Wednesday, January 07, 2009  
Google
Web pcquest.com

CIOL Network sites

Search by Issue | CD Search | Sitemap | Advanced Search

• Ad:Discover Green Intelligence, make your business strong • Ad :- Is your career a part of $12 Trillion global spend?
   
 Home > Infrastructure Mgmt Tools

Tools to Analyze your Network Traffic

Continued from page: 1

Tuesday, May 15, 2007

All in Ones: Wireshark
In 1997 a need for tracking down networking problems and a quest for knowing more about networking prompted Gerald Combs to start writing Ethereal, so as to fulfill both these needs. Since then lots of development has happened and now it has re-emerged under a new name called Wireshark. It is a piece of software that understands the structure of different network protocols, thus it's able to capture packets and interpret their meanings. Wireshark uses pcap to capture packets, hence restricting capturing of packets only to pcap supported networks. Some of the major features of Wireshark include its capability to capture packets not only from wired networks but also from wireless networks. Live data can be read and the captured file can be edited or converted using editcap program. It also has a display filter, which selectively highlights and colors packet summary information. This can be used to refine data display. It has the capability to dissect hundreds of protocols. It can be run on almost all OSs from Linux, Solaris, UNIX and Windows to MAC OS X.

Expert Analysis with Wireshark
In the interface of the Wireshark, go to the capture option. Select the correct interface option, which represents the desired network to be sniffed. Now, start capturing packets.

Once done with the capturing of packets, in the pop up window you will be able to see all packets captured for each protocol. After a while, stop packet capturing and in the Main window you can see all the details of each packet captured. The details include IP address, destination IP address, type of protocol used and information present in the packet header. Now to analyze data, from the Analyze option, select Expert info. This will list packets according to the security filters, i.e., errors, warnings, notes and chats. You can also specify the type of packets you want to filter, like errors only, errors and warnings etc. Select on any packet to check its detail in the Main window. You can notice the hexadecimal codes dump of the packets, as well as, details about the source ports, destination ports, MAC addresses of the packets etc.

Captured RTP Streams of a voice conversation

If you want to view the summary of any packet, which has information like protocol hierarchy, details of conversation which took place at the time of the capture, the IO graphs etc, you can go to the Statistics tab to get all of these. If you have captured a VOIP conversation, then you can go to the RTP option and select Show all streams. In the pop-up window, you will notice all the streams of the conversation and you can select the one which you want to hear.

Graphical analysis of VoIP Streams

To analyze the stream, choose Payload option and save the file in .au format. Once this is done, you can hear one side of the conversation, to hear the other part of the conversation, repeat the same steps with the other stream.

Page(s)   1  2  3  4  



Untitled 1


Does your business have Green Intelligence


Before you press ctrl+p, get innovative


   
 


 
 

Magazine Subscription | RQS | Contact Us | Team PCQuest