Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


July 2004

6 Network Protocol Analyzers

Do you know what's passing over the wire? These products can tell you.
RSS
Subscribe to Windows IT Pro | See More Products / Hardware Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
SideBar    Hardware Protocol Analyzers

Protocol Expert supports more than 250 protocols, including Cisco, IBM Lotus Notes, SIP, Virtual LAN (VLAN), and Voice over IP (VoIP). The product offers more than 150 predefined, customizable alarms that can generate alerts to send over a LAN, in an email message, or to a pager. You can set alarms and triggers to launch predefined applications, such as antivirus scanners or IDSs. I found Protocol Expert's protocol decodes informative, though not quite as detailed as those of Netasyst Network Analyzer and Observer. Protocol Expert lets you display the usual set of summary reports, such as protocol distributions, conversation tables, top senders, and host matrixes, by clicking a menu bar icon. You can save captured data to bitmap (.bmp), comma-separated value (CSV), or Microsoft Excel file formats. Protocol Expert also lets you modify captured traffic and replay it over the network. This feature can be useful in testing firewalls, IDSs, and other network defenses.

Protocol Expert's Expert View is formatted in a welcoming Open System Interconnection (OSI) layer model, which Figure 4 shows. Different layers report different events, which can make troubleshooting easier. For example, the Data Link layer expert analysis might report spoofed MAC addresses or broadcast storms, and the Transport layer might report IP checksum errors or synchronous idle character (SYN) attacks. I found the product's Expert View useful for the most part, although the Application layer expert-analysis module needs more depth. This module covers only the basic applications, such as FTP, HTTP, and NetWare Core Protocol (NCP), and even those reported summary counters need improvement. Several competitors offer Exchange, SQL Server, and many other common applications and counters.


OptiView Protocol Expert
Fluke Networks - 425-446-4519 or 800-283-5853 - www.flukenetworks.com
PRICE: $3195 to $3500
DECISION SUMMARY
PROS:
Solid protocol decoder
Distributed network support
Expert-analysis view
Traffic replaying
CONS:
User-friendliness and GUI need improvement
More application-layer expert analysis needed
Doesn't run on Windows 2003 or Win2K Server

Network Associates' Netasyst Network Analyzer
Network Associates has a long history of providing network protocol analyzer products, including the InfiniStream Network Management, Netasyst Network Analyzer, and Sniffer product lines. Recently, Network Associates sold these lines to Silver Lake Partners and Texas Pacific Group, which will sell the products through a new company called Network General upon completion of the acquisition (expected in third quarter 2004). The InfiniStream Network Management and Sniffer product lines, which include a hardware appliance and software, are targeted at larger enterprises that need high-speed (i.e., gigabits per second—or Gbps) analysis, long-term storage and capturing, and the ability to replay captured traffic over the network. Netasyst Network Analyzer is targeted at small-to-midsized businesses that have fewer than 1000 nodes. The product comes in two versions—standard and expert (X)—with three options for each version: 10Mbps/100Mbps LAN (L), 802.11 wireless (W), or wireless and LAN (WL). The standard and expert versions have the same packet-decoding engine, but the expert version offers additional analysis automation and tools. Pricing varies depending on the version and options you buy.

Netasyst Network Analyzer is a solid network protocol analyzer, and its maturity is evident. Although the Netasyst Network Analyzer name is new, the product is backed by Network Associates' years of experience in the protocol analyzer market. When you install Netasyst Network Analyzer, you can catch glimpses of the filenames of Sniffer and Net X-Ray, upon which the product is based. Netasyst Network Analyzer requires Windows XP or Win2K, Microsoft Internet Explorer (IE) 6.0 or later, and Sun Microsystems' Java 2 Runtime Environment (JRE2), which is used to display graphics. Netasyst Network Analyzer is chock-full of features everywhere you look. The default statistics dashboard displays at start-up and is one of the product's most recognized features. The dashboard displays network utilization, the number of packets, and the number of errors.

Netasyst Network Analyzer decodes more than 280 different protocols. The product provides some of the most accurate and detailed decodes among the products in this review. It's hard not to be impressed. For example, the summary window, which Figure 5 shows, offers a wealth of information. HTTP packet summaries tell you what the packets are doing (e.g., which HTML command is being issued, what page or graphic is being downloaded). Each packet flag has a value and a short explanation right in the decode, which isn't unusual for any protocol analyzer product. However, Netasyst Network Analyzer conveys this information a degree better than most of its competitors. It analyzes packets and notes relationships among them; for example, fragmented packets or session data that's split up among multiple packets is readily identified as belonging together. The product highlights abnormal conditions, such as long acknowledges (ACKs), retransmissions, and out-of-sequence packets. None of the other products I review noted as many network problems as Netasyst Network Analyzer does. Although the immediate value of seeing retransmissions and TCP window locks is questionable to the ordinary administrator, such information is useful for determining a baseline view of your network. Developers and network de-signers should strongly consider using Netasyst Network Analyzer when they fine-tune application performance. When I tested the product, it picked up traffic running on nonstandard ports. Many of its Windows decodes were exceptional; the product explained most packet fields and converted binary information into information I could understand.

Another interesting feature of Netasyst Network Analyzer (probably influenced by its antivirus cousin, McAfee VirusScan) is its ability to download malware filters from the McAfee Web site, which you can then load into Netasyst Network Analyzer to detect malicious code. The McAfee Web site http://www.nai.com/us/security/resources/sv_home.htm#filters currently lists 20 malware filters, including filters for recent viruses, such as MyDoom and Netsky. Although Netasyst Network Analyzer isn't meant to be a full network IDS or antivirus scanner, its ability to download malware filters can come in handy.

   Previous  1  2  [3]  4  5  6  Next 


Reader Comments
Another good low cost product for the budget minded admin is LinkFerret from Baseband technologies. According to their website, they write most of the code for the other analyzer vendors.

Randall Ader July 06, 2004


Another good sniffer is LanRaptor from www.shakti-software.com.

You can define your own protocols, so if they dont provide support, you can still fully decode any protocol that is important to you.

Anonymous User October 08, 2004 (Article Rating: )


One thing not touched on in the article is the major difference between a software and a hardware analyzer. Only good packets can be seen by a software analyzer. If the packet cannot make it up to the top layer of the OSI 7 Layer model, you won't see it. Also the quality of the network driver is important. Some LAN cards and drivers won't work or work properly in a promiscuous mode.

Anonymous User November 23, 2004 (Article Rating: )


Check our Greenleaf ViewComm System, excellent async and ethernet protocol analyzers - www.sysfire.com

Anonymous User January 04, 2005 (Article Rating: )


This article is worthless

Anonymous User February 14, 2005 (Article Rating: )


Good overview of some of the more popular protocol analyzers and their features. A matrix with comparison criteria and ratings would have been helpful. The posting made by the Anonymous user from Feb 14th, 2005 is worthless, not this article.

Anonymous User March 23, 2005 (Article Rating: )


good passage!

haiwanxue March 10, 2006 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

How can I stop and start services from the command line?

...

PsExec

This freeware utility lets you execute processes on a remote system and redirect output to the local system. ...


Windows OSs Whitepapers Why SaaS is the Right Solution for Log Management

Related Events SQL Server 2008 – Can You Wait? | Philadelphia

SQL Server 2008 – Can You Wait? | Atlanta

SQL Server 2008 – Can You Wait? | Chicago

Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing