Thursday, January 11, 2007

Spiking, max'd out, flatlined, dropped...


Bandwidth is max'd out

The school I worked at today had some serious networking issues. I spoke with them at 9:45 a.m. and asked them to swap out a fiber cable. You can see the dip in the traffic at that time. With the new fiber cable in place, it wasn't long before it shot back up there. This school has three T1 lines coming back to our home office.

I know the graph makes it appear as if they have 4 T1 lines, but figure each T1 is actually 1.544 Mbps (so 3 times 1.544 = 4.632 Mbps). The very top of the traffic (green) is peaking above the 4 on the graph. We bond the 3 T1 lines together (through the telco) to give the school on big Internet pipe. To read more about "The speed of..." you can go here.


We are changing our schools from T1 line(s) to a fiber connection. Since my area (lucky me) has recently switched cable companies, we are still discussing this option over with the new company. Our telco was way too pricey, so we won't even consider them. Until then (maybe another year) most of the school's in my area have to limp along on the T1 connections.

I went to the school at 12:30 p.m. You can see my troubleshooting results as I would dis-connect one section of the LAN and the traffic would drop, just to have it crop up in another area. We had tried to setup VLAN's at this district over the holidays, but the home office had not properly prepared for it and they ordered the wrong type of fiber cables. Blah.

So the term "spiking" is when you see a sudden rise in the traffic bandwidth and it shoots straight back down. The "max'd out" (maximum bandwidth) is when it uses all of the bandwidth that it can and stays up there full throttle. The bandwidth is "max'd out". When it finally stops - it "drops". The bandwidth goes down to a more normal reading. The "flatline" part is when the network is dead, with no traffic and the indicator line sits at the bottom of the graph not showing any movement on the network.

It gets pretty interesting using this terminology. I guess it all carries over from another occupation's terminology.

Anyways, I was working on the problem tonight and I "hope" I found the problem. This district has 8 LAN switches with old code on them. In each and every one, I re-configured 50 ports (48 ethernet and 2 gigabit) to "port block multicast". Hopefully, they can play defense against any ip multicast storms that happen their way. As I was in the middle of my fifth switch, it dawned on me that perhaps I only needed to block multicast on the gigabit ports. I am really hoping I don't have to go back in and block all ports for unicast flooding as well. Sigh.

Alas, this was my world today. I am so ready for bed.

No comments: