Ethereal-users: [Ethereal-users] Information on Internet packet monitoring/analysis

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

Date: Tue, 6 Nov 2001 11:20:28 -0800

Hi,

I work with Sniffer Po and Microsoft Network Monitor sniffs.  I am also beginning to use Ethereal as well.  I think I like it alot better than Microsoft Network Monitor, but I am still experimenting.

Does anyone know of any books or internet sites that have good information on monitoring/analyzing internet traffic.  I can find lots of things on network (Lan/Wan) monitoring and analysis, but very little on monitoring/analyzing internet traffic.  I am definitely applying a number of things I am finding at this level to my work.  But the network monitoring/analysis resources that I can find do not seem to directly address a number of the types of issues that I am working with.  I am especially looking for things on what various anomylous patterns mean (i.e. many multiple acks to the same packet, abnormally large #s of resets, other unusual patterns, ...), information on using sniffer traces for latency analysis, and just general troubleshooting hints for analyzing breakdowns or slowdowns in communication between internet sites.  This would be very useful information which I could compare against and/or incorporate into the procedures we are already using/developing on our own.

Thanks in advance for any leads anyone can provide.

Jeanne