Data Flowing Upstream Mirroring Downstream While Browsing?
May 28, 2011
using task manager in XP it is clear that while browsing data is being uploaded mirroring the data downloaded..ie in a given period if 18mB comes downstream (just surfing) then 11mB goes upstream. The graph in task manager shows that the peaks and troughs of the data upstream and downstream exactly correspond and watching the bytes tick over confirms that data goes out for every data coming in.I assume that this should not happen? I realise ip protocols have some kind of error detection that may require uploading data, but the amount sent seems excessive! From my limited understanding of networking and running wireshark it looks like that when packets come from an ip on the web ( i use the terms web/internet interchangeably ) then packets are sent out to the same ip ... using TCP and HTTP ( I don't really understand them ). The info for one such packet going out is "Continuation or non-HTTP traffic" using the HTTP protocol, which sounds a bit contradictory. I regularly run virus scans and rarely find anything. The cpu regularly maxes out and its usually something to do with firefox ( I've heard of buffer overflows but i assume the problem is a relatively old processor and hardware).The browser is firefox. OS is XP.Coincidentally, the pc was recently rebooting after crashing until I disabled "restart on system failure" which prevented the crashes ( if they were crashes and not just the system reacting to an error ). Again, that is a bit suspicious but maybe not. Spybot, bit defender quickscan,avira, zone alarm, malwarebytes etc haven't flagged anything up.Maybe the router is not configured properly. As with all these things, there will be some simpler things to start with to diagnose this issue (if there is one ) but I don't know what they are.The pc uses wifi to connect. The isp is not the best and the speed is pretty bad for adsl. Every couple of days the router needs rebooting because it stops giving out ip's.
View 6 Replies
ADVERTISEMENT
Mar 19, 2011
I'm using an RFC 1483 Bridged adsl connection on a WAG54GS router. Downstream rate says 2043 Kbps, and upstream rate only 35 Kbps. In the router setup page I have not found any place to change downstream/upstream rates. How can I increase \the upstream rate?
View 2 Replies
View Related
Aug 1, 2012
I have an RV042 router and I'm looking to monitor the total upstream and downstream traffic from within the router. I know there is tons of software that I can put on a netowrk computer to monitor traffic, but is there any software that I can put on the router itself that will monitor the traffic from within the router?
View 1 Replies
View Related
Jan 29, 2011
Is RTP port open indicates that rtp is flowing in the network.
View 2 Replies
View Related
Jun 7, 2011
im attempting to setup a L2L VPN between an 1841 and an NSA 2400, via the SDM.The Tunnel comes up, and when I test connectivity it shows as being successful, but I do get an error stating:-
"A ping with data size of this VPN interface MTU size and 'Do not Fragment' bit set to the other end VPN device is failing. This may happen if there is a lesser MTU network which drops the 'Do not fragment' packets."
From my reading this shouldnt cause all traffic to drop though, right?
Currently I cannot ping or telnet to services from one end of the tunnel to the other. I was able to ping momentarily from the Sonicwall end at one point, but this disappeared shortly afterwards (without my changing anything regarding the config).
All of the ACLs created were populated through the SDM.
View 3 Replies
View Related
Mar 27, 2011
I'm currently using ASA 5510 with software 8.4.1 and I have an issue with nat configuration. I used the following config line:nat (inside, dmz) source dynamic LAN Pat1 destination Server1 Server1
The traffic is not flowing and when I use Packet Tracer, packets are dropped at the NAT rule with the following error: Drop-reason: (acl-drop) Flow is denied by configured rule.The only ACE I have is permit ip any any.
View 2 Replies
View Related
Jul 12, 2011
I have manually configured the Firewall ASA 5510 from existing PIX to match the configuration, however when I connect the firewall to the Network, no traffic is flowing in either direction. I have the Inside network on the 172.29.0.0 subnet and the outside network on 20.2.0.0 subnet. I am attaching the cofiguration file.
View 4 Replies
View Related
Jun 13, 2013
i have a gateway router going to the internet....using public IP addresses on both interfaces. starting on Monday, traffic would suddenly stop flowing from the inside of the network going out, though i can still ping the outside interface , but when I log in to the router I am able to ping to the internet. so its like traffic is not passing from the outside int to the inside int. I have a 3900 router. other thing is, when i restart the router it will work for some time and then just stop again....
View 6 Replies
View Related
Aug 20, 2012
I've got an ASA 5505 with the Security Plus license that I'm trying to configure.
So far I have setup NATing on two VLANs, one called 16jda (VLAN 16 - 10.16.2.0/24) and one called 16jdc (VLAN 11 - 10.105.11.0/24).
From each subnet I am able to connect to the internet, but I need these subnets to also be able to talk to each other.
I have each VLAN interface at security level 100 and enabled "same-security-traffic permit inter-interface", and I have setup static NAT mappings between the two subnets, but they still can't communicate.
When I try to ping there is no reply and the only log message is: 6 Aug 21 2012 09:00:54 302020 10.16.2.10 23336 10.105.11.6 0 Built inbound ICMP connection for faddr 10.16.2.10/23336 gaddr 10.105.11.6/0 laddr 10.105.11.6/0
View 11 Replies
View Related
Apr 10, 2011
We use a couple of 2910al ProCurves for our core switching/routing then we have a few 2626 access switches.
Despite allocating adequate ports in our new building, I'm still having a problem with users plugging in shitty little D-Link 5 port hubs at there desk.
I'm guessing I'm going to have to only allow the mac's of approved workstations? Which sounds like a management nightmare.
View 18 Replies
View Related
Oct 4, 2011
We have 3560 switch with following IOS. version 12.2(55)SE3 and image name is C3560-IPSERVICESK9-M. On one of the interface we need to know what are traffic is flowing.
Do we have "ip nbar or ip route-cache" support on this switch IOS? Is there any other way to find out which protocol traffic is flowing through that interface.
View 1 Replies
View Related
May 17, 2011
I am using a broadband connection on a PC running Windows 7. The plan which my ISP is providing me comes with a speed of 4Mbps upto first 20 GB and then 512Kbps after that, every month. My problem is that I am getting only 65-70 Kbps download speed. (tested over various sites and torrents). My router (Nokia Siemens) settings show that my Downstream speed has been assigned as 7999 Kbps but still I am not getting the speed anywhere near that and I have not consumed the 20GB limit as yet.
View 12 Replies
View Related
Sep 16, 2011
I fought my ISP (frontier) for weeks trying to get their 7500 DSL/modem/router configured in bridge and working into the WRT600N. Finally gave up and put a new Engenius EVR100 behind the 7500 bridge and it came up fine in 10 mins. Now I would like to use my old WRT600N downstairs as a second router and run it in the range of the Engenius DHCP, with DHCP turned off in the WRT600N.
My question is this ... Do I set the WRT600N as a static IP address and use an address in the range issued by the EVR100?And, if so, what would the sub-net mask, default gateway and DNS numbers be? Also would the router address itself (lets say I use 192.168.0.120 from the EVR100 range) be different then the static IP address?
View 1 Replies
View Related
Mar 12, 2013
Comparing my brand new linksys x3000 (Firmware Version:v1.0.03) with my old zyxel p660hw I see that the linksys is running a downstream noise margin of 8.2dB while the old zyxel is running a downstream noise margin of 15dB. Needless to say, I am very disappointed. why the linksys value should be so much lower?
View 5 Replies
View Related
May 7, 2012
I have configured multicast(ip pim dense-mode) on two 2911 that are connected by a Multilink( 3 Mbps) Wan connection.The configuration works fine for awhile and sometimes all day but at some point one of the Multilink interfaces stops passing multicast traffic.I perform a SH Multilink 1 on the interfaces and one show multicast packets incrementing and one does not, it just stops.The problem acts like there is a buffer that gets full and after that happens it just stops working.
View 2 Replies
View Related
Jun 3, 2013
I have two 1841's, setting up a Lab WAN in Packet Tracer. I have one of the 1841's run to a DSL modem, then out to the cloud and the same setup on the other end... from the cloud to the DSL modem and to the 1841 on that end... I have all green lights, so that tells me layer 2 is up, but I'm trying to figure out
what IP to assign the routers to test pinging and getting traffic flowing. but the DSL Modem's have the public IP's and dynamically assign an IP to the routers? I've also tried setting up a static IP on the routers fa0/0 interfaces and the pings fail.. Wondering what I am missing to get these two talking.
View 2 Replies
View Related
Aug 24, 2011
How important is the upstream to a VPN? We are getting terribly sluggish results from our VPN at the moment and looking to upgrade to a 16/2 line, the host only needs to handle about 3-5 client computers, would this be adequate? How important is upstream?
View 1 Replies
View Related
Sep 3, 2012
I have a 5K with 5 downstream 3560's. I now have a new 5k that I would like to add to the existing 5K as a HA peer. What is the best way to accomplish this with the least amount of downtime for the downstream switches.On the 3560's, i plan setting up port-channels once HA is setup on the 5k's.
View 1 Replies
View Related
Nov 6, 2012
We have several DMVPN-connected sites that are connected to our 2821 ISR pair.They're all configured as eigrp stub connected summary. Yesterday, a few of the sites went inaccessible, but the VPN tunnels were still up and running. Upon further investigation, we noticed that the remote sites stopped receiving routing updates from our 2821's. As a quick fix, we added static routes to bring the sites back up.Later that night, we removed the static routes and cleared the eigrp neighbors, hoping it would fix the problem. When it didn't, we cleared them two more times.Suddenly, the router lost all downstream adjacencies. While we were adding statics to at least bring the sites back up, all of the adjacencies came back.
View 2 Replies
View Related
Jan 16, 2013
We are in the process of rolling out iPads to our offices. As part of this implementation, we need to print from the iPads to our network printers. Our network printers are mostly HP and Xerox and do not have native Apple AirPrint capabilities. As such, we have been using the FingerPrint software to share out the network printers as Apple AirPrint printers. We have a mixture of switches at our offices. Most offices utilize a 3550 PoE switch. In these offices the AirPrint traffic is being transferred successfully and everything works great. In the offices which are using 3560 PoE switches, the traffic is never seen at the iPads. We are using EnGenius EAP300 access points connected into the Cisco switches to provide wireless access to the iPads. Both 3550 and 3560 switches are running iOS 12.2(25). What might be stopping/blocking the AirPrint traffic on the 3560 switches?
View 3 Replies
View Related
Feb 20, 2013
I need to support a bunch of security cameras mounted on poles in our parking lot and an IP intercom system mounted on some gates. Because of environmental factors the switches at the poles need to be hardened and the spec from the vendor installing the gear is for GarretCom Industrial unmanaged switches which would make sense.
However when Information Security got wind of this scheme they (probably correctly) are requiring me to secure the ports that these unmanaged switches connect to. I have 2 choices: port security w/ MAC filtering or 802.1x. Because all the devices at the poles and gates support 802.1x and because I may need to go out there to troubleshoot stuff (and will invariably forget to add the MAC of whatever device I am using) I would prefer 802.1X multi-auth mode.
Problem:
When I ran a quick test on a test 3560 running some 15.0.1 code I could get a laptop to connect via 802.1x EAP-TLS successfully if it was directly connected but when I connected the same laptop via a dumb Netgear switch I confiscated from a luser it would not connect. The 3560 error said that the laptop never responded.
Question:
Before I spend a whole lot of time on this, is this something that should work? I don't see any practical use for the feature if it won't however the documentation I am using specifically mentions downstream hubs but I am not sure if they mean real hubs (which I don't think are even made anymore) or if they mean unmanaged switches.
I plan to try a couple of different unmanaged switches tomorrow and digg a little but I would like to know if I am wasting my time on something that will never work or if there is a little gotcha somewhere.
View 2 Replies
View Related
Jan 14, 2013
Network settings. What I want to do is limit the rate that people can download files from my webserver remotely. LAN connections should still be able to transfer at full speed, but anything outside of the local network should be limited to 200Kbps per connection. Is that even possible? Can I limit the number of connections per client (probably by IP)?
If this can't be done at the OS level, is there any way I could script it using PHP? Maybe read X bytes into a file and then sleep...
View 1 Replies
View Related
Oct 31, 2011
I have a Cisco Catalyst 3750X switch, and I have configured port mirroring on it. Traffic from 12 of the 1G ports will be mirrored to both 10G ports, and I have connected both 10G ports to a server that captures the traffic.
Currently, I have one of the 12 1G ports connected to another server that replays a pcap file once at maximum speed (i.e. option -t in tcpreplay). I thought that this setup means I should get twice the number of packets (and rate) from the two 10G ports. However, I noticed that although the original pcap file contains 4288 packets, the number of packets from the two 10G ports varies between 31000 to 34000 packets, which is about 7 to 8 times the original number of packets. Why am I getting more than twice the amount of traffic, and why does the output vary?
View 2 Replies
View Related
Jan 31, 2011
I have looked up the command sequence for port mirroring and it seems pretty straight forward however in my case the command will not execute.
I have a 851W with 12.4T
If I do: #monitor session 1 source interface fa 4 (wan port)
i get the response invalid input detected however if I do the same command for fa 1, fa ,2 and fa 3 they work
Using the ? shows the valid entries are [0-4] for fastethernet
I just want to monitor WAN traffic with WireShark, particularly DDNS requests, with a spare PC connected to a free lan port.
I would use a hub on the Wan connection but unfortunately I do not have one at the moment.
View 8 Replies
View Related
Nov 26, 2012
Region : Russia
Model : TL-WR1043ND
Hardware Version : v1
Firmware Version :
ISP :
Region : Russia
Model : TL-WR1043ND
Hardware Version : v1
Firmware Version : wr1043nv1_ru_3_13_10_up(120614)
ISP : netbynet
Connection to a router on a cable speed of dowstream-50MBit/s, upstream-3Kbit(!) wifi-dowstream-50MBit/s, upstream-3KbitA cable directly in the personal computer to 70 Mbps there and back.Measured speedtest.net, and as [URL] The matter is that even elementary with an investment it is impossible to send mail - I am connected by different devices-2 of the laptop and 2 smartphones - the same. Technical support of provider already talk sense only in a router. Insertions updated, changed - the same( Firewalls are disconnected, any more don't know what to do and where proceeding speed and all digs-is killed. Russian forum TP-Link is idle.
View 3 Replies
View Related
Apr 13, 2012
Since I've bought my RV042 CISCO (v3 hardware, firmware v4.1.1.01-sp Dec 6 2011 20:03:18) i wasn't able to let it work properly with my two DSL network lines. I explain. I got 2 DSL network:
1- PPPoE with authentication (MTU setted as auto) with upstream speed 4Mbit/S and downstream speed 5Mbit/s
2- Direct line with static IP with upstream speed 7Mbit/S and downstream speed 1Mbit/s
I was never able to SUM the two WAN using the LOAD BALANCE set. I tried all combinations:
DSL 1 in WAN 1 or in WAN 2
DSL 2 in WAN 2 or in WAN 1
I've tested all type of speeds in WAN SPEED in Web Management
it seems that for some kind of reason it takes the upstream speed i can set in web management as the default value on which it decides to use the other WAN. When i set low upstream bandwidth for DSL 2 it's able to sum the down streams of both WANs but not the up streams.
I wasn't ever able to sum the up streams? How does it work?
View 4 Replies
View Related
Apr 28, 2013
I have created a mirror to copy all packets from Interface gi1 to interface gi28. I don't see any port 80 traffic, or 443 or any revelant traffic. I see mostly broadcast from other devices. I have a security device that is logging all the copied packets from my firewall for malware/IPS, etc inspection.Right now I have it monitoring vlan 1 in the hope that it would resolve this issue but I see no change.
View 1 Replies
View Related
May 3, 2011
I want to configure port mirroring on SG300 swtich, port monitoring status is "Not Ready" , and i can not monitor the source interface!
View 1 Replies
View Related
Nov 8, 2011
I'm troubleshooting a LAN issue I have, and I wanted to hook up wireshark to record traffic over the course of a couple of hours for later diagnostics. I went into the web administration interface, clicked Administration > Diagnostics > Port and VLAN Mirroring, and added a port mirror from the port I wanted to watch to a port to which I had connected a laptop. I picked the Tx and Rx options, and clicked Apply.I did receive lots of traffic in wireshark, but I noticed immediately that the server on the port I had mirrored was suddenly unavailable on the network -- pings timed out. This lasted until I removed the mirror, then the server was suddenly reachable once again.Does this feature not work the way I had thought it does? What I saw looked more like a forward than what I would call a mirror. The documentation leads me to believe mirroring is intended to be used in just the way I was attempting to use it.
View 1 Replies
View Related
Apr 29, 2013
Region : Malaysia
Model : TD-W8968
Hardware Version : V1
Firmware Version : 0.6.0 0.4 v0005.0 Build 130217 Rel.62075n
ISP : TM Streamyx
I have internet speed : 8Mbps.
The status of Internet in the modem config as foloows:
UpstreamDownstream
Current Rate (Kbps)636 10240
Max Rate (Kbps) 900 23412
SNR Margin (dB) 12.8 23.5
Line Attenuation (dB) 8.1 1.1
Errors (Pkts) 0 0
from the above informations the upstream is 636 Kbps but when I did the speed test it show me that the upload not more than 300 Kbps.
I used another modem D-link modem and the upload is more than 550 kbps when I used speed test.
Actually the upload is very slow by using TP-link modem and when I used another modem the upload is double speed.
View 1 Replies
View Related
Nov 9, 2011
Is it possible, through a QoS profile, to control how much bandwidth a user gets to use for upstream traffic? I can easily set limits for downstream traffic, via the per user bandwidth contracts, but it is not obvious to me on how to control upstream traffic.
View 1 Replies
View Related
Nov 11, 2012
I am imagining a smallish networking (AS1234) with say three full BGP table peers that provide transit to the network (just to keep the maths simple here); Lets say AS100 and AS200 are preferred transit providers with AS300 as a backup/least prefered (AS prepends or similar stop us from using this network by default). So in this scenario our little network gets two different paths across the Internet, as not to rely solely on one provided, with a backup provider to hand also.
How do you mange issues like packet loss somewhere in AS100's or AS200's network? So lets say a host on our AS1234 network is talking to host in AS888 and the preferred route is through AS100 but somewhere deep in AS100 a link is flapping (for example) and I can't get to AS888 reliably through there anymore, but I can through to other peers of AS100 OK. We can postulate that AS100 is the best path for 50% of the Internet and AS200 for the other 50% (this is a best case fictional scenario). I can't ping 50% of the internet via AS100 and then in the event a ping fails (or some other more reliable test) tear down the BGP session to use AS100 until it's fixed again, nor vice versa with AS200.
First of all, I asume you don't know about the issue between AS100 and AS888 until someome moans about it to you? Secondly, do you then some how modify the route(s) to AS888 that come from AS100 (route map for example to change the weight or preference) so AS200 is now preferred for AS888? Do you infact shut down the AS100 peering and now use AS200 & AS300? How do you rectify these situations that are beyond you control using what is in your control?
View 2 Replies
View Related
Sep 14, 2011
I'm trying to setup port mirroring on a Cisco ASA 5510, but when I try to use the switchport monitor command, that command is not recognized.I've selected what interface I want to configure (conf-if), but the switchport command seems to not be part of the IOS.I'm running ASA version 8.2(1)
View 9 Replies
View Related