A network protocol analyzer is a vital part of a network administrator's toolkit. Network protocol analysis is the truth serum of network communications. If you want to find out why a network device is functioning in a certain way, use a protocol analyzer to sniff the traffic and expose the data and protocols that pass along the wire. You can use a network protocol analyzer to
* troubleshoot hard-to-solve problems
* detect and identify malicious software (malware)
* gather information, such as baseline traffic patterns and network-utilization metrics
* identify unused protocols so that you can remove them from the network
* generate traffic for penetration testing
* work with an Intrusion Detection System (IDS) or a honeypot
* eavesdrop on traffic (e.g., locate unauthorized Instant Messaging—IM—traffic or wireless Access Points—APs)
* learn about networking
If you manage a network and don't yet have a protocol analyzer, you need one. To help you find the network protocol analyzer that suits your environment, I first survey some typical features of software-based protocol analyzers. Then, I examine and compare these features in six popular network protocol analyzers. . . .
Tuesday, March 24, 2009
Selecting a protocol analyzer
Consultants have used a protocol analyzer or "sniffer" to help identify the source of problems on our network. I have been thinking about adding a tool like this to our collection but wasn't sure which one to use?
-- via the Internet
Choosing a protocol analyzer is not something that you should jump right into. There are several good candidates out there. The three most popular ones that I know of are Sniffer from Sniffer Technologies (www.sniffer.com aka Network Associates), Etherpeek from www.wildpackets.com and Ethereal from www.ethereal.com. I used to recommend a fourth candidate from Novell but they seem to have stopped supporting their software based analyzer. I haven't seen any new protocol decodes released for several years.
The cost of these ranges from free (in the case of Ethereal) to more than $10,000 for a fully equipped Sniffer package from Network Associates. I encourage you to get an eval copy of the above mentioned sniffers and run them through their paces. Etherpeek and Ethereal can be downloaded while Sniffer will require you to fill out a form and someone will call you in a couple of days to follow up.
Advertisement:
You won't have to delve deep into the guts of a packet or need to decode the parts that make up a packet frame to see a problem. When I have used a protocol analyzer in the past, I have found problems by finding abnormal traffic on the network. Just like your anti-virus software, you should also keep the protocol decodes up to date. This will allow you to see the traffic that is on the wire.
Most of the vendors will offer some type of training to help you use their product to its fullest. One last option comes from Laura Chappell. Laura travels the world giving seminars on how to use protocol analyzers and has written several books on the subject. You can check her web sites www.packet-level.com and www.podbooks.com for packet trace files she has made available for download and for books she has written on the subject. If you have the chance, go hear her speak either at Novell's Brainshare conference or at other events. This is money well spent!
-- via the Internet
Choosing a protocol analyzer is not something that you should jump right into. There are several good candidates out there. The three most popular ones that I know of are Sniffer from Sniffer Technologies (www.sniffer.com aka Network Associates), Etherpeek from www.wildpackets.com and Ethereal from www.ethereal.com. I used to recommend a fourth candidate from Novell but they seem to have stopped supporting their software based analyzer. I haven't seen any new protocol decodes released for several years.
The cost of these ranges from free (in the case of Ethereal) to more than $10,000 for a fully equipped Sniffer package from Network Associates. I encourage you to get an eval copy of the above mentioned sniffers and run them through their paces. Etherpeek and Ethereal can be downloaded while Sniffer will require you to fill out a form and someone will call you in a couple of days to follow up.
Advertisement:
You won't have to delve deep into the guts of a packet or need to decode the parts that make up a packet frame to see a problem. When I have used a protocol analyzer in the past, I have found problems by finding abnormal traffic on the network. Just like your anti-virus software, you should also keep the protocol decodes up to date. This will allow you to see the traffic that is on the wire.
Most of the vendors will offer some type of training to help you use their product to its fullest. One last option comes from Laura Chappell. Laura travels the world giving seminars on how to use protocol analyzers and has written several books on the subject. You can check her web sites www.packet-level.com and www.podbooks.com for packet trace files she has made available for download and for books she has written on the subject. If you have the chance, go hear her speak either at Novell's Brainshare conference or at other events. This is money well spent!
Subscribe to:
Posts (Atom)