SHARKFEST ‘10 | Stanford University | June 14–17, 2010 Wireshark in the Large Enterprise June 16, 2010 Hansang Bae Senior Vice President | Citi (f.k.a.

Slides:



Advertisements
Similar presentations
Deloitte Technology Fast 500 Asia Pacific Winners Accelerating Your Network WACC Technology.
Advertisements

Lord Mandelson of Foy and Hartlepool is a descendant of which Labour leader? 1.Harold Wilson 2.George Brown 3.Gordon Brown 4.Herbert Morrison 5.Clement.
| Copyright © 2009 Juniper Networks, Inc. | 1 WX Client Rajoo Nagar PLM, WABU.
CISTECH R7.8 SERIES Managing an R7.8 Environment with R7.8 Link Manager.
Session B1: The Art of Packet Analysis
A3: APPLICATION AWARE ACCELERATION FOR WIRELESS DATA NETWORKS Athours: Zhenyun Zhuang and Tae-Young Chang GNAN Research Group, Georgia Tech, Atlanta, GA.
Top Causes for Poor Application Performance Case Studies Mike Canney.
B5 – TCP Analysis - First Steps Jasper Bongertz, Senior Consultant Airbus Defence and Space.
How to use a scanner Throughout this slide show there will be hyperlinks (highlighted in blue) follow the hyperlinks to navigate to the specified Topic.
10/10/14 INASP: Effective Network Management Workshops Unit 6: Solving Network Problems.
Motorola Mobility Services Platform (MSP3.2) Control Edition Optimizing use of your mobile assets Daphanie Wallace June 2008 Enterprise Mobility Solutions.
QoS Solutions Confidential 2010 NetQuality Analyzer and QPerf.
SHARKFEST ‘10 | Stanford University | June 14–17, 2010 The Shark Distributed Monitoring System: Distributing Wireshark Deep Packet Analysis to LAN/WAN.
Save the World! What’s appropriate for global networking?
Performance Analysis of Orb Rabin Karki and Thangam V. Seenivasan 1.
We all know the world is changing… Upgrades may break apps We need sufficient time to test Our key software vendors need time to test & issue statements.
Network Terminology … Remember: Knowledge is Power!
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 14: Troubleshooting Windows Server 2003 Networks.
VMWare Workstation Installation. Starting Vmware Workstation Go to the start menu and start the VMware Workstation program. *Note: The following instructions.
Virtual techdays INDIA │ November 2010 Windows Virtual PC & Windows XP Mode Aviraj Ajgekar │ Regional Site Manager │ Microsoft Corporation Blog:
1 Lab 3 Transport Layer T.A. Youngjoo Han. 2 Transport Layer  Providing logical communication b/w application processes running on different hosts 
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Troubleshooting Your Network Networking for Home and Small Businesses.
SHARKFEST '09 | Stanford University | June 15–18, 2009 Protocol Analysis in a Complex Enterprise: The Importance of “The Art of Recognition.” June 16 th,
Slow Web Site Problem Analysis Last Update Copyright 2013 Kenneth M. Chipps Ph.D. 1.
Computer Networking From LANs to WANs: Hardware, Software, and Security Chapter 12 Electronic Mail.
Network Protocols. Why Protocols?  Rules and procedures to govern communication Some for transferring data Some for transferring data Some for route.
ISO Layer Model Lecture 9 October 16, The Need for Protocols Multiple hardware platforms need to have the ability to communicate. Writing communications.
SHARKFEST '08 | Foothill College | March 31 - April 2, 2008 Protocol Analysis in a Complex Enterprise April 2 nd, 2008 Hansang Bae Senior VP | Citigroup.
Global NetWatch Copyright © 2003 Global NetWatch, Inc. Factors Affecting Web Performance Getting Maximum Performance Out Of Your Web Server.
University of Sunderland COMM80 Risk Assessment of Systems ChangeUnit 12 Risk of Change: Networks and Software COMM80: Risk Assessment of Systems Change.
Networking Basics Lesson 1 Introduction to Networks.
Paul Pantazis, Manager IT/OPS.  17 years of IT experience  Started as a DEV but saw the light ( Then DEVOPS ruined the whole thing for me)  Pure ops.
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
Module 4: Planning, Optimizing, and Troubleshooting DHCP
Introduction to Wireshark Making Sense of the Matrix
The Transmission Control Protocol (TCP) Application Services (Telnet, FTP, , WWW) Reliable Stream Transport (TCP) Connectionless Packet Delivery.
A powerful network monitoring system
5 Firewalls in VoIP Selected Topics in Information Security – Bazara Barry.
Mapping Technology to Geography Dylan J. Sather Grinnell College.
XA R7.8 Link Manager How to Manage an R7.8 Environment Ruth Anne Pharr Sr. IT Consultant, CISTECH Inc.
Wireshark In the Large Enterprise Hansang Bae Director – Product Architecture
science/internet-intro
COMP2322 Lab 1 Introduction to Wireshark Weichao Li Jan. 22, 2016.
Page 1 Monitoring, Optimization, and Troubleshooting Lecture 10 Hassan Shuja 11/30/2004.
Authored by Frank Hamelly, Microsoft MVP Regional Chapters.
Office of Administration Enterprise Server Farm March 2006 Briefing.
Chapter 7: Using Network Clients The Complete Guide To Linux System Administration.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 ISP Help Desk Working at a Small-to-Medium Business or ISP – Chapter.
Techdotcomp Support nd Ave, Seattle, WA 98122, USA Phone: Based on Seattle, WA USA.
Website : What is a PSD File?
SharkFest ‘16 Computer History Museum June 13-16, 2016 SharkFest ‘16 Markers – Beacons in an Ocean of Packets Matthew York 15th June 2016 Performance &
25/09/2016 INASP: Effective Network Management Workshops Unit 6: Solving Network Problems.
Real World Case Studies
Solving Real-World Problems with Wireshark
Instructor Materials Chapter 8: Network Troubleshooting
David Wetherall Spring 2000
In the Packet Trenches – Searching is not learning...
Advanced Troubleshooting with Cisco Prime NAM-3: Use Case
The Packet A(nalysis)-Team
Instructor Materials Chapter 9: Testing and Troubleshooting
Upgrade, upgrade, upgrade! Say goodbye to clean installs of Windows 10
Wireshark Lab#3.
Network, Server, or App? Chris Greer
Chapter 16: Distributed System Structures
Juno Technical Support Number
Tailor slide to customer industry/pain points
Packet Sniffing.
The Service Portal What is the Self-Service Web Portal?
Chapter 11: Printers IT Essentials v6.0 Chapter 11: Printers
EFT for Payables Elaine Foley EFT for Payables is a hole in one!
Presentation transcript:

