![]() |
Monitor network activity in real-time with the Visual Network Explorer (VNE) Automatic NetBIOS and DNS name resolution Monitor activity at remote WAN sites with integrated Cisco NetFlow Collector (v1, v5, v7, and v9) and sFlow Built-in protocol database identifies thousands of protocols Raw packet capture utility for low-level packet analysis in compatible client software (i.e. Ethereal, Wireshark) Instantly narrow activity views to specific hosts or protocols. |
One of the key features that Netmon provides is the real-time traffic sniffer. The network sniffer enables us to provide features like real-time reporting and the Visual Network Explorer (image above). The sniffer enables us to provide real-time insight into monitored networks.
Compared with traditional network management via Simple Network Management Protocol (SNMP), the real-time traffic sniffer has much more detailed and fine-grained output. Devices provide summarized data via SNMP, and are typically limited in what information can be provided. For example, a layer 2 network switch (the type typically used for network infrastructure) can not provide detailed information about TCP/IP connections passing through its interfaces, since it operates at a more basic level.
A network sniffer can examine the entire packet, including the ethernet frame, TCP/IP packet headers and payload. The sniffer does not require configuration on devices to be monitored; it inspects all network traffic regardless of source or destination.
These advantages come with some attendant disadvantages. Netmon and other traffic sniffers only operate on a local network segment. Traffic sniffing requires relatively high-end switches since the switch device must be capable of port spanning or port mirroring. Performance of the traffic sniffer can be negatively impacted by network throughput and system settings (such as the size of the Netmon database).
Netmon Software Edition [1], Professional Edition [2] and Enterprise Edition [3] all support both SNMP device management and traffic sniffing, along with other management protocols.
Links:
[1] http://www.netmon.ca/solutions/networkmonitoring/SE
[2] http://www.netmon.ca/solutions/networkmonitoring/PRO
[3] http://www.netmon.ca/solutions/networkmonitoring/ENT