Network Troubleshooting: Broadcast Analysis 101
When I'm working at a client site, I always start a packet capture -- with the client's permission of course -- and stop after approximately 1,000 packets. Then I review the various protocols and services sent out on the wire by any network-connected device. I will see packets from clients, servers, phones, printers, switches, routers, and other devices. I do not need a tsp, mirror/span port to do this broadcast analysis.
By analyzing this traffic, I can make suggestions to clean up "space junk" (all those unnecessary packets) floating around the network. The benefits of going through this exercise are many. For example, you will have fewer packets to sift through when performing network troubleshooting. In some cases, it will be easy to pinpoint problems. In extreme cases, I have seen standard configurations cause broadcast storms that were easily fixed by cleaning up the desktop standard configuration. In other cases, I have found problems such as misconfigured load balancing and misconfigured ip helper addresses.
I encourage you to take a quick sample of your network traffic and give it a try. You will be surprised at what you find.
In this video, I cover STP, LLDP, CDP, NTP, LLMNR, IPv6 and SSDP, what they look like in your trace, and what to do when you come across them. I also discuss how you can streamline your analysis by leveraging the Protocol Hierarchy and Endpoint report features in Wireshark. If you are using another protocol analyzer, poke around and you should find similar reports.
Recommended For You
In honor of St. Patrick’s Day, there’s no better time to reflect on those instants when life threw us a curveball, but we were able to hit a home run.
The success of modern enterprises, especially those utilizing real-time communications solutions, is highly reliant on IT infrastructure availability.
To understand the critical role of HTTP/2 in streamlining operations, we must look back at the technologies and implementation gaps that got us where we are today.
A video overview and best practices on how to reduce broadcasts and find other things to tune.
This is a great example of the perfect storm of variables coming together to cause performance issues. Watch the video to see how the problem was found.
Providers should be making infrastructure work for everyone in 2019, improving efficiency and opening up networks for all apps on their infrastructure.