Wednesday, February 18, 2009

Selecting a protocol analyzer

Consultants have used a protocol analyzer or "sniffer" to help identify the source of problems on our network. I have been thinking about adding a tool like this to our collection but wasn't sure which one to use?
-- via the Internet

Choosing a protocol analyzer is not something that you should jump right into. There are several good candidates out there. The three most popular ones that I know of are Sniffer from Sniffer Technologies (www.sniffer.com aka Network Associates), Etherpeek from www.wildpackets.com and Ethereal from www.ethereal.com. I used to recommend a fourth candidate from Novell but they seem to have stopped supporting their software based analyzer. I haven't seen any new protocol decodes released for several years.

The cost of these ranges from free (in the case of Ethereal) to more than $10,000 for a fully equipped Sniffer package from Network Associates. I encourage you to get an eval copy of the above mentioned sniffers and run them through their paces. Etherpeek and Ethereal can be downloaded while Sniffer will require you to fill out a form and someone will call you in a couple of days to follow up.

No comments:

Post a Comment