Here are my first lines about how investigating on our production network.
One of my tasks in my current job is to do some "network forensic".
As a CSI agent with a crime, we have to investigate and find the cause of some network problems: link down, bad performance or lost packets (in trading rooms, the packet loss may even be more critical, it is hard to believe that banks can lose a lot of money by losing a packet).
To be able to provide a cause to network problems, here some clues to check: