Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


June 2008

Network-Monitoring Tools

Gain insight into the content and characteristics of your network traffic
RSS
Subscribe to Windows IT Pro | See More Products / Hardware Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Executive Summary:

We drill down into the basics and look at what matters most in a network-monitoring tool, covering data-monitoring products, or packet sniffers, which examine the contents of individual packets, giving you the power to monitor the data traversing your network at a protocol level, and statistical monitoring products, which examine the way data flows through the network. The best network-monitoring tactic combines both approaches. More than fifteen network-monitoring products are laid out in the accompanying table offering a quick overview of features offered and prices.

Perhaps your network performance has become rather sluggish, or maybe you’ve just realized that you have no idea what kind of data is actually traveling through your network. Either way, you need a tool that’ll not only let you peek at network traffic and data but also let you perform analysis and troubleshooting.

In a previous buyer’s guide, we provided a unique approach to the topic by focusing on both network-traffic monitoring and service monitoring (see “Network-Monitoring Tools,” December 2006, Instant- Doc ID 93841). We found that many tools in this space were monitoring email databases, Active Directory (AD), WANs, and even the environment. Now, let’s look at what matters most in a network-monitoring tool: After all, what you really want is to be able to study the content and characteristics of your network traffic, and you need to know which products will best help you achieve that goal.

Packet vs. Flow
Network-monitoring products split into two approaches: data monitoring and statistical monitoring. Data-monitoring products, or packet sniffers, examine the contents of individual packets, giving you the power to monitor the data traversing your network at a protocol level. For example, you can keep an eye on FTP, HTTP, and SNMP packets to reveal inappropriate usage involving those particular protocols. When you’re shopping for a packet sniffer, check out the granularity of the tool’s reach and get a feel for the types of information the tool can discern from the captured data.

Statistical monitoring, by contrast, examines the way data flows through the network. Patterns of network usage can not only show you traffic trends (e.g., peak usage, bottlenecks) and general network functionality but can also expose vulnerabilities and even ongoing attacks. Using statistical monitoring, you might see many packets bombarding your network at once, indicating some kind of internal misconfiguration or even a malicious attack. A packet sniffer might be blind to that kind of problem. With a traffic-flow monitoring solution, you can also identify the source and destination of network traffic. If you have Cisco components in your network, you’re going to need a product that supports Netflow. Watch for the inclusion of other popular embedded technologies, such as sFlow (an industry-standard mechanism for capturing traffic from switches and routers) and SNMP (an application-layer protocol for monitoring network-attached devices).

Perhaps you’ve considered dropping traditional packet capture and network analysis and going instead with a statistical monitoring infrastructure. After all, statistical-monitoring tools offer excellent visibility and perspective. However, they won’t replace the essential ability to capture and analyze the data flowing through your network.

Think of Netflow, sFlow, and SNMP as reporting technologies— not as troubleshooting technologies. Embedded in your monitoring infrastructure, these technologies are best used to get an idea of traffic flow, usage patterns, and highly used applications in the environment. But they don’t let you look at the data itself and perform serious troubleshooting. The best network-monitoring tactic uses both packet sniffing and statistical monitoring approaches.

Other Considerations
Most network-monitoring products offer some kind of network topology map, though some maps are more dynamic or granular than others. You might also require VoIP support (e.g., call quality, call drops) and Multi-Protocol Label Switching (MPLS) support, so that you can see data as it traverses the MPLS mesh and determine whether it’s running correctly and whether your provider is offering what it claims to be offering.

You’ll see increasing support for 10GbE bandwidth. Maybe you don’t need it today, but making the investment in that future 10GbE visibility is worth considering. Finally, retrospective analysis is gaining popularity in the market, letting you funnel data to a disk array and perform retrospective troubleshooting—a new mainstay of the industry.

Tool Evolution
Many problems affect network performance—hardware breakdowns, incorrect network configurations, viruses, users taking advantage of your resources inappropriately—and the monitoring tools that unearth those problems take various approaches. Tools in this space continue to evolve and incorporate existing and changing methodologies so that you can tackle as many causes as possible.

See associated table

End of Article



Reader Comments
firewall's like stonegate, pix and checkpoint do help also if IP Security is applied and routers are secured, third party softwares like DAEMON Tools also do help and play a big role in monitoring

PrinceKanago June 02, 2008 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Learning Path To Learn More About Network-Monitoring Tools
"Network-Monitoring Tools: Buyer's Guide"

"Top Networking Trends of 2008"

"Wireless Best Practices"


Top Viewed ArticlesView all articles
The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 24, 2008

An often irreverent look at some of the week's other news, including a Vista Capable dismissal request, Zune price reductions, Morrow musings, Novell and Microsoft sitting in a tree ... two years later, Yahoo!, IE 6 on Windows Mobile, and so much more ...


Related Articles VPN Firewalls for SMBs

NETIKUS.NET EventSentry 2.8

Enabling Netmon in Windows 2003

Essential Network Monitoring for the SMB, Part 1

Networking Whitepapers Managing Unix/Linux with Microsoft System Center Operations Manager 2007 Cross Platform Extensions Beta

Continuous Data Protection and Recovery for Microsoft Exchange

KVM Over IP For the Distributed IT Environment

Related Events SQL Server 2008 – Can You Wait? | Philadelphia

SQL Server 2008 – Can You Wait? | Atlanta

SQL Server 2008 – Can You Wait? | Chicago

Check out our list of Free Email Newsletters!

Networking eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

SQL Server Administration for Oracle DBAs

Related Networking Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing