Relay-Version: version B 2.10 5/3/83; site utzoo.UUCP Path: utzoo!mnetor!uunet!seismo!mcvax!nikhefk!keeshu From: keeshu@nikhefk.UUCP (Kees Huyser) Newsgroups: comp.dcom.lans Subject: Re: ethernet analyzer Message-ID: <190@nikhefk.UUCP> Date: Wed, 19-Aug-87 09:20:02 EDT Article-I.D.: nikhefk.190 Posted: Wed Aug 19 09:20:02 1987 Date-Received: Sat, 22-Aug-87 01:45:32 EDT References: <310@intvax.UUCP> <362@rabbit1.UUCP> <904@dutesta.UUCP> Organization: National Institute for Nuclear Physics; Netherlands Lines: 188 Summary: here is a list with responses i got abt 3 months ago Since the questions about Ethernet analyzers pop up every few months or so here's the list of answers I got on a similar question I posted a few months ago. I hope it is of some help. -- Kees --------------------------------------------------------------- From: foster@seismo.uucp (Glen Foster) Organization: Computing Analysis Corp., Arlington, VA 3Com has a program called "EtherSpy" that may do some of what you want, it is similar to the MIT netwatch progam that allows you to look at individual packets on the cable. It has a few more bells and whistles than the MIT program, like assignment of logical names to particular addresses, some protocol dependent decoding capabilities (3Com's protocols, of course), etc. Run it on an AT, it drops too many packets on a PC. The program is ``unsupported'' by 3Com but your local 3Com support office can probably get you a copy (especially if they sense a potential sale). I was not charged for mine, I'll have to check for distribution rights, if it's ok and you can't get it from 3Com, I'll send you a copy. The MIT PCIP netwatch program provides somewhat more limited functionality but is completely free of charge and works adequately. Neither of these could be described as "protocol analyzers" but could be useful, especially in a development environment. I will be interested in what you learn. Glen Foster --------------------------------------------------------------------- From: ncrwic!jmatrow@ncr-sd.uucp Organization: NCR Corporation, Wichita, Kansas The LANalyzer from Excelan would be worth investigating. ----- John Matrow Automation Engineering, NCR E&M Wichita {sdcvax,cbatt,dcdwest,nosc.ARPA,ihnp4}!ncr-sd!ncrwic!john.matrow ---------------------------------------------------------------------- From: rmarks@bbking.PRC.Unisys.COM Organization: Unisys/Knowledge Systems Organization, Bluebell, PA Excellan has a good board and software. It has an onboard processor with 1 meg memory. The display software is a little weak but I am told it has been improved since I used it six months ago. Cost is $10,000 with quantity discounts available. Richard Marks 215-542-2139 ---------------------------------------------------------------------- From: normt@ihlpa.uucp Although this is not quite the arrangement you want, Excelan Inc. has a "LANalyzer EX 5000E" which does this real well. It is a PC board with an Ethernet controller, 80186 co-processor, and 2Meg of memory. The software is a real nice menu driven package, which allows you to set up various virtual receive channels and monitor (i.e. time averages, totals of everything, statisical figures) for any or all of these channels, plus you can optionally store and buffer to memory or disk any or all of the received packets. There is also limited capability for transmitting packets. 5 different packets can be stored and then transmitted on a time or at some time interval or to produce a certain load characteristic. (i.e. 10, 20, 50% ... load on network). We have been using it for about a year now to analyze our network of 10-12 microprocessors, and have found NO bugs or problems. This isn't quite what you want, since you are looking for a software package to sit on an already existing interface, but it really does the trick. I don't believe there is any way to use this without the hardware supplied, it is just to dependant on the arrangement. If you want more information or the address of Excelan (in the US) send me mail and I'll get the info to you. Norm Tiedemann (312) 979-3535 AT&T Bell Labs Naperville, IL 60566 mcvax!seismo!ihnp4!ihlpa!normt ---------------------------------------------------------------------- From: csib!jwhitnel@csi.uucp (Jerry Whitnell) Organization: Communications Solutions Inc., San Jose, Ca Network General makes a product called the Sniffer that can be used to monitor traffic on Ethernet. The Sniffer monitors and stores data packets which can be displayed for further investigation. There is some statistics in the product but it is primarily for debugging network applications. You can reach them at: Network General Corp 1296B Lawerence Station Road Sunnyvale, CA USA 94089 (408) 734-0464 I've used the Token Ring version of the Sniffer (there is also a combined Ethernet/Token Ring) and consider it very well done. I also know both the founders, but have no other connection (finacial or otherwise) with them. BTW, they also have a demo of the Token Ring product, so they should have one for the Ethernet. Be sure to ask about it. Jerry Whitnell Communications Solutions, Inc. ---------------------------------------------------------------------- From: dave@rosevax.rosemount.com (Dave Marquardt) Organization: Rosemount Inc., Eden Prairie, MN Well, with either the MIT or CMU PC/IP packages, you get a program called "netwatch". This program watches every packet going by, and displays them by type, source address, destination address, etc. It also keeps statistics on how many of which type of packets are going by. I don't think it's quite what you'd want, but it might be useful. Dave -- Dave Marquardt dave@rosevax.Rosemount.COM {cbosgd,ihnp4,uiucdcs}!rosevax!dave ---------------------------------------------------------------------- From: Andy Linton Organization: Computing Laboratory, U of Newcastle upon Tyne, UK NE17RU If you use the 3Com board and MIT's PC/IP software there is an Ether monitor program bundled in with that software. It may work with the Micom board - I don't know. Other PC/IP type implementations may have similar programs. -- SENDER : Andy Linton PHONE : +44 91 232 9233 ARPA : andy%cheviot.newcastle.ac.uk@cs.ucl.ac.uk JANET : andy@uk.ac.newcastle.cheviot UUCP : andy@cheviot.UUCP ---------------------------------------------------------------------- From: robert@acad.uucp (Robert Wenig ext 609) Organization: Autodesk, Sausalito, CA 3COM has a product called ETHER-PROBE which can monitor all types of ethernet activity including XNS, TCP-IP, etc. ---------------------------------------------------------------------- From: fair@ucbarpa.Berkeley.EDU (Erik E. Fair) Organization: USENET Protocol Police, Western Gateway Division Give FTP Software in Cambridge, MA, USA a yell (they can be reached through romkey@xx.lcs.mit.edu on the ARPANET); they have an ethernet monitoring program that runs under MS/DOS with a wide variety of PC ethernet interfaces. Erik E. Fair ucbvax!fair fair@ucbarpa.berkeley.edu ---------------------------------------------------------------------- From: Susan Pollack We saw you request on the net. Network Research Corp. has developed a networking product which runs on various computers from PCs (MS-DOS and Xenix) to large DEC hosts (VMS). We have both XNS and TCP implementations. Our PC products run on the 3Com 3C501, 3C505 and Micom 5010 boards. Our basic packages includes telnet and ftp functions. In addition, we offer a substantial library package and a network monitoring package. I believe this package, running on top of our standard FUSION Network Software standard package will provide you with the features you were asking for. We offer network statistics, network test and packet monitoring capabilities. Please let me know where we can send additional information about our product. ------ Susan R. Pollack USENET- ...ihnp4!nrcvax!susan ...{sdcsvax|hplabs}!sdcrdcf!psivax!nrcvax!susan ARPA ihnp4!nrcvax!susan@BERKELEY.EDU.ARPA U.S. Mail Network Research Corporation 2380 N. Rose Ave., Oxnard, CA 93030 Telephone 805-485-2700 (outside CA 800-541-9508) ---------------------------------------------------------------------- -------------------------------------------------------