Re: Network Traffic Analyzer Recommendations?



Are you looking for a full-on IDS? If so, try Snort - its open-source,
free and infinitely configurable. You can run it on almost any platform
you like and there are excellent guides on setting it up available on
the net. For instance, if you want to run it on Windows, try
http://www.winsnort.com

Also available for use with snort are various plugins which enable you
to monitor activity on your LAN - BASE or ACID are graphical front-ends
for snort concentrating on intrusion detection - they should be able to
show you the info you need.

If you're just after a basic bandwidth monitoring tool, you could do
worse than using the built-in Windows performance monitoring tools -
there are ways of monitoring individual workstations (hint: use the
'select counters from computer' in your trace.

Alternatively, there are numerous reasonably cheap tools that will give
you what you want (and improve greatly on the rather rudimentary feel
of Performance Monitor) Some of these include NetFlow, EtherPeek and
Sniffer Pro (just google 'em)

Hope this helps!

.



Relevant Pages

  • RE: SNORT + Win32
    ... For monitoring I use BASE http://secureideas.sourceforge.net/ it is based on the ACID code but is so much nice and faster ... I'm using SNORT and Win32 - so far so good. ... Any unauthorized disclosure, dissemination, use or reproduction is strictly prohibited. ...
    (Focus-IDS)
  • Re: [perfmon] perfmon2 code review: 32-bit ABI on 64-bit OS
    ... As such a 32-bt monitoring tool could see 64-bit generated samples. ... which systematically adds a fixed size header to each sample. ... that maps to the current PID, another one that maps to the interrupt IP. ...
    (Linux-Kernel)
  • Re: Info HIDS
    ... Snort will provide the kind of monitoring you are asking about. ... be configured to monitor an entire network, and output logs in tcp dump, ... >configure an HIDS (tripwire) to get intrusion's information about a Web ...
    (Security-Basics)
  • Re: Accidently removed monitoring tool and cannot reinstall
    ... Microsoft Small Business Server Support ... I have a> hunch if I can successfully create a distribution group,> the monitoring tool will re-install successfully. ...
    (microsoft.public.windows.server.sbs)
  • Re: Snort Monitoring
    ... can you use SNMP? ... I would think you are looking at monitoring of alerts and not the snort ... Subject: Snort Monitoring ... He makes progress only when he sticks his neck out. ...
    (Focus-IDS)