Sniffer Network Analyser ®

Seven-layer analysis quickly pinpoints problems and recommends solutions

Overview

Network General's Sniffer Network Analyser is a fault and performance management solution that enables network professionals to maintain, troubleshoot, fine-tune, and expand multi-topology, multi-protocol networks.

By incorporating the expert analysis capabilities and advanced protocol decodes of Network General's own Experience Technology, the Sniffer Network Analyser is able to determine, pinpoint, and analyse performance problems -- automatically recommending a course of corrective action and greatly simplifying the process of finding and resolving network performance issues.

 

How It Works

The Sniffer Network Analyser's job is simple: keep the network running at peak performance levels.

The analyser captures frames, simultaneously building a database of network objects from the observed traffic and using this knowledge to detect network anomalies. An anomaly is categorised as a symptom (a non-critical event such as a single file retransmission or a physical error) or a diagnosis (a critical fault requiring prompt investigation and correction, i.e. a frequently repeated symptom, such as excessive file retransmissions, or a single instance of a major network problem such as a duplicate network address).

After isolating, analysing and categorising the problem, the Sniffer Analyser alerts you, explains the problem, and recommends corrective action - all automatically and in real time.

With Fast Ethernet Snffer Network Analysers placed strategically on your network, you have visibility into both 10/100 Mbps segments.

 

Datasheet

Expert Analysis

The superior expert analysis capabilities of Experience Technology are built into the Sniffer Network Analyser, giving you greater depth of visibility, management automation, and problem-solving information.

Automatic visibility. The Sniffer Network Analyser "sees" into all seven layers of the network model. Regardless of where or when they occur, problems are pinpointed and analysed, and solutions are recommended, automatically.

Automatic analysis and alarms. The Sniffer Network Analyser automates most fault and performance management functions. Configurations are learned automatically and in real time. Performance problems are detected and pinpointed, and alarms are forwarded with event details - automatically. Expert analysis is performed and solutions are offered automatically. Expert analysis can even be scheduled for automatic collection and display.

Automatic problem-solving. Bottlenecks, protocol violations, even problems like duplicate addresses and misconfigured routers are identified automatically - often before they have a chance to impact network performance.

Automatic reporting. For network performance optimisation, expert analysis information can automatically be collected, stored, and then imported to a spreadsheet, database, or Network General's Reporter application.

With Experience Technology built into the Sniffer Network Analyser, performance problems are detected, identified, and analysed. The analyser tells you there's a problem, tells you what it is, tells you why it happened, and then provides experience-based suggestions for correcting it, all automatically.

 

Network Monitoring

Monitoring is an ideal way to keep constant tabs on the network, detect anomalies, and keep a record of network performance. The Sniffer Network Analyser collects current and historical segment statistics which can be displayed in real time for an instant snapshot of network activity, stored for later display, or transferred to database, spreadsheet, or management reporting programs such as Network General's Reporter. The system also comes with a variety of pre-designed management-quality reports for displaying statistical information in easy-to-read formats. Network Monitoring is not available on the Sniffer Internetwork Analyser.

 

Network Statistics

  • Utilisation % (current and average)
  • Frames monitored (current and total)
  • Bytes (current and total)
  • Average frame size (current and total)
  • Number of stations (total and active)
  • Ring state (token ring)
  • Inserted stations (token ring, current, and max)

Error Statistics

  • Number of runt errors (Ethernet and Fast Ethernet)
  • Number of CRC/alignment errors (Ethernet and Fast Ethernet)
  • Number of collisions (Ethernet and Fast Ethernet)
  • Total frame errors (Ethernet and Fast Ethernet)
  • Oversized frames (token ring)
  • Ring purges (token ring)
  • Soft error reports (token ring)

Protocol (Ethertype and SAP) Statistics

  • Network utilisation % by protocol
  • Number of frames by protocol
  • Number of bytes by protocol

Frame Size Statistics

  • % of frames by frame size
  • Number of frames by frame size

Station Statistics (for each active station up to 1,024 stations)

  • Traffic (received and transmitted)
  • Combined (received and transmitted)
  • Utilisation % (average and current)
  • Total frames in sample
  • Start, End, Elapsed time
  • Station status (token ring)
  • Start time (first frame seen)
  • End time (last frame seen)
  • Elapsed time
  • Station status (token ring)
  • Average network utilisation %

 

Traffic History

Traffic history is tracked for the entire network at adjustable intervals from 5 seconds to 24 hours and can be automatically logged to disk.

