I put a switch with a mirror port between ISP router and MX. If you capture on the MX, you won’t see the problem, because the MX can’t capture and “send to the cloud” because there is not sufficient bandwidth. Connect a pc with wire shark to the mirror port. Set Wireshark to capture and log to file. I set it to log to file in 60 sec increment, this way it wouldn’t crash. It is really easy to then go back and correlate a few files with your packet loss. Open in wire shark and go to conversations and you will likely see UDP traffic from DNS servers all over the world. (Likely not a single massive offender). to be clear, you won’t see a spike in bandwidth during this time on the MX. You won’t see any anomalies internally either. The traffic never makes it into the LAN.
... View more