 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Trenches &#187; Network TAPs</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/it-trenches/tag/network-taps/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/it-trenches</link>
	<description></description>
	<lastBuildDate>Fri, 19 Nov 2010 14:37:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Did you see this? &#8211; (Wire)Sharkfest 2008 videos &#8211; including Vint Cerf &#8211; now available</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-wiresharkfest-2008-videos-including-vint-cerf-now-available/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-wiresharkfest-2008-videos-including-vint-cerf-now-available/#comments</comments>
		<pubDate>Mon, 27 Oct 2008 20:52:55 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[analysis]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[IT education]]></category>
		<category><![CDATA[LAN]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[man-in-the-middle]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[network analysis]]></category>
		<category><![CDATA[Network TAPs]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[packet capture]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[performance monitoring]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[toolkit]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[troubleshooting]]></category>
		<category><![CDATA[WAN]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-wiresharkfest-2008-videos-including-vint-cerf-now-available/</guid>
		<description><![CDATA[Checkout the Sharkfest 2008 videos at LoveMyTool.com. If you use Wireshark or want to learn network troubleshooting, this is one of the best resources you can have in your toolkit. The videos will give you a better understanding of this tool and other tools out there. There is even a video of Dr. Vinton G. [...]]]></description>
				<content:encoded><![CDATA[<p>Checkout the <a href="http://www.lovemytool.com/blog/sharkfest.html" target="_blank">Sharkfest 2008 videos</a> at LoveMyTool.com. If you use Wireshark or want to learn network troubleshooting, this is one of the best resources you can have in your toolkit. The videos will give you a better understanding of this tool and other tools out there.</p>
<p>There is even a video of Dr. Vinton G. Cerf, vice president and Chief Internet Evangelist for Google. He is responsible for identifying new enabling technologies and applications on the Internet and other platforms for the company.  Widely known as a &#8220;Father of the Internet,&#8221; Vint is the co-designer with Robert Kahn of TCP/IP protocols and basic architecture of the Internet.</p>
<p>Have a great day and thanks for stopping by!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-wiresharkfest-2008-videos-including-vint-cerf-now-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Did you see this? &#8211; Laura Chappell&#8217;s Troubleshooting &amp; Security Summit</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-laura-chappells-troubleshooting-security-summit/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-laura-chappells-troubleshooting-security-summit/#comments</comments>
		<pubDate>Tue, 30 Sep 2008 13:34:12 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[awareness]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[LAN]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[network analysis]]></category>
		<category><![CDATA[Network TAPs]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[packet capture]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[performance monitoring]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[toolkit]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[troubleshooting]]></category>
		<category><![CDATA[WAN]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-laura-chappells-troubleshooting-security-summit/</guid>
		<description><![CDATA[Maybe you already know Laura Chappell (The Viral Bitgirl), if not then this is your chance to meet her and gain loads of knowledge in 2 days. On November 4-5, 2008 &#8211; Las Colinas, TX (near Dallas-Ft Worth airport) Laura will be holding a Troubleshooting and Security Summit. In two full days you will walk [...]]]></description>
				<content:encoded><![CDATA[<p>Maybe you already know Laura Chappell (<a href="http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-the-bitgirl/" target="_blank">The Viral Bitgirl</a>), if not then this is your chance to meet her and gain loads of knowledge in 2 days.</p>
<p>On November 4-5, 2008 &#8211; Las Colinas, TX (near Dallas-Ft Worth airport) Laura will be holding a Troubleshooting and Security Summit.</p>
<p>In two full days you will walk away with more security, optimization and troubleshooting knowledge than you&#8217;d get after spending months in the field figuring this out.</p>
<p>Learn the best practices and most efficient tools to use to analyze wired and wireless network performance to optimize and secure network communications from Laura Chappell, Founder of Wireshark University and Protocol Analysis Institute. See the Summit 08 special pricing and group discount information below. Register today at <a href="http://www.chappellsummit.com" target="_blank">www.chappellsummit.com</a>.</p>
<p>Key points include:<br />
* TCP Enhancements in Vista/Server 2008<br />
* Faster File Transfers with SMBv1 vs. SMBv2<br />
* Traffic Analysis between Virtualized Hosts<br />
* Proven Techniques to Baseline the Network<br />
* Latency Chokepoints<br />
* Automatic Traffic Capture and Analysis<br />
* Network Security and Forensics Procedures<br />
* Key Points to Deploying Decoys<br />
* Suspicious Traffic Signatures<br />
* Handling Traffic Evidence</p>
<p>Bring Your Own Laptop (BYOL) Format<br />
This hands-on lab-based course offers a series of demonstrations and individual hands-on labs to rapidly improve and expand your skill set. You will leave with your laptop loaded with tools, trace files and configured to improve network performance and security immediately after class.</p>
<p>GUEST SPEAKERS<br />
*Gerald Combs, Creator of Wireshark &#8211; Must-Know Steps to Analyzing Virtualized Communications and the Future of Wireshark</p>
<p>* Tom Quilty, Cybercrime Investigator for BD Consulting and Investigation &#8211; Preparing for and Handling a Data Breach or Theft</p>