Parameters

  • Timestamp
  • Number of frames
  • Number of errors
  • Number of bytes
  • Average frame size
  • Network utilisation

Routing Information (token ring)

Route Path Length

  • Routed frame distribution by length
  • Number of frames by route length

Route Path

  • % and number of frames by route type
  • To/from local ring
  • To/from remote rings
  • To/from broadcast/other addresses

Alarms

Alarms can be set network-wide as well as individually for each station. Alarm actions may be any combination of logged to printer, logged to disk, or audible.

Network Alarms

  • Intruder alarm
  • Rate of error threshold
  • Network idle time threshold
  • Network utilisation % threshold
  • Rate of broadcast frames threshold
  • Oversize frame alarm
  • Collision % threshold (Ethernet and Fast Ethernet)

 

Protocol Interpretation

To solve complex problems you often need details on data packets. The Sniffer Network Analyser provides the most extensive -- and savvy -- collection of decodes available anywhere.

More than 250 protocols at all network layers are interpreted for you, not in cryptic "spec-speak", but with the contents of each frame explained in plain English. And, unlike other protocol guides, our decodes recognize "protocol-creep" to provide you with the latest information, even when it has evolved beyond the technical specifications.

Additionally, sophisticated filters allow you to pre-capture and display relevant packets only, for maximum convenience. Flexible windowing allows you to display traffic in three formats - Summary, Detail and Hex - simultaneously, while multiple viewports present up to six windows at the same time. A traffic generator function also allows you to load captured and altered packets onto the network for stress testing.

With the largest, smartest collection of decodes available including WWW decode and monitoring capabilities, the Sniffer Network Analyser is a powerful tool for viewing, and really understanding, the details of network performance.

For a detailed look at frame packets, the protocol interpretation function provides progressive levels of detail about packets and protocols. Shown here, HTTP analysis enables network managers to monitor and troubleshoot World Wide Web activity.

 

How It Helps

 

The Sniffer Network Analyser -- the industry-standard analysis tool for network fault and performance management -- covers your network with more analysis, more protocol interpretation, more automation, and more visibility than any other solution. This has several practical advantages:

Speedy resolution. With automatic problem identification, analysis, and solution recommendation, you can radically streamline the time spent troubleshooting.

Maximise investments. With precise information about performance degradation, you can avoid the mistake of simply throwing money at a problem. You can plan wisely.

Quality of service. Forewarnings are automatically sent to you before performance is impacted, allowing you to proactively manage your network, keep end-users productive, and meet service-level goals.

Increase Productivity. By learning network configuration automatically and continuously, the Sniffer Network Analyser reduces time you spend on routine maintenance which increases efficiency and productivity.

 

In Action: Sniffer Network Analyser

 

A user complains that "the network is slow." Opening the Sniffer Network Analyser, you do a traffic-capture for that user's segment. Experience Technology, built into the Sniffer Network Analyser, identifies the problem (user is being routed unnecessarily through the router, which is loading up the network and decreasing router efficiency) and recommends the solution (reconfigure the router). Intelligent, actionable information lets you solve the problem and maintain service-level agreements.

Experience Technology immediately and automatically analyses the problem and recommends a specific course of corrective action.

 

Solving Problems with the Sniffer Network Analyser

By providing in-depth seven-layer analysis on all covered segments, the Sniffer Network Analyser helps you maintain service-level agreements and minimise some of the most common challenges to network performance.

Easing Deployment of New Applications/Technologies. By using the Sniffer Network Analyser on a pilot network before production deployment, you can analyse the impact of new applications or technologies. The analyser will show the effect on segment performance and provide advice on where and how to make improvements. For further fine-tuning, use Network General's Reporter application to graph historical data collected from the Sniffer Network Analyser and perform trend analyses.

Minimising Downtime. By providing visibility into every layer of network traffic, the Sniffer Network Analyser quickly locates problems and determines causes. Experience Technology provides the protocol decodes and expert analysis to help you determine the source - and solution - of the problem. And the monitoring and anomaly-alarm functions of the Sniffer Network Analyser help you spot potential problem areas before network performance is impacted.

Improving Response Time. Slow network response has a variety of causes. By automatically assessing and analysing the symptoms, the Sniffer Network Analyser helps you swiftly investigate the problem and move directly into corrective action. And when this information is combined with Network General's Reporter, you can chart historical data to analyse trends and justify investments in additional resources.

Leveraging Resources. To help you maximise your investment, Network General offers a wide range of support, consulting, and educational services.

Our Sniffer University conducts network management and analysis classes (including a Sniffer Network Analyser class) - either at our facilities or your site - at introductory, intermediate, advanced, and expert levels.

To ensure that your network stays up and running, our PrimeSupport programs offer a variety of standard and priority services, including round-the-clock technical support, software updates, rapid spares, and more.

And to assist with your troubleshooting, analysis, planning, and optimisation requirements, Network General Consulting Services provides hands-on expertise delivered by a Certified Network Expert.

 

Experience Technology - Built In

Network General® has taken years of networking experience and literally built this expertise into the Sniffer Network Analyser. The hands-on knowledge and practical experience of top professionals in the networking industry-built in. The inside knowledge culled from working partnerships with key network hardware suppliers-built in. The information and insights gained through our 10-year investment in internal research and development-built in.

All this adds up to a unique value-added component called Experience Technology.

Through Experience Technology, Network General is able to offer more than 250 protocol decodes, along with extensive expert analysis capabilities to help you identify and solve performance problems. In fact, no other company offers more decodes, more analysis, and more network problem-solving automation than Network General.

 

Additional Features

Capture Filters

When collecting frames off the network, it is useful to be able to specify certain types of frames to be captured. The Sniffer Network Analyser allows you to do this with the following capture filters:

  • Protocol (Ethertype or 802.2 LLC SAP)
  • Pattern match (8 pattern combination)
  • Good frames (Ethernet and Fast Ethernet)
  • Error frames (bad CRC, short frames, collisions) (Ethernet and Fast Ethernet)
  • IP address
  • DLC address

Display Filters

Tracking down certain network communications helps to pinpoint network problems and trends. The following display filters enable you to view only the frames that apply to the issue you are trying to resolve:

  • Address level
  • Destination class
  • Station address
  • Protocol (seven layer)
  • Pattern match (8 pattern combinations)
  • Good frames (Ethernet and Fast Ethernet)
  • Error frames (bad CRC, short frames, collisions) (Ethernet and Fast Ethernet)
  • Address level and destination class

 

Triggers

You can establish triggers that will recognise specific incidences on your network and save the capture information to the hard disk automatically. These triggers may be set to recognise:

  • Good frames (Ethernet and Fast Ethernet)
  • Error frames (bad CRC, short frames, collisions) (Ethernet and Fast Ethernet)
  • Pattern match (8 pattern combinations)

 

Traffic Generation

A traffic generation capability is built into the analyser for testing new applications or devices. With this feature, you can load the network with the same frame repeatedly or the custom-edited contents of the capture buffer.

Client/Server Databases:
The Sniffer Network Analyser is available with an optional Oracle7 or Sybase/Microsoft SQL Server Database Module for managing client/server database applications. With visibility inside Oracle TNS and Sybase/Microsoft SQL Server TDS protocols, you've got a clear view of the performance relationship between the database application and the network. This avoids the mutual finger-pointing between network and database administrators, and enables you to quickly troubleshoot and efficiently fine-tune the performance of your client/server database applications.

 

 

First and Foremost

The Sniffer Network Analyser was the first product to provide fully functional, automatic, real-time expert analysis of network performance problems. Now the industry standard, this technology is the preferred choice for over 80% of Fortune 500 companies, and a regular award-winner in the industry press.

Request further information | Return to home page