SHARKFEST ‘10 | Stanford University | June 14–17, 2010 Wireshark in the Large Enterprise June 16, 2010 Hansang Bae Senior Vice President | Citi (f.k.a. Citigroup) P LEASE REFER TO THE “ ANSWERSHEET. DOCX ” FILE FOR ADDITIONAL INFORMATION ABOUT THIS PRESENTATION. T HESE SESSIONS WILL BE AVAILABLE ON YOUTUBE : HTTP :// WWW. YOUTUBE. COM / USER / HANSANGB SHARKFEST ‘10 Stanford University June 14-17, 2010

SHARKFEST ‘10 | Stanford University | June 14–17, 2010 Please Let TCP Do Its Job. Problem: Application developers escalate an issue with slow file (MQ) transfers. Troubleshooting Steps: 1.What should you rule out immediately? 2.What affects throughput and why? 3.Look for patterns and ask the right questions. Quick examination would reveal what? Doesn’t it look normal? Can you spot the issue quickly? Were you guys paying attention yesterday?!? 4.Use the graphing tools. Picture is worth a thousand words. 5.Setup your Wireshark environment in a standard way. Use Configuration Manager to help you.

SHARKFEST ‘10 | Stanford University | June 14–17, 2010 Don’t Jump to Conclusions! Another application development team escalates a “slowness” problem. Troubleshooting Steps: 1.Trust But Verify (tcp.analysis.flags) 2.Look for telltale signs of problems. 3.Who’s sending and who’s receiving? Besides looking at the name of the file….can you figure it out? 4.Apply Occam’s Razor when solving problems.

SHARKFEST ‘10 | Stanford University | June 14–17, 2010 Another (unusual) Hidden Danger! Application testing with an external vendor doesn’t work. It tested fine when tested with intra- resources. Troubleshooting Steps: 1.If it works internally but not with an external vendor (reachable via Internet) what device should you suspect? Learn to Divide and Conquer – the power of binary search! 2.Have “High Bandwidth Conversations” with qualified peers. 3.Look out for “Defaults” HSB’ism: Defaults are the guardian angels for the clueless! 4.Another case of “picture is worth a thousand words”

SHARKFEST ‘10 | Stanford University | June 14–17, 2010 Odd Numbers are Evil? Really? Software Update System is slow in delivering packages to staging servers. It impacts 300,000+ users! Troubleshooting Steps: 1.Usual Suspects (Duplex, Window size, Pkt loss, and LFN) 2.Use the information in the trace to eliminate some of the “usual suspects.” Not all inefficiencies come into play. Does Window come into play here? 3.Do I need to see the SYN/SYN+ACK to see what environment this is? What other options are there? 4.Use Time Reference markings liberally? 5.Case of “too much of a good thing”

SHARKFEST ‘10 | Stanford University | June 14–17, 2010 Another Zebra Case! Users are calling into the helpdesk because the Citrix sessions are dying. Main Concept: 1.Applications traversing the Internet play by a different set of rules/standards. Packet loss is a way of life. 2.Do you **REALLY** know TCP? 3.Did you pick up on why the 500ms delay is significant? 4.What is Fast Retransmit and how is it different from “regular” Retransmission? 5.Learn the art of spotting something unusual. But first, you need to understand “what’s unusual.”

SHARKFEST ‘10 | Stanford University | June 14–17, 2010 Wan Optimization After upgrading WAN optimization appliances, tellers started reporting intermittent printing issues. Transient problems like these are the toughest to resolve. What was the time to Resolution? Three days - thanks to packet captures. Main Concept: 1.Last change was OS upgrade on the wan optimization appliance, so start there. 2.Capturing in the right capture points is critical. Why? 3.Is it worth looking at TCP Session #2? 4.What should you compare? What can you compare? 5.Sake Blok’s session last year on SSL decryption was VERY helpful!

SHARKFEST ‘10 | Stanford University | June 14–17, 2010 Wan Optimization (Con’t)

SHARKFEST ‘10 | Stanford University | June 14–17, 2010 Wan Optimization (Con’t)