Sniffer® Portable Professional User's Guide - NetScout

Sniffer® Portable Professional User's Guide - NetScout Sniffer® Portable Professional User's Guide - NetScout

10.03.2013 Views

Chapter 1 Major Components of Sniffer Portable Professional 14 Sniffer Portable Professional The major components of Sniffer Portable Professional include: Monitor. Calculates and displays real-time network traffic data. Capture. Captures network traffic and stores the actual packets in a buffer (and optionally to a file) for later analysis. Real-time and Postcapture Expert. Analyzes the network packets during capture and alerts you to potential problems on your network. These problems are categorized as either symptoms and/or diagnoses. Expert analysis is also available postcapture. Real-time and Postcapture Decode. Displays protocol decodes in real-time as packets arrive. You do not have to stop a capture session to see protocol decodes. Decodes are also available postcapture. Display. User-interface that provides decodes and analysis of the captured packets in a variety of easy to view and navigate windows.

Introducing Sniffer Portable Professional Sniffer Portable Professional Features for Wireless Networks Sniffer Portable Professional includes many features specifically for 802.11 wireless networks, as summarized in Table 1-2. Table 1-2. Features for Wireless Networks Feature See this topic: Different wireless LAN frame type counters are included in the Dashboard. The Monitor's Host Table includes an 802.11 tab with entries for all detected wireless stations. Each station is listed with several wireless LAN-specific counters. The Monitor’s Host Table includes a zoomed view for Access Points only. Rogue identication is included in both Host Table and Expert displays. The Monitor's Global Statistics application includes a Topology Surfing tab with statistics for each wireless channel selected for monitoring. The Matrix, Host Table, and Protocol Distribution post-analysis tabs in the Display window each include 802.11 views, allowing you to focus specifically on 802.11 statistics for wireless stations. The postcapture Statistics tab in the Display window includes multiple wireless-specific statistics. The Advanced tab in the Define Filter dialog box includes wireless LAN packet types on which you can filter (such as PLCP Errors and WEP-ICV Errors). The 802.11 tab in the Define Filter dialog box allows you to filter on packets seen on a channel to which they do not belong, packets matching different speeds, or packets seen on a particular channel. Sniffer Portable Professional can perform both WPA/WPA2 and WEP decryption both during capture if the keys are specified in the Tools > Wireless > Decryption dialog box and after capture using the Wireless Decryption option in the Decode tab's context menu. Dashboard Counters for Wireless Networks on page 75 Host Table Counters for Wireless Networks on page 85 Viewing Access Points Only on page 88 Identifying Rogue Hosts on the Wireless Network on page 91 The Global Statistics > Topology Surfing Tab on page 117 Monitor Applications and Toolbar on page 71 Postcapture Statistics Tab on page 210 Setting Filter Options in the Advanced Tab on page 235 Setting Filter Options in the 802.11 Tab on page 238 • Configuring Wireless Encryption Settings on page 56 • Postcapture 802.11 Decryption on page 199 User’s Guide 15

Chapter 1<br />

Major Components of Sniffer <strong>Portable</strong><br />

<strong>Professional</strong><br />

14 Sniffer <strong>Portable</strong> <strong>Professional</strong><br />

The major components of Sniffer <strong>Portable</strong> <strong>Professional</strong> include:<br />

Monitor. Calculates and displays real-time network traffic data.<br />

Capture. Captures network traffic and stores the actual packets in<br />

a buffer (and optionally to a file) for later analysis.<br />

Real-time and Postcapture Expert. Analyzes the network<br />

packets during capture and alerts you to potential problems on<br />

your network. These problems are categorized as either symptoms<br />

and/or diagnoses. Expert analysis is also available postcapture.<br />

Real-time and Postcapture Decode. Displays protocol decodes<br />

in real-time as packets arrive. You do not have to stop a capture<br />

session to see protocol decodes. Decodes are also available<br />

postcapture.<br />

Display. User-interface that provides decodes and analysis of the<br />

captured packets in a variety of easy to view and navigate<br />

windows.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!