<p>Register Today &#8211; Seating is Limited<br />
Register online at www.chappellsummit.com. Registration $1,295 &#8211; Early Bird $995 (ends midnight PDT Tuesday 9/30/08)</p>
<p>Group Discounts: Bring in two or more people from your company and receive $100 off each additional registration. Contact Brenda Czech at +1 408-378-7841 for more details.</p>
<p>Wireshark University Savings: Attendees receive the Wireshark University WSU03 Troubleshooting Network Communications self-paced course free with the student kits. Registered attendees also receive a 50%-off coupon on Wireshark University Self-Paced Courses.</p>
<p>Register today.<br />
<a href="http://www.chappellsummit.com" target="_blank">www.chappellsummit.com</a></p>
<p>If you go, please share some of the tips and tricks you gained with the ITKE population. Help spread the word!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-laura-chappells-troubleshooting-security-summit/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Researching Network TAPs &#8211; Strike 1 (part 4)</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/researching-network-taps-strike-1-part-4/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/researching-network-taps-strike-1-part-4/#comments</comments>
		<pubDate>Wed, 04 Jun 2008 19:26:43 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[LAN]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[network analysis]]></category>
		<category><![CDATA[Network TAPs]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[packet capture]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/researching-network-taps-strike-1-part-4/</guid>
		<description><![CDATA[Yesterday, I received my Datacom Systems Singlestream 102 network tap. I installed it during lunch and wouldn&#8217;t you know, something started not working right on the network! Hmmmmm&#8230; maybe I should have tested this before putting it on the live network&#8230;. well&#8230; lesson learned. You ask &#8220;What stopped working?&#8221; Let me tell you my friend&#8230; [...]]]></description>
				<content:encoded><![CDATA[<p>Yesterday, I received my <a href="http://www.datacomsystems.com/products/network-taps.asp" target="_blank">Datacom Systems Singlestream 102</a> network tap. I installed it during lunch and wouldn&#8217;t you know, something started not working right on the network! Hmmmmm&#8230; maybe I should have tested this before putting it on the live network&#8230;. well&#8230; lesson learned.</p>
<p>You ask &#8220;What stopped working?&#8221; Let me tell you my friend&#8230; everything stopped working! Well, actually, to the users it seemed that way. It was as if I had a bad cable between the LAN and the router. Users were reporting slow performance due to packet retransmissions  and the LAN switch and the router were taking errors on the internal ethernet ports. Not a good situation!</p>
<p>So, strike 1 on the SS102. I called Datacom technical support and found out they were closed after 5:30 PM EST. It was now 8:15 PM EST. I left a message with details of what I was seeing on the network.</p>
<p>The next day, around 9:00 AM I tried calling Datacom technical support but received a message that all office staff were in a mandatory company meeting. A short time after this, I received a return call from a very good support engineer. We discussed my application and how I went through troubleshooting the situation. His current suggestion is rather than set the router &amp; LAN switch ports to 100/full to set them to autosensing and ensure that portfast is enabled (this is a Cisco LAN switch). So, that is where I am now. I need to make a network maintenance window to make this change and try once again installing the Singlestream 102.</p>
<p>Stay tuned. More to come.</p>
<p>Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/researching-network-taps-strike-1-part-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Researching Network TAPs &#8211; an end to network blindness? (part 3)</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/researching-network-taps-an-end-to-network-blindness-part-3/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/researching-network-taps-an-end-to-network-blindness-part-3/#comments</comments>
		<pubDate>Tue, 06 May 2008 12:47:46 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[LAN]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Network TAPs]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[WAN]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/researching-network-taps-an-end-to-network-blindness-part-3/</guid>
		<description><![CDATA[I have now gotten back around to working on this activity. In case you have forgotten what I am working on, please review part 1 and part 2. I have ordered the Datacom Singlestream SS102 Link Aggregation Tap. I placed the order last Friday. On Monday, my supplier said that it could take more than [...]]]></description>
				<content:encoded><![CDATA[<p>I have now gotten back around to working on this activity. In case you have forgotten what I am working on, please review <a href="http://itknowledgeexchange.techtarget.com/it-trenches/hello-world/" target="_blank">part 1</a> and <a href="http://itknowledgeexchange.techtarget.com/it-trenches/researching-network-taps-an-end-to-network-blindness-part-2/" target="_blank">part 2</a>.</p>
<p>I have ordered the <a href="http://www.datacomsystemsinc.com/products/details.asp?prod=72&amp;itm=2&amp;cat=" target="_blank">Datacom Singlestream SS102 Link Aggregation Tap</a>. I placed the order last Friday. On Monday, my supplier said that it could take more than two weeks to receive this product. I was surprised by the lead time required for this device. I was first told that it could take 4 weeks for the product to ship. I am in more of a hurry than that and was about to change to a different higher-cost product to pressure the supplier to have a quicker delivery.  The conversation seemed to have worked.</p>
<p>My alternative choice was the <a href="http://www.networkinstruments.com/products/ntaps/aggregator.html" target="_blank">Network Instruments nTap</a>. However, it was almost a 50% premium over the Datacom solution. The link I need to monitor is not a high speed link so I really do not need the memory buffer that NI&#8217;s equipment offers. I was just willing to consider it if I could receive and implement the solution quicker.</p>
<p>I will let you know how the product works and any issues I encounter during implementation.</p>
<p>Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/researching-network-taps-an-end-to-network-blindness-part-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Researching Network TAPs &#8211; an end to network blindness? (part 2)</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/researching-network-taps-an-end-to-network-blindness-part-2/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/researching-network-taps-an-end-to-network-blindness-part-2/#comments</comments>
		<pubDate>Wed, 02 Apr 2008 18:22:33 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[LAN]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Network TAPs]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[WAN]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/researching-network-taps-an-end-to-network-blindness-part-2/</guid>
		<description><![CDATA[As expected there are several different manufacturers and models that can handle this task. The reseller I spoke with suggested three different devices from two different manufacturers. Network Instruments nTAP &#8211; This is the particular device that initially captured my interest in this type of solution. More information can be found here Datacom Systems Singlestream [...]]]></description>
				<content:encoded><![CDATA[<p>As expected there are several different manufacturers and models that can handle this task. The reseller I spoke with suggested three different devices from two different manufacturers.</p>
<p>Network Instruments nTAP &#8211; This is the particular device that initially captured my interest in this type of solution. More information can be found <a href="http://www.networkinstruments.com/products/ntaps/aggregator.html" target="_blank">here</a></p>
<p>Datacom Systems Singlestream aggregation tap &#8211; More information on the 10/100 aggregation tap can be found <a href="http://www.securicore.ca/taps/singlestream/" target="_blank">here</a>. Details on a gigabit tap can be found <a href="http://www.securicore.ca/taps/singlestream1000/">here</a>.</p>
<p>The prices I received on these devices went from around $1000 to $1500 to $2000. As you can see, there are lots of choices. I have requested a demo model of the $1000 device and will see if it will meet my needs. More to come!</p>
<p>Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/researching-network-taps-an-end-to-network-blindness-part-2/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Researching Network TAPs &#8211; an end to network blindness?</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/hello-world/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/hello-world/#comments</comments>
		<pubDate>Thu, 20 Mar 2008 18:09:48 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Network TAPs]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[WAN]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[What is the best means of watching data network traffic at the edge? My need: watch traffic inbound and outbound at the edge of the LAN and be able to remotely view reports. The reports would show information such as: current traffic flow volume &#38; conversations; historic traffic flow volume; netflow data; latency from LAN [...]]]></description>
				<content:encoded><![CDATA[<p>What is the best means of watching data network traffic at the edge? My need: watch traffic inbound and outbound at the edge of the LAN and be able to remotely view reports. The reports would show information such as: current traffic flow volume &amp; conversations; historic traffic flow volume; netflow data; latency from LAN to remote hosts.</p>
<p>So, some questions need to be asked and some answers given.</p>
<p>Where to place potential solutions:</p>
<ol>
<li>In the router or &#8220;cloud&#8221;.</li>
<li>In the edge LAN switch.</li>
<li>Between the router and the edge LAN switch.</li>
</ol>
<p>What are the potential issues with sensor location:</p>
<ol>
<li>Router or &#8220;cloud&#8221; &#8211; network address translation (NAT) may hide actual source address information. What load would this service put on the router? Would there be any costs for implementing this on the router and/or in the cloud? We use managed data network services so this could be a concern.</li>
<li>LAN edge switch &#8211; is port spanning or &#8220;mirroring&#8221; a valid option? What other monitoring services can the switch provide? SNMP or RMON? How would the monitor be remotely accessed if there is only one NIC and it is in listening mode only? Note that placing a destination switch port in span mode does not permit any outbound traffic to occur on that interface.</li>
<li>Between the LAN &amp; WAN &#8211; is another switch needed with port spanning/mirroring? Would a hub work with it creating a half-duplex link for inbound/outbound traffic?</li>
</ol>
<p>What hardware provides potential solutions:</p>
<ol>
<li>Router or &#8220;cloud&#8221; &#8211; not the preferred method since not under my control and may have change request or monthly service costs involved.</li>
<li>LAN edge switch &#8211; monitoring system would require dual NIC&#8217;s; one to listen/monitor and one for remote access. Port spanning or mirroring could place a load on the switch. SNMP or RMON queries can add traffic to the network link and impact the monitoring accuracy.</li>
<li>Between the LAN &amp; WAN &#8211; a hub is not desirable due to the fact mentioned above. It causes a full-duplex link to go to half-duplex and creates a bottleneck even though the WAN link is usually much smaller than the LAN. There is an alternative to the hub. That device appears to be called a network TAP or port aggregator. This is the solution I plan on investigating further.</li>
</ol>
<p>Has anyone else had experience with implementing a network TAP or port aggregator for network monitoring? I will also discuss what applications I plan on using to monitor network traffic in a future post.</p>
<p>Thanks for your time. Let&#8217;s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/hello-world/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
