "Anything that can go wrong, will go wrong" (at the worst possible moment I might add ;) ).
Quote:
4. How much response time in ping is acceptable.
This is directly related to point 2.