Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


July 2004

6 Network Protocol Analyzers

Do you know what's passing over the wire? These products can tell you.
RSS
Subscribe to Windows IT Pro | See More Products / Hardware Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
SideBar    Hardware Protocol Analyzers

Netasyst Network Analyzer has a full complement of features, including many statistics screens, graphical charts, SNMP traps, and triggers. The product also provides dozens of alarms with predefined thresholds, which you can set to generate alerts for various problems, such as slow servers, high-volume VoIP traffic, excessive logon failures, FTP logon attempts, WINS duplicate name errors, too many retransmissions, domain controller (DC) shutdown, Layer 2 errors, broadcast storms, and network topology changes. Although most protocol analyzers provide alarms, Netasyst Network Analyzer is unique in that its thresholds are predefined. In the wireless versions of the product, you can enable route AP or wireless node discovery. Netasyst Network Analyzer also provides more VoIP features than its competitors. On the downside, Netasyst Network Analyzer doesn't decode 802.11g, Kerberos, or RDP traffic and splits LAN and wireless functionality into different product versions.


Netasyst Network Analyzer
Network Associates - 972-963-8000 or 800-764-3337 www.sniffer.com
PRICE: $1995 to $7495 (WLX version); includes 1-year, 24 x 7 technical support
DECISION SUMMARY
PROS:
Many features
Best expert analysis among reviewed products
VoIP support
Downloadable malware filters
Excellent technical support
CONS:
Missing some Windows decoders, such as Kerberos and RDP
Separate versions for LAN and wireless networks
Supports only promiscuous mode on certain NICs

Network Instruments' Observer
Network Instruments' Observer is another solid top performer and a contender for midsized-to-large networks. Observer is built to be distributed, designed to handle large volumes of data, and coded to run on more types of network interfaces than any of the other reviewed products. Distributed protocol analyzers provide two functions: a management station and a client packet-capturing component. Clients can be distributed throughout the enterprise, and all the distributed data is collected and analyzed on one management workstation. Network Instruments calls this distributed architecture Distributed Network Analysis (NI-DNA). When you install Observer, you can choose to install the complete Observer package, which includes the decoding and reporting console, or a probe—software that captures packets on local and remote networks and interacts with the Observer console. Network Instruments says that it's had as many as 350 probes reporting in one production environment. Data can be reported separately or in aggregate. Observer can reserve up to 4GB of memory for packet capturing coming from up to 64 different network interfaces. (Could anyone need that many interfaces?) Observer supports wired topologies from 10Mbps to full-duplex gigabit.

Although some protocol analyzer vendors differentiate their products between LAN and wireless capabilities, every version of Observer supports LAN, remote monitoring (RMON), WAN, and wireless. Network Instruments readily promotes WAN solutions involving DS3, E1, High-Speed Serial Interface (HSSI), and T1 interfaces. You can order prebuilt 4U (7") rack-mounted solutions, with or without the WAN kit. Observer also offers more wireless options than its competitors. It's one of the few LAN protocol analyzers that decodes the 802.11a, 802.11b, and 802.11g wireless protocols. Furthermore, all Observer probes sport the same look and feel. Competing protocol analyzers don't provide nearly as wide a spectrum of choices with the same interface as Observer does.

One of the first things you notice about Observer is that it provides Help windows with explanations during the setup and first use of the product (other products, such as EtherPeek, also provide this sort of help). Multiple 15-minute tutorial windows are available to help you learn to use the product. In Observer, Network Instruments seems to have considered the end-user experience a bit more than some of its competitors have. You can right-click any packet and create a quick filter that displays only packets that are related to that packet's IP address, only packets that are related to that packet's IP address and the other host involved, or only packets sent and received between the two related hosts and to the same or related IP port numbers. For example, with one click you can capture all traffic between a Web server and its back-end database and filter out unrelated traffic. Other protocol analyzers let you define the same types of filters, but most require more than a dozen clicks to accomplish what Observer does in one click.

Like other analyzers, Observer displays a wide spectrum of reports, summaries, and statistics, which Figure 6 shows. The product's filters include more than 30 malware filters, including filters for wireless Denial of Service (DoS) attacks, common malware, and what Observer calls hack filters (which is a subset of a larger filter set that Observer can use). Observer contains a full complement of alarms and triggers. The product also has a distinct network-mapping feature that you can use separately to convert IP and MAC addresses to DNS or NetBIOS names. In my testing, the product analyzed traffic to automatically determine which machines were servers and even which application functions they performed. Observer recognizes 14 different applications, such as Exchange, Oracle, SQL Server, and VoIP.

I found most of Observer's protocol decodes and the information shown at each layer to be among the best of the products I reviewed. Observer sometimes had problems recognizing well-known protocols on nondefault ports (e.g., HTTP, RDP); however, you can modify Observer's decoders to monitor traffic on other ports, as you can with other protocol analyzers. For certain protocols, Observer stood ahead of the pack. It was one of the few analyzers to recognize and properly decode my Kerberos and LDAP traffic each and every time. Other analyzers would note the UDP packets on port 88 and might label them Kerberos packets in the detail view, but Observer told me the difference between my Kerberos requests and tickets that were successfully granted. Observer can replay up to 5MB of data from the capture buffer over the network.

   Previous  1  2  3  [4]  5  6  Next 


Reader Comments
Another good low cost product for the budget minded admin is LinkFerret from Baseband technologies. According to their website, they write most of the code for the other analyzer vendors.

Randall Ader July 06, 2004


Another good sniffer is LanRaptor from www.shakti-software.com.

You can define your own protocols, so if they dont provide support, you can still fully decode any protocol that is important to you.

Anonymous User October 08, 2004 (Article Rating: )


One thing not touched on in the article is the major difference between a software and a hardware analyzer. Only good packets can be seen by a software analyzer. If the packet cannot make it up to the top layer of the OSI 7 Layer model, you won't see it. Also the quality of the network driver is important. Some LAN cards and drivers won't work or work properly in a promiscuous mode.

Anonymous User November 23, 2004 (Article Rating: )


Check our Greenleaf ViewComm System, excellent async and ethernet protocol analyzers - www.sysfire.com

Anonymous User January 04, 2005 (Article Rating: )


This article is worthless

Anonymous User February 14, 2005 (Article Rating: )


Good overview of some of the more popular protocol analyzers and their features. A matrix with comparison criteria and ratings would have been helpful. The posting made by the Anonymous user from Feb 14th, 2005 is worthless, not this article.

Anonymous User March 23, 2005 (Article Rating: )


good passage!

haiwanxue March 10, 2006 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

New Microsoft/Yahoo! Deal? No

On Sunday, the Times of London reported that Microsoft had renewed talks with failing Internet giant Yahoo! and would manage its search engine for 10 years, while Yahoo! would retain control of its email, messaging, and content services. This report ...

How can I stop and start services from the command line?

...


Windows OSs Whitepapers Why SaaS is the Right Solution for Log Management

Related Events SQL Server 2008 – Can You Wait? | Philadelphia

SQL Server 2008 – Can You Wait? | Atlanta

SQL Server 2008 – Can You Wait? | Chicago

Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing