Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout

Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout

10.03.2013 Views

EARLY FIELD TRIAL Chapter 1 Using Traditional Packet Capture 18 Sniffer Adaptive Application Analyzer In addition to the new Adaptive capture mode, the Expert analysis and raw packet decodes traditionally available in Sniffer products are also available in Sniffer Adaptive Application Analyzer. You can change the capture mode by clicking the Configure Capture button in the Capture toolbar and setting Capture Type to Raw instead of Adaptive (the default; Figure 1-4). Select the Capture Mode in the Configure Capture dialog box. Figure 1-4. Setting the Capture Mode Protocols Supported for Sniffer Adaptive Processing Sniffer Adaptive Application Analyzer supports the following protocols for adaptive processing, storing ASPs with derived payloads. For all other protocols, you have the choice of capturing full packets, sliced packets, or filtering them out entirely. HTTP FTP DNS SMTP POP3 RTP RTCP SIP Cisco Skinny

EARLY FIELD TRIAL Sample Trace Files What’s Different? Sniffer Adaptive Application Analyzer Overview Sniffer Adaptive Application Analyzer is provided with several sets of sample trace files in the \Netscout\Sniffer Adaptive Application Analyzer\traces folder. Each set contains both a raw packet capture (.cap) file and the corresponding Adaptive Traces (.asp/.asr) generated by replaying the capture file. Each raw packet capture file contains flows using the protocols supported for ASI processing listed above. This way, you can compare the raw packet file and its corresponding Adaptive Session files to understand how the ASI technology works. In particular, you can see how Adaptive Intelligence stores key elements of supported protocols. For example, the key elements captured for a HTTP flow are Host and URL details, while for a RTP flow, the Caller and Callee Media Addresses are stored. The sample trace files also demonstrate the compression achieved by Adaptive processing – you can see at a glance the size differences between the raw and Adaptive traces. Sniffer Adaptive Application Analyzer’s Adaptive mode combines a modified version of the InfiniStream Console user interface with the local network interface and packet buffer familiar to users of Sniffer Portable Professional and Sniffer Global Application. This section summarizes some of the differences users of those products will notice as they work with Sniffer Adaptive Application Analyzer in Adaptive mode. Key Differences for InfiniStream Console Users Users accustomed to working with the InfiniStream Console will notice some key differences in Sniffer Adaptive Application Analyzer. Most of the differences are due to the differences in how capture/monitoring takes place – rather than operating as a unified Console with connections to multiple persistent stream-to-disk interfaces on remote InfiniStream appliances, Sniffer Adaptive Application Analyzer uses a single local Ethernet interface capturing data to a local buffer. Key differences between Sniffer Adaptive Application Analyzer and the InfiniStream Console summarized below: User’s Guide 19

EARLY FIELD TRIAL<br />

Sample Trace Files<br />

What’s Different?<br />

<strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> Overview<br />

<strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> is provided with several sets of<br />

sample trace files in the \Netscout\<strong>Sniffer</strong> <strong>Adaptive</strong><br />

<strong>Application</strong> <strong>Analyzer</strong>\traces folder. Each set contains both a raw packet<br />

capture (.cap) file and the corresponding <strong>Adaptive</strong> Traces (.asp/.asr)<br />

generated by replaying the capture file.<br />

Each raw packet capture file contains flows using the protocols<br />

supported for ASI processing listed above. This way, you can compare<br />

the raw packet file and its corresponding <strong>Adaptive</strong> Session files to<br />

understand how the ASI technology works.<br />

In particular, you can see how <strong>Adaptive</strong> Intelligence stores key elements<br />

of supported protocols. For example, the key elements captured for a<br />

HTTP flow are Host and URL details, while for a RTP flow, the Caller and<br />

Callee Media Addresses are stored. The sample trace files also<br />

demonstrate the compression achieved by <strong>Adaptive</strong> processing – you<br />

can see at a glance the size differences between the raw and <strong>Adaptive</strong><br />

traces.<br />

<strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong>’s <strong>Adaptive</strong> mode combines a<br />

modified version of the InfiniStream Console user interface with the local<br />

network interface and packet buffer familiar to users of <strong>Sniffer</strong> Portable<br />

Professional and <strong>Sniffer</strong> Global <strong>Application</strong>. This section summarizes<br />

some of the differences users of those products will notice as they work<br />

with <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> in <strong>Adaptive</strong> mode.<br />

Key Differences for InfiniStream Console Users<br />

Users accustomed to working with the InfiniStream Console will notice<br />

some key differences in <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong>. Most of<br />

the differences are due to the differences in how capture/monitoring<br />

takes place – rather than operating as a unified Console with<br />

connections to multiple persistent stream-to-disk interfaces on remote<br />

InfiniStream appliances, <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> uses a<br />

single local Ethernet interface capturing data to a local buffer.<br />

Key differences between <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong> and the<br />

InfiniStream Console summarized below:<br />

User’s Guide 19

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!