To discover the problem, follow these steps:
- Start Wireshark with capture on the interface that is close to the problem:
- If the line to the internet becomes slow, port-mirror the line
- If a server becomes slow, port-mirror the server
- If remote offices become slow, port-mirror the lines to them
- If you see that Wireshark does not respond, it is probably because you have a very strong attack that generates thousands or more packets per second; so, Wireshark (or your laptop) cannot process them. In this case, stop Wireshark (with Ctrl + Alt + Del in Windows, the kill command in Unix if necessary, or Force Quit in Apple Mac) and configure it to capture multiple files (described in the start capturing data section in Chapter ...