ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Server platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Protocol analysers are good for admin work

Ron Nutter

Published: 18 Apr 2002 16:14 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Protocol analysers now top out at around $1,000, and some are even free -- and they can all make the life of a network administrator much easier. I'm going to explain how you can use various protocol analysers on your network to perform such tasks as benchmarking, intrusion detection, and troubleshooting e-mail problems.

Finding network abnormalities

I have never used a protocol analyser for a byte-level analysis to resolve a problem. Instead, I usually use one to benchmark my network or to spot abnormalities when troubleshooting. For example, several years ago, I received a panicked phone call from a network administrator in a bank several hours away from the office where I worked. Its network was locking up every 10 to 15 minutes. I talked with the administrator for several minutes and had him make sure that other possible causes such as a bad electrical ground, faulty network cable, or a broken network card weren't the source of the problem.

After I arrived at the site, I ran the protocol analyser for a few minutes. It was then that I noticed something strange: Each workstation on the network was requesting the current date and time from the Novell server 20 to 30 times per minute. In normal conditions, this should happen only when the workstations boot up. A little investigation found that a third-party utility was being loaded that was supposed to get the current date and time about two or three times per day. After removing this utility from the workstations, the problem disappeared. Had I not been using a protocol analyser, my troubleshooting time would have been much longer.

Perform intrusion detection

Unfortunately, detecting intrusions is becoming more and more important as unwelcome visitors from the outside try to access and damage your network. This is another area where a protocol analyser can be handy. First, look for services that shouldn't be running on a particular server, such as FTP. It's a good practice to check for and disable such rogue services whenever new servers are added to your network and when service packs or updates are applied to existing servers.

You should also watch for people trying to do things that they shouldn't be doing on your servers. For example, say you have a server that allows you to use the Secure Shell utility for remote administration. Upon analysing the server, you find another user taking advantage of this open port (ssh or port 22). This allows you to immediately track down their source address and block that address from accessing your network. Another way to find intrusions is to look at login accounts that have been disabled or should have been disabled to see whether they are being used to access the network.

Next

Previous

1 2 3


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
210 out of 373 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:

















Related Jobs

UNIX Systems Administrator / Trading Floor Support Banking Sector, Consultancy, London City

Job Title: UNIX Systems Administrator / Trading Floor Support Banking Sector, Consultancy, London City Location: London (City) Salary: Competitive + ...

Solaris Systems Administrator West Midlands

A Solaris Systems Administrator is needed to support my clients major consolidation of their existing Network/Server infrastructure. This is a brand ...

System Administrator Linux Level 2 ( RedHat, Linux+, SQL ) West London

Job Title: System Administrator Linux Level 2 ( RedHat, Linux+, SQL ) Company Description: Rackspace Hosting is the worlds leading hosting company. ...