cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
910
Views
0
Helpful
2
Replies

How to LOG the incoming and outgoing HTTP request ?

Didier1966
Level 1
Level 1

Hello,

I have a CISCO 1841 ROUTER and sins short our internet speed has decreased dramatically , it does not happens all the time , so I am sure it is not the ROUTER.

I have put a small router (CISCO WRT 610N) and it was the same.

When I look to the UP and DOWNLOAD GRAPH from my ISP , I see really BIG peeks.

I would like to see what is causing this ?!?

DEBUG ? LOG ?

Any help is welcome

Best Regards,

Didier

1 Accepted Solution

Accepted Solutions

Atif Awan
Cisco Employee
Cisco Employee

Didier1966 wrote:

Hello,

I have a CISCO 1841 ROUTER and sins short our internet speed has decreased dramatically , it does not happens all the time , so I am sure it is not the ROUTER.

I have put a small router (CISCO WRT 610N) and it was the same.

When I look to the UP and DOWNLOAD GRAPH from my ISP , I see really BIG peeks.

I would like to see what is causing this ?!?

DEBUG ? LOG ?

Any help is welcome

Best Regards,

Didier

Have you considered turning on Netflow on the 1841 and looking at the top hosts from a traffic perspective? This will not only identify the top hosts but also the protocols in use. What it will not be able to tell you is that whether it is genuine HTTP traffic or some peer-to-peer application hiding itself behind port 80. If you need that level of visibility you can consider NBAR with appropriate PDLMs.

Atif

View solution in original post

2 Replies 2

Atif Awan
Cisco Employee
Cisco Employee

Didier1966 wrote:

Hello,

I have a CISCO 1841 ROUTER and sins short our internet speed has decreased dramatically , it does not happens all the time , so I am sure it is not the ROUTER.

I have put a small router (CISCO WRT 610N) and it was the same.

When I look to the UP and DOWNLOAD GRAPH from my ISP , I see really BIG peeks.

I would like to see what is causing this ?!?

DEBUG ? LOG ?

Any help is welcome

Best Regards,

Didier

Have you considered turning on Netflow on the 1841 and looking at the top hosts from a traffic perspective? This will not only identify the top hosts but also the protocols in use. What it will not be able to tell you is that whether it is genuine HTTP traffic or some peer-to-peer application hiding itself behind port 80. If you need that level of visibility you can consider NBAR with appropriate PDLMs.

Atif

Hello Atif,

Thank you for this really good information

I am actually reading all the white pages and when I understand it I will implement it.

Thanks Again.

Best Regards,

Didier

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card