Link to home
Create AccountLog in
Avatar of jmergulhao
jmergulhaoFlag for Canada

asked on

Packet Sniffer/Network Analyzer

Can anyone recommend a very good Commercial Sniffer/Analyzer that works well on a Switched Network...

It should be able to :

1. Collect all traffic from various switched and routed networks onto a central consolse..
2. Alert triggers
3. Network Analyzer

ETC ETC ETC...

Any guidance in the correct direction greatly appreciated..

Cheers

John
SOLUTION
Avatar of zephyr_hex (Megan)
zephyr_hex (Megan)
Flag of United States of America image

Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
See answer
Avatar of jhance
jhance

How either of these are going to sniff through a switch is beyond me...
SOLUTION
Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
Avatar of giltjr
All network packet capturing tools work the same on switched networks.  If the switches are managed and allow for port mirroring, the work well.  If the switches are unmanaged, they won't see a thing but the traffic on the port they are connected to, unless of course you have taps.

For simple things I use Ethereal, jabiii already posted the link

For complex or doing tracing for more that a few minutes things I use Network Observer Suite (http://www.networkobserver.com).
1) 'Collect all traffic from various switched and routed networks onto a central consolse.'
It's possible only if your switch supports  port 'tapping', but it works for  switched port only (not for all).
Cisco Catalists supports such feature.
2) Alert triggers.
Triggers on what? On amount of traffic data? On collision errors? On some malicios network patterns?
3) Network analyzer. Read previuos post of 'giltjr'
SOLUTION
Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
ASKER CERTIFIED SOLUTION
Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
Helped? Problem solved ?

Cheers,
SOLUTION
Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
jhance,
port spanning/mirroring what ever you like to call it, where 1 port can basically see all other ports or specific other ports on a managed switch. unmanaged your hosed, use a hub :p

probably best to stick the sniffer between your switches and routers so it catches all traffic between network segments.
Avatar of jmergulhao

ASKER

Thanks for all your advice and solutions

Cheers

John