Home > Ask the Networking Experts > Networking fundamentals with Chris Partsenidis Questions & Answers > What is a network sniffer?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

What is a network sniffer?

Chris Partsenidis EXPERT RESPONSE FROM: Chris Partsenidis

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 03 August 2005
What is a network sniffer? How can I understand broadcast and multicast packets that might be flooding the network?

>
EXPERT RESPONSE
A network sniffer is an administrator's 'best friend' and I'll explain why.

It's basically a program that allows you to 'sniff' (hence the term 'sniffer') data off your local network, examining packets that are running between your computers.

In addition, when your dealing with a problem in your network, a packet sniffer will 'show' you exactly what is happening on the network. From then on, with the appropriate level of knowledge, you'll be able to determine the source of the problem. Keep in mind that a packet sniffer won't tell you what the problem is, but only show you what's happening.

On another note, in the good old days where hubs were used to connect all networking devices in an office, sniffing the network was a pretty easy job. With today's switches, its somewhat more troublesome because of the way switches work – i.e. they do not replicate packets out of all ports (for more information you can check http://www.firewall.cx/hubs.php and http://www.firewall.cx/switches.php). This is also one reason I always carry a hub with me – I can plug it between the two end points I need to monitor and do my job without any problems!

While there are number of packet sniffers out there, you need to take a good look at a few and decide which one suits you best. Each sniffer has its positive and negative points, but it all depends on the job you want to do with it and how demanding you are from such a product.

In closing, you'll be able to find out if you've got a problem with broadcast and multicast packets if you simply run a sniffer on your network and observe the packets your receiving. Broadcast packets are easily identified as they contain "FF:FF:FF:FF:FF" as their destination MAC address or "255.255.255.255" as their destination IP address. Generally you'll see some traffic depending in the size of your network and the protocols/services your running.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Networking fundamentals with Chris Partsenidis
Do multiple router interfaces affect the amount of IP addresses?
How can I prevent collisions on my network?
What makes a WAN different from a LAN and MAN?
The difference between half-duplex and full-duplex
What is a logical network? How do you improve one?
How to retrieve passwords from locked laptops
What's the Ethernet packet collision rate in Windows OS?
What are a TV tower's effects on your network?
Differences between Internet Connection Sharing (ICS) and bridging
How do you design networks to allow for future growth?

Network Security Products
Securing the new network architecture
What security measures are recommended for each level of the TCP/IP model?
Securing the new network architecture: Security for distributed, dynamic networks
What is data loss prevention? -- An introduction to DLP
To simulate voice over IPSec VPNs which simulators work?
Is my firewall setting preventing wireless network guest access?
How to configure Windows Server 2008 advanced firewall MMC snap-in
How to retrieve passwords from locked laptops
How to interpret test scan results to assess network vulnerability
What commands allow network traffic to pass through PIX firewalls?

Network Performance
Application acceleration cements concrete co.'s consolidation project
Streaming Olympics video will drain corporate bandwidth
College IT department transforms itself with network management tools
How to prioritize wireless traffic
WAAS accelerates collaboration, increases revenue at engineering firm
Network management frameworks: FCAPS and ITIL
Governance, compliance, security: How are these network problems?
Network pros spend months on troubleshooting
Open source network monitoring reaches for the enterprise
Server virtualization and the network: Site consolidation's impact on latency

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Nessus  (SearchNetworking.com)
network analyzer  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
Visit KnowledgeStorm's comprehensive and easy to use business white paper directory.
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts