Ask Your Question

Revision history [back]

Unexplained data usage > Wireshark > Ethernet / NIC config >

Hi there.

I was hoping that you could help me with a couple of issues that I'm trying to get resolved.

Background: I'm helping out a friend who has a pretty complex home network set-up

Basic network overview:

Enterprise wireless modem/router (using a SIM card and mobile network, for network access) > Swich 1 > Switch 2 Switch 3 Swtich 4

Switch / network 2 = security cameras Switch / network 3 = office / work PCs Switch / network 4 = guest Wi-Fi

Issue: They are experiencing very large and (unexplained) spikes in data usage We are trying to establish what is causing this.

We have done a variety of testing and the issue is definitely being caused from something within this internal network infrastructure.

They have a spare PC which they are going to install Wireshark onto (it currently only has x1 NIC card, and Ethernet port)

This PC is going to be connected directly between the modem/router and the 1st Switch on the network (to capture as much traffic and throughput as possible).

Enterprise modem/router > Spare PC with wireshark > Switch 1 > Rest of network

Questions:

  1. Do we need a 2nd NIC card installed into the PC, to feed out from the PC back into the 1st Switch, so that we can capture all of the traffic on the network ?

  2. Or could we instead, use an Ethernet splitter with the original NIC card to give us 2 Ethernet ports, and use one of them to connect back into the 1st switch. Again - to capture all of the network traffic ?

  3. Is there anything else that I'm missing to be able to achieve this ?

TIA for any help or advice !