www.howtonetwork.org

CCNA & CCNP Certifcation Training

  • About
  • Contact
  • FAQ
  • Join
  • Home
  • CCNA
    • ICND1
    • ICND2
    • 101 CCNA LABS
  • CCNP
    • ROUTE
    • SWITCH
    • TSHOOT
    • 101 CCNP LABS
  • CompTIA
    • Security+
    • Network+
  • Design
    • CCDA
    • CCDP
You are here: Home / CompTIA / Network+ / Section IV: Network Management / Chapter 22: Hardware Troubleshooting Tools / Protocol Analyzers

Protocol Analyzers

A protocol analyzer is a powerful tool that gathers packets directly from the network and presents them for analysis. Protocol analyzers are generally used to troubleshoot application problems that require in-depth packet analysis. They can come in two forms:

  • Hardware appliances
  • Software tools

One of the most common software protocol analyzers is Wireshark, which is an open source application. Although working with such analyzers may be difficult at the beginning, they can provide a lot of information about the specific packet contents on the connection.

Hardware protocol analyzers can come in multiple forms, including stackable appliances that provide functionality similar to software analyzers but on a larger scale, as shown in Figure 22.8 below:

 22.8

Figure 22.8 – Hardware Protocol Analyzer

 

To use a protocol analyzer, you first have to capture the traffic and direct it to the analyzer device. This can be achieved in multiple ways:

  • Using port mirroring
  • Physical tap
  • Using a hub

Port mirroring is one of the most useful methods, as it does not require any physical modification to the network. It is a feature offered by many switches that clones traffic that passes through a switch port (source) to another switch port (destination). You can connect the protocol analyzer to the port mirroring destination port and capture all the packets that pass through the source interface.

The objective of this process is capturing as much information as possible and it can be filtered based on the desired criteria at a later time. As a best practice, you should document the packet capturing process with a clear time indication of each operation. The results of the packet capturing process can be saved as capture files, which can be reviewed at a later time.

Prev

Next

About Us

This is a free bonus site for members of www.howtonetwork.com

Copyright

The content on this copyright Reality Press Ltd.
Copyright Reality Press Ltd.