10.03.2013 Views

Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout

Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout

Sniffer Adaptive Application Analyzer: Adaptive Mode ... - NetScout

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

EARLY FIELD TRIAL Chapter 4<br />

78 <strong>Sniffer</strong> <strong>Adaptive</strong> <strong>Application</strong> <strong>Analyzer</strong><br />

Doubled Counts for Packets with Same Source and Destination<br />

Port<br />

The Statistics panel's Port tab includes a Packets column tabulating<br />

the number of packets seen with a particular port designation. When a<br />

packet has the same source and destination port, it will be counted in<br />

this column twice – once for the source port and once for the<br />

destination port.<br />

For example, a single packet with the source and destination port both<br />

set to 137 (a NetBIOS port) would be counted twice in the Packets<br />

column for the 137 port. This is the way that the IP Address, TCP/<br />

UDP Port, and MAC Address columns are all displayed, because there<br />

are two of each of these addresses per each applicable packet.<br />

As shown in the figure below, you can create a custom tab that will<br />

display a correct count of packets containing any or all of these index<br />

types (IP Address, TCP/UDP Port, MAC Address) by adding columns for<br />

both sides of the connection. This way, you can see the directionality of<br />

the exchange broken out. For example, in this case, you could create a<br />

custom tab that included:<br />

Port A<br />

Port B<br />

Packets TX<br />

Packets RX<br />

Packets<br />

Summary tab shows total of 111 packets<br />

accepted, but Port tab shows 118 packets on<br />

port 137 because of doubled counts for packets<br />

with same source and destination ports.<br />

Custom tab broken out for directionality shows<br />

the true packet count – 59 packets with the<br />

same source and destination port were counted<br />

twice to arrive at the 118 total.<br />

Figure 4-5. Interpreting Packets with the Same Source/Destination Port.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!