975 pts.
 Scanning network packets on Windows server 2003
We need to capture network packets for analysis on our Windows server 2003. How can we achieve this and is there a guide to analyzing this data?

Software/Hardware used:
ASKED: September 16, 2010  3:29 PM
UPDATED: September 16, 2010  9:58 PM

Answer Wiki:
<a href="http://www.wireshark.org/">Wireshark</a> can do that for you. The 'resources and documentation' section of the official site has many documents and videos that will help you get started. ================ from Labnuke99: The <a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=983b941d-06cb-4658-b7f6-3088333d062f&displaylang=en">Microsoft Network Monitor 3.4</a> is a tool from Microsoft and is another good packet capture/analysis tool for Windows networks. You can capture in Network Monitor and analyze in Wireshark or vice-versa. The reason I suggest Network Monitor is that there are parsers in the tool that might help you analyze specific Windows protocols. What in particular are you looking at capturing and analyzing? As far as a specific capture analysis guide goes, I would recommend <a href="http://itknowledgeexchange.techtarget.com/it-trenches/wireshark-book-coffee-a-quickie/">Laura Chappell's Wireshark Network Analysis</a> book. This will help you understand packet capture and analysis. Feel free to post additional detailed questions and we will be glad to help out.
Last Wiki Answer Submitted:  September 16, 2010  9:58 pm  by  Labnuke99   32,645 pts.
All Answer Wiki Contributors:  Labnuke99   32,645 pts. , carlosdl   63,535 pts.
To see all answers submitted to the Answer Wiki: View Answer History.


Discuss This Question:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _