home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


ON THE WIRE

Intranet + Internet = Bottleneck

by Bill Alderson and J. Scott Haugdahl

Many of the problems associated with intranet-to-Internet access are difficult to diagnose, since a problem can be manifested on either side of a firewall or even in the firewall itself. This month, we examine two such Internet-access problems as experienced by our customers. Here's our first problem as described by our client: "Many of our 5,000 corporate Internet subscribers are complaining about slow response time. Our corporate internetwork (intranet) has a firewall between it and the Internet , connected via a full 1.544-Mbps T1 link. We need to pinpoint where the problem is before we start upgrading equipment or paying for more lin speed in hopes that response time will improve."

Scott: Since users frequently ask questions like "Where's the 'any' key?"--as if it were a network problem--the first thing we needed to do was monitor a user's browser during a period of slow access.

Bill: In this case, the user appeared to have a legitimate complaint, since a number of browser requests took several seconds before the response appeared.

Scott: Of course, we could have attributed this delay to uncontrolled f actors in the Internet and called it a day, but we don't give up that easily. We needed to capture some of the user's browser traffic and analyze it in detail.

Bill: Having done so, our analysis showed a delay of up to 10 seconds from the time a packet entered the firewall to the time it was sent on the T1 link to the Internet.

Scott: Based on this information alone, one might have concluded that the T1 was the bottleneck.

Bill: Not so in this case. Further analysis on the T1 side revealed that despite a backlog of packets, the firewall couldn't keep the T1 link saturated.

Scott: A more robust, or faster, firewall was needed.

Bill: And, based on the backlog, our client also had to add more firewalls and install a link to the Internet that was faster than the T1 in order to service the multiple firewalls. Problem solved.

Scott: Now for our next problem.

"My Windows95 workstation suddenly loses all its IP connections while accessing the Internet. Although the workstation doesn't freeze, the only way to regain Internet access is to reboot. Needless to say, the Windows95 rebooting process is very slow and obviously isn't the solution to this problem."

Bill: Sounds like a problem for Bill Gates.

Scott: Especially since the workstation in question was using th e standard stock TCP/IP stack that comes with every copy of Win95.

Bill: Having limited access to Mr. Gates, we opted for the analysis approach instead.

Scott: So we went out and captured a failed Internet session, and noted that whenever a packet was lost or delayed in cyberspace, Win95 IP sent up to three packet retransmissions before trying the next gateway (router) from the user's list of default gateways.

Bill: The user's workstation attempted to find the new gateway using the Address Re solution Protocol (ARP). An ARP packet contains the IP address of the desired device (the target gateway) and is broadcast on the user's local segment to find the Data Link Control address associated with that IP address.

Scott: If the subsequent default gateway is not on the same network segment as the user, it will never respond (unless a router on that segment is set up for proxy ARP). After moving onto a subsequent default gateway, Win95 IP will not recycle to the top of the user's default gateway list where it would find its initially successful default gateway.

Bill: Not only does the current application fail, but all IP applications in the workstation can no longer function!

Scott: So why didn't the user experience this problem in the corporate intranet?

Bill: When accessing the Internet, the retransmission rate was much higher because of delays and lost packets, increasing the likelihood of retransmitting a packet more than once in succession.

Scott: Originally, the user simply got a list of all the default gateways and added them to the configuration.

Bill: Of course, the user didn't realize that you're supposed to use only gateways that exist on your local segment, so the solution in this case was to get rid of the "remote" default gateways.

Scott: We could have turned on proxy ARP or adjusted the retransmission timers or number of retries at the user's workstation. However, sinc e everyone needed to know their default gateway for their local segment, the correct default gateway was a more straightforward solution and was easier to manage across the intranet.

Bill: Win95 IP would also try legitimate gateways on retries, and if there was only one gateway, it would cycle the retries only on that gateway.

Scott: As an exercise to our readers: Analyze your IP intranet-to-Internet traffic and see how your TCP/IP stack responds to problems like these. Feel free to drop us an e-mail with your experiences.

Bill: Don't forget to e-mail your favorite network horror stories to us. We'll be printing our favorites in our October 15 column--just in time for Halloween.

Bill and Scott can be reached at otw@ pmg.com. Portions of trace files from selected columns are available via Pine Mountain Group's Home Page (www.pmg.com).


The Networkologist by Patricia Schnaidt
Perspectives by Eric Hall
Perspectives by Robert J. Kohlhepp
Corporate View by Robert Moskewitz
In The Middle by Bruce Robertson
Return To The Table Of Contents


Updated September 9, 1996





Looking for a new job?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
The tumbling of IT jobs stopped in the second quarter, as the IT sector added about 44,000 jobs.

It's just a glimmer, but Oracle is starting to see a bit of light at the end of the recession tunnel.










2009 IT Salary Survey: Meager Raises, Solid Prospects
Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service