Analyze Reasons for Slow Network

Slow network is a common phenomenon. For the diversity of the reasons causing slow network, to troubleshoot slow network is one of the most common and troublesome work in daily network management.

According to analysis, major reasons for slow network are:

  1. Loopback
  2. Broadcast/Multicast storm
  3. Virus attack
  4. Server slow response
  5. Too many clients
  6. Application slow response
  7. Error client mask

How can we quickly find out the cause for slow network happens? It's a good idea to capture and analyze packets with a network analyzer.

Deep Analysis of Slow Network

Network analyzer works in sniffing mode. It can capture and analyze network communications in real time. After analysis, we can find reasons for slow network. Here we use Colasoft Capsa.

The following table lists the reasons, phenomenon of slow network in Colasoft Capsa GUI, and corresponding solutions:

Reason Phenomenon Solution
Loopback A lot of retransmission packets in the Packet tab, all field values are same, such as: IP identification, TCP sequence number, TCP ack-number. Obvious increase of network utilization. Check connection of switching device, pull out the line directly connecting two ports
Broadcast/Multicast storm Large numbers of broadcast/multicast packets in the Packet tab. Broadcast/Multicast traffic is higher than 20% of total traffic in the Summary tab. Locate retransmission packets, view source MAC address. Then disconnect the problem host.
Virus Attack There are a lot of connections with same source MAC address and same destination port but different destination address, and in short intervals. View source address of these connections and disconnect the suspect hosts.
Server Slow Response In the Packet tab, SYN/ACK response time too long in TCP three handshakes process. Adjust server configuration and optimize the parameter
Too Many Clients Too many nodes in the Node Explorer, the Physical Endpoint tab and the IP Endpoint tab. Upgrade network settings.
Application Slow Response In the Packet tab, packets response time to applications is too long. Adjust server configuration and optimize the parameter
Error Client Mask In the Packet tab, data that should be transmitted through layer 2 are retransmitted through layer 3. Change IP address and mask of the client.

Conclusion

Reasons causing slow network are diversified, there is no absolute way that can guarantee normal network operation. With a network analyzer you can quickly find out the reason that causes slow network, thus greatly enhanced network management efficiency.