Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > PC Technology Zone > Computer Networking & Internet Access » Pinpointing a 'bad apple' on a network...
Closed Thread
Old 02-24-2005, 11:25 AM   #1 (permalink)
 
Newb Techie

Join Date: Feb 2005

Posts: 3

DTAces

Default Pinpointing a 'bad apple' on a network...

Hello all--

Recently I have been having problems with my network here and I was just wondering if anyone could give me some tips.

Heres what my current setup looks like:

I have a

Comcast Cable Modem Connection

that goes to a

Linksys Router

which splits off into

two 15-port switches

All in all, there are about 25-30 computers connected to this network.

The recent problem has been a slow or nonexistant internet connection due to some computers having spyware/adware/viruses/etc... on them. I have given each computer Spybot S&D, run HijackThis! on each computer, and installed Norton Anti-Virus on each box. The problem is that I dont really have control as to how each computer is being used (since these are other people's PCs) and some mess them up within a few days (sad but very common around here).

Is there some way I can pinpoint that 'bad apple' who is bogging down the network connection?

Everyone has a static IP right now. Is it possible to give everyone unique IP's so I can tell how much traffic is coming from which computer?

Thank you for your help in advance it is much appreciated.

--Dave
DTAces is offline  
Old 02-24-2005, 11:37 AM   #2 (permalink)
 
Super Techie

Join Date: Sep 2004

Posts: 269

VICone

Send a message via AIM to VICone Send a message via Yahoo to VICone
Default

Monitor the network traffic, and use DHCP to see what computer is using what address.
__________________
MCSA, MCP (070-210, 070-218, 070-215), A+, Network+, Security+<br>
<a href=\"http://profiles.myspace.com/users/17229411\" target=\"_blank\">MySpace</a> | <a href=\"http://mcmcse.com\" target=\"_blank\">MCMCSE</a> | <a href=\"http://brainbench.com\" target=\"_blank\">Brainbench : Free Certifications</a>
VICone is offline  
Old 02-24-2005, 11:52 AM   #3 (permalink)
 
Junior Techie

Join Date: Feb 2005

Posts: 67

imDAtek

Default

If you are responsible for the network, you need to be able to control access. Go with the DHCP idea, but even now I would just monitor the network as is & work toward restricting users accounts to prevent access to things that will kill the network.
imDAtek is offline  
Old 02-24-2005, 02:47 PM   #4 (permalink)
 
Newb Techie

Join Date: Feb 2005

Posts: 3

DTAces

Default

Thanks for the input, but I dont think restricting PCs would work in this situation. The only reason Im in charge of the network is because the other 20+ users know jack squat about computers, let alone how a network works.

Basically I want to pinpoint what computer(s) are the problem and just disconnect them from the network and snip their CAT5 so they can never plague the network again.

Now by using DHCP Im assuming I can track what box is using what IP. Now how do I go about tracking the traffic of these IPs?
DTAces is offline  
Old 02-24-2005, 03:23 PM   #5 (permalink)
 
Ultra Techie

Join Date: May 2004

Posts: 725

digitaloracle

Default

Some routers have a stutus page, that reports where recent requests for remote sites came from. Try typing in the ip of your router (a common one for such a device is 192.168.0.1) into a web browser and see if you get anything. Better yet, check the Linksys site. That's the easiet way of identifying the problem comps that I can think of, and probably the only way that I can fully undersand. Rather than killing their connection, which with what info you gave sounds a bit harsh, you might want to consider a firewall computer. Doesn't have to be very fast, and I'm sure that there are plenty of free apps out there for such a device. Alternatively, you could by a business firewall apartus for around $500-$2000 US.

I only put thse out as solutions that come to mind. I have no idea how do imlement any of those systems, if they are even a viable option for your situation.
__________________
AGP won\'t fit in PCI-E... unless you use a really good hammer. ~Trotter
digitaloracle is offline  
Old 02-24-2005, 04:59 PM   #6 (permalink)
 
Junior Techie

Join Date: Feb 2005

Posts: 67

imDAtek

Default

Google for look@lan, download & install. It's freeware that will give you a little insight to what's sitting on your network
imDAtek is offline  
Old 02-24-2005, 07:31 PM   #7 (permalink)
 
True Techie

Join Date: Feb 2005

Posts: 122

geffin

Default

Quote:
Originally posted by imDAtek
Google for look@lan, download & install. It's freeware that will give you a little insight to what's sitting on your network
Yes, look@lan is good, you can also try browsing
SourceForge.

just make sure you are browsing windows software, there, you will find many network utilities under the gnu/gpl (free open source). Just try finding a good network monitor that works for you.
__________________
Quote:
In the eyes of Bill Gates, the open source world seems un-activated...
geffin is offline  
Old 02-24-2005, 10:39 PM   #8 (permalink)
 
Wizard Techie

Join Date: Apr 2004

Posts: 3,248

killians45

Default

use net monitor in conjuction with time frames that IP's were logged in. net monitor will let you know when traffice starts to spike. to freak the individual out, net send to the person when you pin point him to let him know you're on to him.
__________________
If you argue with an idiot he will drag you down to his level and beat you with experience.

I am not a fast writer.
I am not a slow writer.
I am a half-fast writer.

-Robert Asprin
killians45 is offline  
Old 02-24-2005, 10:59 PM   #9 (permalink)
 
True Techie

Join Date: Feb 2005

Posts: 122

geffin

Default

Quote:
Originally posted by killians45
use net monitor in conjuction with time frames that IP's were logged in. net monitor will let you know when traffice starts to spike. to freak the individual out, net send to the person when you pin point him to let him know you're on to him.
LOL. brings back memories of school, and when the techs didn't know that net send could work (or even existed). Don't ask me, the school that I went to must have been poor, and way too stoopid... they hired normal people. not nerds....
__________________
Quote:
In the eyes of Bill Gates, the open source world seems un-activated...
geffin is offline  
Old 02-25-2005, 01:07 PM   #10 (permalink)
 
Newb Techie

Join Date: Feb 2005

Posts: 3

DTAces

Default

haha! Too funny...

I remember netsending comps "Internal Windows Error: The computer will restart in 5 seconds."

"3"

"2"

"1"

"Goodbye"

and then use a remote connection prog to shut down their computer.

Those were the days...

Back on subject: Thank you for all the help. Ill try some of these progs and get back to you with some results (Im sure you guys are dying to know :rolleyes: )

Thanks again!
DTAces is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On