Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


July 2004

6 Network Protocol Analyzers

Do you know what's passing over the wire? These products can tell you.
RSS
Subscribe to Windows IT Pro | See More Products / Hardware Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
SideBar    Hardware Protocol Analyzers

On the need-to-improve side, Observer's main UI is overly busy because it attempts to provide as much functionality as possible in one window. The window is a little crunched, tabs obscure one another somewhat, and the overall picture can be a bit daunting to new users. Also, when I changed malware filters, the window often resized itself, thereby undoing my custom settings. Despite these minor imperfections, Observer is a solid standalone performer and an obvious choice for distributed-networking environments with a wide range of needs.


Observer
Network Instruments - 952-932-9899 or 800-526-7919 www.networkinstruments.com
PRICE: $995; includes 90 days of standard support; optional maintenance packages and 24 x 7 support available
DECISION SUMMARY
PROS:
Easy to use
Excellent packet decodes
Geared toward distributed environments
LAN, WAN, and wireless abilities
Replay ability
CONS:
Main window overly busy
Minor screen redraw problems
Protocol decodes not always accurate

Sunbelt Software's LanHound
Although Sunbelt Software might be best known for its iHateSpam product, the vendor provides many other useful products. Sunbelt Software markets LanHound specifically as a low-cost choice that provides many of the basic features that most network administrators need in a protocol analyzer. LanHound consists of two products: an administrative console and a remote packet-capturing agent (the console also captures packets). LanHound runs on any platform with Win98 or later installed, except for Windows 2003.

LanHound has an easy-to-use GUI, which Figure 7 shows, with most of the features you expect in a protocol analyzer, including capture filtering, name lookups, alarms, triggers, and a host of display reports. The alarm feature is limited; it notifies you only when a protocol session, such as FTP or POP, sends unencrypted passwords. LanHound provides little other expert analysis beyond the alarm feature. Reports include histograms, host tables, packet summaries, and traffic matrixes. As with other analyzer products, you can slice and dice the analysis data that LanHound provides just about any way you want, including as bar graphs and pie charts. I was surprised to find that LanHound can manipulate and replay captured traffic back over the network—a feature that isn't always available in lower-end products.

Overall, I was pleased with LanHound's feature set, although as I expected, its decoding wasn't as strong and detailed across most protocols as that of competing products. For example, default packet details are displayed by default in hex instead of easier-to-read ASCII, which can make reading traffic such as HTTP difficult. LanHound's Server Message Block (SMB) traffic decoding was rather good, but the product completely missed identifying Exchange, RDP, and many other default Windows protocols. Like some other products I reviewed, LanHound missed classifying well-known protocols running over nondefault ports. LanHound is a low-end protocol analyzer that provides all the basics plus traffic replaying, but it lacks the decode support of other products in this review.


LanHound
Sunbelt Software - 727-562-0101 or 888-688-8457 www.sunbelt-software.com
PRICE: Starts at $595 for one administrative console and three remote agents
DECISION SUMMARY
PROS:
Easy-to-use GUI
Good summary reporting
Accurate SMB decoding
Packet replaying
CONS:
Weak decoding of many protocols
Doesn't work on Windows 2003
No expert analysis

WildPackets' EtherPeek
WildPackets' product line includes protocol analyzers for a range of needs. EtherPeek is geared toward small-to-midsized businesses. I reviewed the NX 2.1 version of the product ("NX" means it provides expert analysis). EtherPeek offers a variation on the typical contents of the three-pane protocol analyzer window by providing a dashboard and a log window in two bottom panes, as Figure 8 shows. EtherPeek's UI is a bit softer on the eyes than the UIs of the other products and contains more default color differentiation. Although the purely technical side of me hated to admit it, EtherPeek's use of color does make analyzing protocols easier. Most other analyzers let you color-code packets, but EtherPeek does this automatically and thoughtfully. EtherPeek has the best UI, in terms of form and natural workflow, among the competitors.

Although EtherPeek is meant for smaller networks, it doesn't skimp on features. The product displays captured packets in real time by default (real-time display is turned off by default in most products because it affects performance), and still the display seems crisp and responsive. I didn't test EtherPeek under high network-utilization loads, but I'd be interested to see the results for display performance. Conventional wisdom says that the great-looking real-time interface, use of color, and default name resolution will slow the product down under larger packet loads, but you can disable these features if performance suffers. EtherPeek, like the other products in this review, can open multiple capture windows at the same time, each displaying different interfaces being captured or with different focuses. For instance, you could capture IP traffic in one window, IPX in another, and in another display RMON input (with the help of the WildPackets' RMONGrabber add-on).

EtherPeek decodes hundreds of protocols, and I found most of the decodes to be accurate. Netasyst Network Analyzer and Observer gave a few more decode details for several protocols, but EtherPeek held its own in most areas. The product showed TCP flags and whether they were on or off but not what they meant in practical terms. Or, EtherPeek noted that HTTP data was being downloaded but not that it was graphical. And just when I started to think that EtherPeek was a second-place product, I discovered that it recognized IM, Kerberos, and VoIP traffic correctly and surpassed some of its better-known competitors. In fact, on the network and application layers, EtherPeek came in just behind Netasyst Network Analyzer in its reporting capabilities. EtherPeek noted DNS errors, slow servers, POP logon errors, and unreachable hosts. Well-placed icons made these errors easy to notice. Unfortunately, making errors easy to see can be problematic. My EtherPeek testing revealed numerous bad TCP checksum false-positive errors, but WildPackets has promised to fix this problem soon.

   Previous  1  2  3  4  [5]  6  Next 


Reader Comments
Another good low cost product for the budget minded admin is LinkFerret from Baseband technologies. According to their website, they write most of the code for the other analyzer vendors.

Randall Ader July 06, 2004


Another good sniffer is LanRaptor from www.shakti-software.com.

You can define your own protocols, so if they dont provide support, you can still fully decode any protocol that is important to you.

Anonymous User October 08, 2004 (Article Rating: )


One thing not touched on in the article is the major difference between a software and a hardware analyzer. Only good packets can be seen by a software analyzer. If the packet cannot make it up to the top layer of the OSI 7 Layer model, you won't see it. Also the quality of the network driver is important. Some LAN cards and drivers won't work or work properly in a promiscuous mode.

Anonymous User November 23, 2004 (Article Rating: )


Check our Greenleaf ViewComm System, excellent async and ethernet protocol analyzers - www.sysfire.com

Anonymous User January 04, 2005 (Article Rating: )


This article is worthless

Anonymous User February 14, 2005 (Article Rating: )


Good overview of some of the more popular protocol analyzers and their features. A matrix with comparison criteria and ratings would have been helpful. The posting made by the Anonymous user from Feb 14th, 2005 is worthless, not this article.

Anonymous User March 23, 2005 (Article Rating: )


good passage!

haiwanxue March 10, 2006 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

How can I stop and start services from the command line?

...

PsExec

This freeware utility lets you execute processes on a remote system and redirect output to the local system. ...


Windows OSs Whitepapers Why SaaS is the Right Solution for Log Management

Related Events SQL Server 2008 – Can You Wait? | Philadelphia

SQL Server 2008 – Can You Wait? | Atlanta

SQL Server 2008 – Can You Wait? | Chicago

Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing