efficient and effective Problem resolution
Advanced Network Analysis and MonitoringNetwork and Security Forensics Retrospective Network Analysis
Aggregate Reporting Network and Route Mapping
Supporting Full-Duplex Gigabit, 10 Gb, WAN, Fibre Channel, LAN, and WLAN
Network Instruments, LLC is the industry-leading developer of distributed, user-friendly and affordable network management, analysis and troubleshooting solutions. The award-winning Observer family of products combines a comprehensive management and analysis console with high-performance probes and network TAPs to provide integrated monitoring and management for the entire network (LAN, wireless, gigabit, WAN, Fibre Channel, and 10 Gb).
Network Instruments’ software-based and hardware-based solutions are used by thousands of major corporations, including Intel, IBM, U.S. Navy, NASA, Motorola, Microsoft, Bayer, Daimler/Chrysler, Boise Cascade, FAA, USPS, Toshiba, Xerox, Boeing, ESPN, Norfolk Southern, BBC, Warner Bros., United Way, BMW, Burger King, and many more.
Corporate Headquarters Network Instruments, LLC 10701 Red Circle Drive Minnetonka, MN 55343 USA toll free: (800) 526-7919 telephone: (952) 358-3800 fax: (952) 358-3801 European Office Network Instruments 4 Old Yard Rectory Lane Brasted, Westerham Kent TN16 1JP UK telephone: +44 (0) 1959 569880 fax: + 44 (0) 1959 569881
France, Italy, Spain Network Instruments 1 rue du 19 janvier 92380 Garches Paris France telephone: +33 (0) 1 47 10 95 21 fax: + 33 (0) 1 47 10 95 19 Germany Network Instruments Schubertstr. 29 85655 Großhelfendorf Deutschland telephone: +49 8095 87 58 58 fax: +49 8095 87 59 57 [email protected]
Configurations and product specifications are subject to change without notice.
© 1994-2008 Network Instruments, LLC. All rights reserved. Network Instruments, Observer, NI-DNA, Gen2, GigaStor, NIMS, nTAP, Link Analyst, NI University, and all associated logos are trademarks or registered trademarks of Network Instruments, LLC. All other trademarks, registered or unregistered, are property of their respective owners.
Visit us online for a full-featured product evaluation:
observer® standard . . . .3
Protocol analysis, network troubleshooting, management, and long-term trending for shared and switched networks observer expert . . . .5
Real-time and post-capture Expert event identification, VoIP and flow technology monitoring, and analysis for any topology observer suite. . . .7
Complete protocol analysis, Expert systems, distributed architecture, SNMP/RMON device management, and web access for any topology software Probes . . . .9
Monitor LAN, wireless, and gigabit networks with software-based probes Hardware Probes . . . .11
Monitor LAN, WAN, wireless, gigabit, 10 Gb, and Fibre Channel networks with high performance appliances 10/100/1000 Probe Appliance . . . .11
10/100 Probe Appliance . . . .11
Full-Duplex Probe Appliance . . . .12
Gigabit and 10 Gb Probe Appliance . . . .13
wAN Probe Appliance . . . .15
Fibre Channel Probe Appliance . . . .17
Gigastor™ Probe Appliance . . . .19
Gigabit observer suite system . . . .21
Portable wire-speed, full-duplex, feature-complete gigabit analysis wAN observer suite system . . . . 23
Portable Expert system, statistics, and analysis for serial and digital WAN links Fibre Channel observer suite system . . . .25
Portable, self-contained system for Fibre Channel analysis NIms™ . . . .27
Centralized Probe Management for Enterprise Networks observer reporting server . . . .29
Enterprise-wide reporting of network and application performance Link Analyst® . . . . 31
Network route mapping, device tracking, response monitoring, and analysis ntAPs™ . . . .33
Hardware devices designed to deliver network traffic to analysis systems on full-duplex networks Full-Duplex ntAPs . . . .33
Aggregator ntAPs . . . .35
NI university . . . .37
Comprehensive courses to fine tune your troubleshooting skills
T
ABLE OF C
ONTENT
www.networkinstruments.com
A software-only, first-level network monitoring and troubleshooting tool
Observer Standard provides first-level network analysis, including real-time packet captures and decodes, filtering, real-time statistics, triggers and alarms, trending and reporting, error tracking, and router usage across multiple topologies (LAN, wireless, and gigabit).
Packet Capture and Decode
• Decodes over 590 primary protocols and countless sub-protocols
• Nanosecond resolution provides precise analysis, even for gigabit networks • Schedule automated packet captures • SSL decryption
Powerful Packet Filtering Features • Filter packets by address, address range,
protocol offsets, and protocol presets • Use Boolean logic and regular expressions
to create filters
• Design complex filters easily with a graphical interface
• Execute multiple filters concurrently
Over 30 Real-Time Statistics
• Obtain insight into the total network load with bandwidth utilization
• Use Internet Observer to track Internet usage by user
• See usage by device with Top Talkers • Monitor VLAN activity with VLAN analysis • Get a comprehensive snapshot of network
health with Network Summary Triggers and Alarms
• Set an alarm for a particular network condition and trigger an action to alert you when the condition is present
• Be alerted of abnormal activity with a page, e-mail, and pop-up window
• Configure multiple triggers and alarms to run concurrently
OBSERVER® STANDARD
observer’s main Console
monitor wired and wireless networks concurrently keep on top of current activity with real-time statistics maximize analysis performance with a 64-bit application core receive immediate notifications as vulnerabilities are detected Get insight into typical network activity with trending and reporting
Network Trending and Reporting • View and analyze long-term trending for
Ethernet, Internet activity, VLANs, and WLANs • Justify capacity upgrades from Comparison
Analysis Reports Error Tracking
• Get a snapshot of error conditions with Network Vital Signs
• Review wireless errors, as well as aggregate signal strength, quality, and network speed • Track all errors by topology, then drill down to focus on the problem device with Network Errors by Station
Router Observer • Determine router usage • Review traffic by direction • Obtain a current heads-up display of
packets/sec, bits/sec, and interface utilization (one-minute and one-hour displays are also available)
Wireless
• Observer Standard includes a complete and scalable solution for monitoring wireless networks
• Determine optimal access point locations, configure security, and verify performance with Wireless Site Survey
• Monitor wireless activity just as easily around the world as on-site with distributed probes • View individual access point activity with the
Access Point Load Monitor
• Get a heads-up display of wireless health, including statistics on key performance characteristics with Wireless Vital Signs 64-Bit Application Core
• Maximizes analyzer performance • 32-bit version also included
• Capture buffer only limited by operating system IPv6
• Tracks, monitors, and reports on IPv6 traffic
real-time Access Point statistics
OBSER
VER ST
AND
www.networkinstruments.com Expert Summary Problem Analysis
Observer includes over 570 Experts designed to isolate problems and suggest possible solutions for network events, including:
• TCP • NetBios
• UDP • VoIP
• ICMP • Wireless
• IPX
Application Analysis
Application Analysis provides a way to track application communications to identify application problems and determine when the network is actually the source of an issue by allowing you to:
• Track application session flows and failed transactions
• Receive statistics on errors • Monitor application response time
• Perform automatic server/application discovery • Monitor and report on SQL (TDS), Oracle (TNS),
VoIP, DNS, FTP, HTTP, POP3, Telnet, SMTP, SNMP, Citrix, MS Networking (SMB), and MS Exchange
VoIP Analysis
Observer’s VoIP Analysis is designed to help monitor, troubleshoot, and maintain VoIP traffic across the entire network with over 70 metrics, including:
• Call Detail Records • Call Quality Scoring • Precedence (QoS)
• Current jitter, maximum jitter • Aggregate VoIP metrics MultiHop Analysis
MultiHop Analysis tracks conversations through up to 10 segments, hops, or routes to help:
• Determine if slowdowns are caused by network delay or system processes
• Identify packet loss and location
• Measure one-way delay, round-trip delay, and individual hop delay
OBSERVER EXPERT
Observer Standard’s functionality plus the ability to identify network issues
and offer immediate solutions
Observer Expert provides the second level of network analysis by adding both real-time and post-capture Experts, which identify network issues and offer immediate solutions. It also includes an extended level of VoIP analysis, conversation tracking, application analysis, flow technology support, and the ability to reconstruct the data stream.
VoIP summary 5
Stream Reconstruction
For enterprise administrators concerned with network forensics, compliance, and security, Observer Expert can now take captured traffic and recreate the communication, including:
• Web pages (including images) • E-mails
• Instant messages • Documents Connection Dynamics
Connection Dynamics simplifies viewing communication and identifying problems between two devices by:
• Providing a graphical view of system conversations
• Illustrating packet-by-packet delay, allowing instant identification of long latency and response times
• Offering the ability to drill down into the packet decode for further investigation
Wireless Experts
Observer’s Wireless Experts help troubleshoot and manage wireless activity:
• Track wireless conversations • Identify rogue access points • Monitor signal strength and quality NetFlow and sFlow
• Obtain critical metrics across the network • Analyze traffic statistics over weeks and
months
• Aggregate data from many devices to a single console
• Manage traffic patterns and plan for capacity upgrades
MPLS Analysis
• Track varying MPLS priorities
• Monitor, isolate, and report on MPLS issues • Segment MPLS data by label, precedence,
and embedded protocol type • Scrutinize Service Level Agreements monitors VoIP communication in depth tracks conversations through up to 10 segments, hops, or routes Identifies and solves application problems with Application Analysis raises network and traffic visibility with NetFlow and sFlow® integration Pinpoints difficult problems through real-time or post-capture expert Analysis
OBSER
VER EXPERT
www.networkinstruments.com
Observer Standard and Observer Expert’s functionality plus SNMP device
management, RMON compliance, and web publishing
Observer Suite provides an enterprise level of network analysis and reporting, including all the functionality of Observer Standard and Observer Expert, as well as built-in web reporting, SNMP device management, and RMON and HCRMON management consoles.
Web Publishing and Web Reporting A web browser is all that is needed to view data and generate reports by non-Observer users (other employees or outside consultants). You control the level of access.
• Share reports with non-Observer users • Access current and historical statistics from
any browser
• Define different access permissions for users • Automate report delivery
• Display report data based on time, stations, switches, and SNMP info
• Publish network “weather reports” for your corporate intranet/extranet
• Obtain current and historical data and usage trends based on specific stations
Complete SNMP Device Management Observer Suite offers a single solution for multi-vendor hardware networks, including a remote console for SNMP-compliant devices anywhere on your LAN/WAN or connected by the Internet.
Full Support
• Obtain multiple views of device data • View both readable and writable SNMP objects • Monitor notifications triggered by SNMP traps • Maintain compatibility with all SNMP versions • Configure triggers and alarms for SNMP data
Extensive Reporting and Trending
• Report SNMP data in real time • Collect data for baseline comparisons • Share findings through custom charts, tables,
lists, and graphical objects (forms)
OBSERVER SUITE
rmoN Console 7
RMON Device Management RMON is an industry standard for traffic management and packet-level data collection from multi-segment LANs.
• Monitor and control any RMON-standard device (router/switch/server/hardware probe) or program anywhere on the network • Comply with all RMON1 and RMON2
specifications
• Configure alarms to warn of impending problems
• Support high-capacity RMON (HCRMON)
Supports all 21 RMON and HCRMON groups, providing metrics such as:
• Packets received/sent/dropped • Statistics by host
• Statistics by conversation • Lists of events
XML/SOAP Reporting
Get a complete report for XML and Simple Object Access Protocols
• Get access to errors, capacity, and historical network data for any application that supports XML or SOAP
Custom Decode Kit
The Custom Decode Kit permits you to add additional protocols for complete, customized analysis
• Add custom, proprietary, or additional protocols to Observer decodes • Full wireless support
OBSER
VER SUITE
monitors sNmP traffic Act as rmoN and HCrmoN consoles Non-observer users can generate web-based reports
www.networkinstruments.com
SOFT WARE PROBES
Monitor remote LAN, WAN, wireless, and gigabit networks by
deploying software-based probes
Monitor your entire network through a single console interface by deploying remote software probes throughout your enterprise. Whether you have many remote offices or multiple network closets, Network Instruments probes offer complete access to remote data without the time and expense of travel. Software Probe Benefits
Software-based probes are installed on a remote LAN, wireless network, segment, or switch to collect data and report back to the Observer console. Appropriate for analyzing speeds of up to 1000 Mbps or for low-utilization gigabit networks via a SPAN port on a switch.
• Gain multiple points of visibility
• Manage remote networks as if they were local • Eliminate the time and expense of travel • Reduce training costs by using one technology
to monitor all topologies
Three software options available:
Advanced Single Probe
For a basic level of network analysis, the Advanced Single Probe permits you to:
• Continuously collect and store remote network information for baseline comparison • Protect network data with passwords
and data encryption
• Adhere to RMON and HCRMON standards with RMON probe option
Advanced Multi-Probe
Includes all the functionality of the Advanced Single Probe plus:
• Monitor data from multiple network adapter cards simultaneously
• Collaborate across locations to solve complex network problems by analyzing the same data concurrently
• Capture up to 24 GB worth of data with the industry’s largest memory buffer Advanced Expert Probe
Includes all the functionality of the Advanced Single Probe and the Advanced Multi-Probe, plus:
• View remote Expert Analysis in real time for faster troubleshooting
• Perform packet captures and decodes at the individual probe level
• Conserve bandwidth by only transferring Expert screenshots, not raw data packets
Probe security 9
SOFT
W
ARE PR
OBES
Collaborate to solve remote network problems match with an observer console for complete analysis monitor the entire network from a single user interface eliminate travel time and resolve issues from one location reduce training costs by using one technology for all topologies
Software Probes Report to Observer Consoles for In-Depth Analysis
• Over 590 protocol decodes • Nanosecond resolution
• A graphical filter rule editor to easily create complex filters
• Triggers and alarms for immediate alerts on network activity or errors
• Application analysis statistics, including response time and total/failed transactions for common applications such as SQL, MS Exchange, Oracle, Citrix, VoIP, MS Networking (SMB), and DNS
• Over 570 real-time Experts
• In-depth VoIP analysis, including call detail records, aggregate call summaries, QoS, MOS, and R-factor
• Real-time statistics on network activity such as bandwidth utilization, Top Talkers, VLANs, and Internet use
• Data stream reconstruction, including web pages, e-mails, and instant messages • MultiHop analysis tracks conversations through
up to 10 network segments, showing packet loss along the way
• Automated and customized network trending and reporting
• Statistics and packet captures/decodes that adhere to RMON 1, RMON 2, and HCRMON standards
RMON Support
All software probes can be turned into an RMON probe supporting all 21 RMON groups with full adherence to all RFCs. A probe running in RMON mode can report to any RMON or SNMP management console.
www.networkinstruments.com
10/100 Probe Appliance
HARDWARE PROBES
Monitor remote LAN, WAN, wireless, gigabit, 10 Gb, and Fibre Channel
networks with hardware-based probes
Monitor your networks through a single console interface by deploying remote hardware probes throughout your enterprise.
Hardware Probe Benefits
Appliances installed on a LAN, WAN, wireless, gigabit, 10 Gb, and Fibre Channel network, segment, or switch to collect data and report to the Observer console. With hardware probes, you can:
• Monitor network links across multiple topologies
• Capture and decode full-duplex links • Solve issues with a comprehensive
Expert system
• Analyze at the probe to limit network overhead • Configure the probe to support RMON
and HCRMON
10/100/1000 Probe Appliance The Probe Appliance is designed for low to moderately used gigabit networks and comes preloaded with Advanced Single Probe, Advanced Multi-Probe, or Advanced Expert Probe software. Observer consoles on the network connect to any Probe Appliance for in-depth analysis.
The Advanced Probe Appliance is available in five hardware configurations:
1) Single-Port Advanced Single Probe–allows for a single session to view traffic on a single 10/100/1000 network segment
2) Single-Port Advanced Multi-Probe–allows for multiple sessions by multiple users on a single 10/100/1000 network segment
3) Dual-Port Advanced Multi-Probe–allows for multiple sessions by multiple users on two 10/100/1000 network segments
4) Single-Port Advanced Expert Probe–allows for multiple sessions by multiple users, and real-time Expert processing at the probe level on a single 10/100/1000 network segment 5) Dual-Port Advanced Expert Probe–allows for multiple sessions by multiple users, and real-time expert processing at the probe level on two 10/100/1000 network segments
10/100 Probe Appliance
The Probe Appliance is designed for low to moderately used Fast Ethernet networks and comes preloaded with the Advanced Multi-Probe or the Advanced Expert Probe software. Observer consoles on the network can connect to any 4U Probe Appliance for in-depth analysis.
This 4U rackmount probe appliance is available in two configurations:
1) Advanced Multi-Probe Appliance–Monitor multiple networks simultaneously, speed up problem solving with multi-session support, and define individual levels of probe access 2) Advanced Expert Probe Appliance–Offers the
advantages of the Advanced Multi-Probe plus performs real-time Expert Analysis and packet decodes at the individual probe level RMON Support
All hardware probes can be configured as an RMON probe supporting all 21 RMON groups with full adherence to all RFCs. RMON probes report to any RMON or SNMP management console such as Observer.
Wireless Analysis
Hardware probes can be configured to support wireless networks. Monitor for rogue access points, view current activity on individual access points, speed troubleshooting with over 50 wireless Experts, and more.
10/100 Full-Duplex Probe Appliance The Full-Duplex Probe Appliance is designed for full-duplex Fast Ethernet networks and comes preloaded with the Advanced Expert Probe, which allows for multiple sessions by users, real-time Expert processing at the probe level, and individual levels of probe access. Observer consoles connect up to the Full-Duplex Probe Appliance for in-depth analysis.
RMON Support
All full-duplex probes can be configured as an RMON probe supporting all 21 RMON groups with full adherence to all RFCs. RMON probes report to any RMON or SNMP management console such as Observer.
Wireless Analysis
Full-duplex probes can be configured to support wireless networks. Monitor for rogue access points, view current activity on individual access points, speed troubleshooting with over 50 wireless Experts, and more.
Transparency with nTAPs
Every full-duplex hardware probe comes with an
nTAP to copy data from the full-duplex network
to the probe, allowing you to:
• Ensure complete and accurate full-duplex, wire-speed analysis
• Acquire an independent view of Ethernet data flow
• Eliminate dependence on a SPAN session or mirror port
• Insert and remove the probe without network disruption
Appliance Advantages
• Eliminate dependence on a SPAN or mirror port • Gain real-time Expert processing
• Reports to any Expert or Suite console
Full-Duplex Link utilization
10/100 FULL-DUPLEX PROBE
Monitor remote LAN and wireless networks with a full-duplex
10/100 hardware-based probe
Monitor your full-duplex Fast Ethernet networks through a single console interface by deploying remote full-duplex hardware probes throughout your enterprise. Whether you have many remote offices or multiple network closets, Network Instruments probes offer complete access to remote data without the time and expense of travel.
www.networkinstruments.com
Comprehensive analysis for full-duplex, gigabit, and 10 Gb networks
The Gigabit and 10 Gb Probe Appliance is designed for administrators that require wire-speed, full-duplex capture. Probes provide a direct, passive link into the data stream, offering an independent, proven, and trusted view of network traffic. Deploy a Probe Appliance to add gigabit or 10 Gb analysis, statistics, trending, and reporting to any Observer Expert or Observer Suite console.
Industry-Leading Performance
• Localizes processing at the probe to minimize network overhead
• Boosts troubleshooting power by allowing multiple users to work in collaboration or by relying on individual users to monitor different network events
• Provides visibility into optical or copper links with SFP technology
• Gain visibility into trunked links 64-Bit Application Core
• Provides speed advantages over similar 32-bit applications
• Permits up to a 24 GB memory buffer (the largest in the industry)
Transparency with nTAPs
• Insert and remove probe without disruption • Acquire an independent view of gigabit and
10 Gb data flow
• Eliminate dependence on a SPAN session or mirror port
• Ensure complete and accurate full-duplex, wire-speed analysis
• nTAP automatically included Easy Deployment
• Rackmount 4U unit
• Fits seamlessly into the Distributed Network Analysis (NI-DNA™ ) architecture
• Reports to any Observer Expert and Observer Suite console on the network
• Configures as a local console for on-site analysis
GIGABIT AND 10 Gb PROBE APPLIANCE
VLAN reports 13
Designed with Gen2™ capture technology • Ensures full-duplex, wire-speed gigabit and
10 Gb capture on high-utilization links • Monitors up to eight ports for any combination
of SPAN sessions, full-duplex links, and trunked links
Observer Features • Over 590 protocol decodes
• Application analysis statistics, including response time and total/failed transactions for common applications such as SQL, MS Exchange, Oracle, Citrix, VoIP, MS Networking (SMB), and DNS
• A graphical filter rule editor to easily create complex filters
• Nanosecond resolution
• Triggers and alarms for immediate alerts on network activity or errors
• Over 570 real-time Experts
• 70 VoIP-specific metrics, including call detail records, call quality scoring, and QoS • Real-time statistics on network activity such as
bandwidth utilization, Top Talkers, VLANs, and Internet use
• Data stream reconstruction, including web pages, e-mails, and instant messages • MultiHop analysis tracks conversations as it
hops through up to 10 network segments, showing packet loss along the way • Automated and customized network trending
and reporting
• Statistics and packet captures/decodes that adhere to RMON 1, RMON 2, and HCRMON standards
track gigabit and 10 Gb statistics in real time switch easily between copper and optical links solve issues with a comprehensive real-time expert monitor up to eight ports independently or in aggregation obtain an independent view of gigabit and 10 Gb data flow
GIGABIT AND 10 G
b PR
OBE APPLIANCE
www.networkinstruments.com
WAN PROBE APPLIANCE
Troubleshoot and document WAN circuits without leaving your desk
The WAN Probe Appliance offers complete inline monitoring, decodes and statistics for WAN traffic, and all payload data for serial and digital WAN links.Industry-Leading Performance • Ensures full-duplex capture on serial HSSI,
digital T3/DS3/E3, and serial and digital T1/E1 • Monitors up to 16 connections individually or
in aggregation
• Localizes processing at the probe to minimize network overhead
Real-Time Analysis
• Obtain over 30 WAN metrics in real time, including utilization, Top Talkers, and Application Analysis
• Solve issues immediately with WAN Experts • Perform packet captures and review statistics
that adhere to RMON1/RMON2 and HCRMON standards
• Run network trending and reporting • Manage VoIP communication with an
enterprise-strength VoIP Expert
WAN Vital Signs
• Get a comprehensive summary of WAN errors, statistics, utilization, and congestion • View DCE/DTE traffic individually or in
aggregation
• Statistics are shown in packets, bytes, FECNs, BECNs, number of packets marked discard eligible, errors, and utilization
• Monitor CIR and compare with max line utilization to confirm SLA
MultiHop Analysis
• Track conversations and transactions through up to 10 segments, hops, or routes • Quickly determine how long it takes data to
transfer across WAN links
• Examine if slowdowns are caused by network delay or system processes
• Identify packet loss and location • Measure one-way delay, round-trip delay,
and individual hop delay
multiHop Analysis 15
W
AN PR
OBE APPLIANCE
monitor CIr for cost effectiveness Verify and enforce service Level Agreements obtain an independent view of wAN data flow review data across serial and digital wAN links Perform analysis on wAN encapsulation and payload data
WAN Probe
A complete range of WAN Probe configurations is available for most types of WAN circuits.
Advantages of the WAN Probe
• Completely configured and ready to use • Identify and resolve WAN anomalies with an
included Expert system
• Monitors up to 16 connections, individually, or in aggregate
• Localizes processing at the probe to minimize network overhead
• Performs WAN RMON data collection with included MIB
• Includes TAPs
Easy Deployment • Rackmount 4U unit
• Fits seamlessly into the Network Instruments Distributed Network Analysis (NI-DNA™ ) architecture
• Reports to any Observer Expert and Observer Suite console on the network
• Configures as a local console for on-site analysis
• Can be licensed as an RMON probe Transparency with a TAP
• Insert and remove the probe without disrupting network traffic
• Acquire an independent view of data flow • Ensure complete and accurate full-duplex,
wire-speed analysis
www.networkinstruments.com
FIBRE CHANNEL PROBE APPLIANCE
Troubleshoot your SAN without leaving your desk
The Fibre Channel Probe Appliance quickly identifies and solves SAN issues, providing real-time SAN analysis, statistics, trending and reporting to any Observer Expert or Observer Suite console.
Real-time SAN Analysis
• Obtain SAN metrics in real time such as top communicating disk subsystems, protocol distribution, and error counts
• Solve issues immediately with 20 real-time SAN Experts
• Utilize network trending and reporting features such as comparison reports and web-based reporting
• Evaluate server and network response time under various load scenarios
• Observe all Fibre Channel protocols by packets, bytes, percentage, or percentage of utilization
Industry-Leading Performance
• Ensure full-duplex, wire-speed capture on Fibre Channel links
• Capture large amounts without packet loss with up to 24 GB buffer
• Monitor up to two full-duplex links independently or in aggregate • Localized data processing at the probe
minimizes network overhead Easy-to-Deploy
• Rackmount 4U unit
• Fits seamlessly into the Network Instruments Distributed Network Analysis (NI-DNA™) architecture
• Reports back to the award-winning Observer Expert and Observer Suite console
• Configure as a local console for on-site analysis
Fibre Channel expert summary
FIBRE CHANNEL PR
OBE APPLIANCE
Transparency with an nTAP
• Ensure complete, full-duplex capture at wire speed
• Insert and remove the probe without network disruption
• Acquire an independent view of SAN data flow • Eliminate dependence on a SPAN or mirror port • Ensure full-duplex, wire speed passive analysis Gen2™ Capture Technology
• Designed by Network Instruments • Takes advantage of 64-bit Observer • Maximizes Fibre Channel analysis • Monitor up to four ports simultaneously
Comprehensive Analysis with Observer • Over 590 protocol decodes
• Nanosecond resolution for enterprise-level networks
• Easily create complex filters with the graphical filter rule editor
• Over 570 Expert events
• Application analysis statistics, including response time and total/failed transactions for critical applications such as Citrix, SQL, Oracle, MS Exchange, VoIP, MS Networking (SMB), and HTTP
• Long-term network trending and reporting • Statistics and packet captures/decodes that adhere to RMON 1, RMON 2, and HCRMON standards
Decode Fibre Channel protocols monitor over 30 Fibre Channel statistics obtain an independent view of Fibre Channel solve issues with a comprehensive, real-time expert system
www.networkinstruments.com
Capture terabytes of traffic for large-scale analysis, data-mining, and
network forensics
GigaStor captures and stores every packet of data crossing the network and performs back-in-time or retrospective network analysis at line rate on high-speed enterprise networks.
Use GigaStor to:
• Perform high-level application views and deep packet analysis from one device
• Utilize a time window to isolate problems • Ensure internal and external corporate
compliance
• Perform network forensics with stream reconstruction
• Monitor gigabit, 10 Gb, Fibre Channel, WAN, Ethernet, and WLAN
• Eliminate the laborious task of having to replicate network problems
High-Performance • Line-rate gigabit captures
• Resolve events down to the nanosecond with time-based navigation
• Real-time Expert processing on the probe eliminates unnecessary data transfer • Flexible filtering technology helps immediately
pinpoint the problem
• Gen2™ technology optimizes data capture for analysis
Easy to Deploy • Rackmount unit
• Includes nTAPs to insert and remove the GigaStor without disrupting network traffic • Reports to any Expert and Suite console • Configures as a local console for on-site
analysis
• Integrates into Network Instruments’ Distributed Network Analysis (NI-DNA™) architecture, so it works seamlessly with other Network Instruments products
High Capacity
• Capture up to 48 TB of data (or write to SAN) • 64-bit permits up to a 24 GB memory buffer Troubleshooting Power
• The GigaStor captures and stores all network data • Any Observer Expert and Observer Suite
console on the network can access the captured network data for analysis • Multiple users can connect and analyze the
captured data independently–allowing users to work individually or in collaboration
GIGASTOR™
Gigastor Interface 19
Network Forensics
The GigaStor plays a significant role in data mining, network forensics, and data retention compliance. It is ideal for transaction-heavy organizations. For example, the GigaStor not only shows the communication that took place, it can also reconstruct the mined data— providing hard evidence such as:
• Phone conversations • Web pages • Instant messages • E-mails • Documents Security Forensics
• Identify thousands of attacks and anomalies with “Snort-style” IDS functionality • Pinpoint source of attack, time of occurrence,
and location
• Drill down for packet-level forensic analysis • Locate compromised machines and network
infrastructure
• Provide evidence for compliance and security issues
Ease of Navigation
• View conversations and transactions by time • Navigate through data with ease
• Filter down to nanosecond intervals • Perform Expert analysis in real time and
post capture Observer Features
The GigaStor reports to any Observer Expert and Observer Suite console located on the network for the most comprehensive real-time analysis in the industry:
• Over 590 protocol decodes • Over 570 real-time Experts
• Over 70 VoIP metrics, including call detail records, aggregate call summaries, QoS, MOS, and R-factor
• Application statistics, including response time and total/failed transactions for common applications (SQL, MS Exchange, Oracle, VoIP, Citrix, MS Networking (SMB), and DNS)
GIGAST
OR
maximizes analysis with 64-bit core Captures days, weeks, even months worth of data reconstructs data stream to support network forensics Performs analysis on-site at probe to limit network overhead monitors sPAN sessions, full-duplex links, and trunked links flexibly
www.networkinstruments.com
GIGABIT OBSERVER SUITE SYSTEM
A portable, gigabit and 10 Gb analysis system for field service engineers
The Gigabit Observer Suite System (GOSS) is a portable device that contains all the hardware and software required to troubleshoot and manage the most advanced wire-speed gigabit and 10 Gb networks in real time. Complete Gigabit Analysis• Obtain full-duplex, wire-speed gigabit capture • Troubleshoot with real-time metrics and a
comprehensive Expert system
• Passive view—will not interfere with the network
• Get complete visibility into the network with an nTAP
Portable, Compact Design
• Designed for convenience in travel and shipping
• Fully loaded, the GOSS weighs 25 lbs (11.3 kg) • With case, the GOSS weighs less than 50 lbs
(22.7 kg)
• Includes all necessary hardware and software for real-time, wire-speed analysis
Transparency with nTAPs
• Insert and remove GOSS without disrupting network traffic
• Acquire an independent view of gigabit and 10 Gb data flow
• Eliminate dependence on a SPAN or mirror port • Ensure complete and accurate full-duplex,
wire-speed analysis
High Performance
• Includes a 64-bit core, providing speed advantages over similar 32-bit applications • Permits up to a 24 GB memory buffer, the
largest in the industry
• Includes the award-winning Observer Suite console for in-depth analysis
• Reports to any Observer Expert and Observer Suite console on the network
Gen2™ Capture Technology
• Ensures full-duplex, wire-speed capture on high-utilization links
• Monitors up to eight ports for any combination of SPAN sessions, full-duplex links, and trunked links
• Implement driver updates with a simple downloadable firmware patch
• Guarantees accurate time stamping across multiple gigabit and 10 Gb links
• Provides visibility into optical or copper links with SFP technology
top talkers 21
GIGABIT OBSER
VER SUITE SY
STEM
Observer Features • Over 590 protocol decodes • Nanosecond resolution
• A graphical filter rule editor to easily create complex filters
• Triggers and alarms for immediate alerts on network activity or errors
• Application analysis statistics, including response time and total/failed transactions for common applications such as SQL, MS Exchange, Oracle, VoIP, Citrix, MS Networking (SMB), and DNS
• Over 70 VoIP metrics, including call detail records, aggregate call summaries, QoS, MOS, and R-factor
• Real-time statistics on network activity such as bandwidth utilization, Top Talkers, VLANs, and Internet use
• Data stream reconstruction, including web pages, e-mails, and instant messages
• MultiHop analysis tracks conversations as it hops through up to 10 network segments, showing packet loss along the way • Over 570 real-time Experts
• Automated and customized network trending and reporting
• Statistics and packet captures/decodes that adhere to RMON 1, RMON 2, and HCRMON standards
System Components
• Observer Suite software • Gen2 Gigabit Capture Card
• 10/100/1000 Ethernet management port • All required cabling
• nTAP
• Built-in display, keyboard, trackpad, and DVD+/-RW drive
• Durable, ATA hard case appropriate for travel Full-duplex, wire-speed gigabit capture switch easily between copper and optical links monitors up to eight ports independently or in aggregation Comprehensive gigabit and 10 Gb analysis in a rugged case weighs less than 50 lbs for convenience in travel and shipping
www.networkinstruments.com
WAN OBSERVER SUITE SYSTEM
Perform complete packet capture, decode, and real-time analysis
of WAN encapsulation and payload data
The WOSS is a portable system that offers comprehensive inline monitoring, decode and statistics for WAN traffic, as well as all payload data for serial and digital WAN links.
Industry-Leading Performance • Ensures full-duplex capture on serial HSSI,
digital T3/DS3/E3, and serial and digital T1/E1 • Monitors up to eight connections, which can be
monitored individually or in aggregation • Localizes processing at the probe to minimize
network overhead Real-Time Analysis
• Obtain metrics in real time, including utilization, Top Talkers, and Application Analysis • Perform packet captures and review statistics
that adhere to RMON1/RMON2 and HCRMON standards
• Manage VoIP communication with enterprise-strength VoIP Experts Trending and Reporting
• Utilize trending data to plan for upgrades and prepare capacity planning
• Publish WAN reports via the web to share findings across the organization
• Provide non-Observer users controlled access to WAN baseline data
MultiHop Analysis
• Track conversations and transactions through up to 10 segments, hops, or routes • Quickly determine how long it takes data
to transfer across WAN links
• Determine if slowdowns are caused by network delay or system processes
• Identify packet loss and location • Measure one-way delay, round-trip delay,
and individual hop delay WAN Vital Signs
• Get a comprehensive summary of WAN errors, statistics, utilization, and congestion • View DCE/DTE traffic individually or in
aggregation
• Statistics are shown in packets, bytes, FECNs, BECNs, number of discard eligibility, errors, and utilization
• Monitor CIR and compare with max line utilization to confirm SLA
Statistics
• Over 30 real-time statistics for WAN Analysis • Real-time information is displayed by Data Link
Connection Identifiers (DLCI), Private Virtual Circuit (PVC), or whole link
• DLCI and Committed Information Rates (CIRs) can be auto-discovered or user defined Capture/Decode
• Capture and decode WAN encapsulation and payload data with detailed packet information • Filter traffic by DLCI or IP address, using
pre-defined protocol filters, or create your own
wAN observer suite system
W
AN OBSER
VER SUITE SY
STEM
Filtering
• Utilize many WAN-specific filtering options • Select WAN conditions to include or exclude
packets based on flow direction, forward/ backward congestion, and discard eligibility Real-Time Expert
• Displays hundreds of Expert items in a format that makes troubleshooting effortless • Summary window quickly highlights critical
WAN and network anomalies
• Break down conversations by application or problem device for further investigation
Transparency with a TAP
• Insert and remove probe without disruption • Acquire an independent view of WAN data flow • Ensure accurate full-duplex analysis
System Components
• Observer Suite software • WAN adapter
• 10/100/1000 Ethernet management port • All required cabling
• TAP
• Built-in display, keyboard, trackpad, and DVD+/-RW drive
• Durable, ATA hard case appropriate for travel monitor CIr for cost effectiveness Portable unit for convenient travel supports wAN speeds up to Ds3/t3/e3 Verify and enforce service Level Agreements obtain an independent view of wAN data flow
www.networkinstruments.com
FIBRE CHANNEL OBSERVER SUITE SYSTEM
25
Portable, ready-to-go SAN analysis system
The Fibre Channel Observer Suite System (FOSS) is a portable device that contains all the hardware and software required to troubleshoot and manage the most advanced storage area networks. Complete SAN Analysis
• Full-duplex, wire-speed capture • Real-time metrics and a comprehensive
Expert system
• Monitor over 30 Fibre Channel statistics • Over 20 real-time SAN-specific Experts • Track application performance • Review aggregate summaries of overall
SAN health
• Passive view—will not interfere with the network
Portable, Compact Design
• Fully loaded, the FOSS weighs 25 lbs (11.3 kg) • With ATA case, the FOSS weighs less than
50 lbs (22.7 kg)
• Designed for convenience in travel and shipping
• Includes all necessary hardware and software for real-time, wire-speed analysis
High-Performance
• Permits up to 24 GB memory buffer, the largest in the industry • Monitor up to two full-duplex links
independently or in aggregate
• Utilize internal Expert probe for collaboration with other consoles
Transparency with an nTAP
• Ensure complete, full-duplex capture at wire speed
• Insert and remove the probe without network disruption
• Acquire an independent view of SAN data flow • Eliminate dependence on a SPAN or mirror port • Ensure full-duplex, wire speed passive analysis
FIBRE CHANNEL OBSER
VER SUITE SY
STEM
Gen2™ Capture Technology
• Ensures full-duplex, wire-speed capture on highly utilized Fibre Channel links • Implement driver updates with a simple
downloadable firmware patch
• Guarantees accurate time stamping across multiple Fibre Channel, gigabit, and 10 Gb links
System Components
• Observer Suite console software • Gen2 Fibre Channel Capture Card • 10/100/1000 Ethernet management port • All required cabling
• nTAP
• Built-in display, keyboard, trackpad, and DVD+/-RW drive
• Durable, ATA hard case appropriate for travel Full-duplex, wire-speed Fibre Channel analysis monitor up to four ports independently or in aggregate Less than 50 lbs for convenience in travel and shipping Comprehensive Fibre Channel analysis in a rugged case
www.networkinstruments.com
NIMS™
The Network Instruments Management Server centralizes probe
management for enterprise networks
For IT professionals tasked with maintaining multiple software probes and probe appliances across their enterprise, the Network Instruments Management Server (NIMS™) simplifies probe management, security, and maintenance. The NIMS eliminates the need to keep track of authentication lists and multiple filters—allowing you to manage probe permissions on a global level.
NIMS Advantages:
• Authenticates users from one central location • Manages user passwords and permissions
globally
• Defines probe access and rights by individual users, user groups, or probe groups • Logs all probe access activity
• Shares filters with Observer users across the network
Centralized Rights Management
The NIMS replaces individual probe administration tasks with a centralized repository for
authentication information. Rather than maintaining separate user accounts on each probe, all probes query the NIMS to authenticate users. Choose to manually enter accounts or automatically populate and update accounts from a local Windows system, Active Directory, or RADIUS server.
Use NIMS’s centralized rights management to:
• Record all access activity, including successful and unsuccessful logins
• Grant access permissions based on group or individual probe membership • Block access after a pre-defined number
of unsuccessful login attempts • Setup alarms and e-mail notifications
on failed logins
• Automatically disable user accounts after periods of no activity
• Set packet view detail by user or user group • Globally reset passwords
Centralized Licensing
Network managers can utilize the NIMS to centrally maintain individual probe licenses.
Use NIMS’s centralized licensing to:
• Grant licenses on a first-come, first-served basis
• Efficiently authorize multiple Observer products • Manage multiple types of console and probe
licenses
Centralized Update System
The NIMS can localize the administration of major and minor version updates, allowing network administrators to maintain version control.
Manage software updates in a variety of ways:
• Automatically update to the latest software version
• Ensure all software remains at a certain version number
• Upgrade minor releases only • Only update Observer consoles Failover Redundancy
Use the redundant NIMS to protect against connection failure. Ensure that real-time analysis and distributed visibility will continue if the primary NIMS becomes unavailable.
Shared Access to Analysis Tools
A key NIMS benefit for network administrators is the ability to share filter libraries across probes and across the network with other Observer users. Filter lists can be uploaded or downloaded to or from the NIMS as often as necessary. Filters ensure only relevant data is displayed or collected, ultimately speeding troubleshooting and analysis.
NIMS Configuration Options:
• NIMS Software • NIMS Appliance
NIMS
Centralize probe management Authenticate users from one location segment probe rights and permissions keep a record of all probe access activity share filters and probe lists with observer usersNIMS lets IT staff centrally manage secure access to sensitive analyzer data. Instead of each probe maintaining its own list of usernames, passwords, and permissions, all such access control lists are held in the NIMS database. Probes then query the NIMS to validate users and set access permissions for consoles requesting connection. Once authenticated, the connection is secured by 128-bit shared key encryption.
10/100/1000 Probe Appliance NIMS-enabled probes
with unique Observer encryption keys.
NIMS-enabled Observer consoles with key to
match probe. Observer Expert Network Instruments Management Server (NIMS) Observer Suite Software Probe Software Probe User PW Permissions Ted **** xxxxxx Bill **** 00x0x0 Sue **** 00000x Pat **** xxxxxx
www.networkinstruments.com
OBSERVER REPORTING SERVER
Enterprise-wide intelligence for managing network performance
Observer Reporting Server aggregates reports from multiple Observer Suites into a single view, providing convenient access to in-depth network and application analysis across the enterprise.Enterprise-Wide Visibility
• High-level aggregate reporting across large-scale Observer deployments • Drill down for quick problem resolution
with Observer
• Evaluate the overall impact of mission-critical applications on your business
• Assess developing trends to prepare for capacity expansion
Reporting by Business Unit
• Set up reporting by department, infrastructure type, or business activity
• Manage utilization and application performance by business unit • Align performance with business goals • Evaluate new application rollouts with macro
and micro-level views
Network-Wide Statistics
• Monitor performance across the enterprise • NetFlow/sFlow statistics
• In-depth application metrics • Transaction delay
• Top Talkers • Link Utilization
Comprehensive Analysis and Drill Down • Synchronize reports in real-time with Observer
Suite consoles and Probes
• Gain full activity details on Citrix, SQL, Oracle, MS Exchange, VoIP, MS Networking (SMB), and HTTP
• Drill down on individual link or user detail using Observer
• Utilize in-depth network and application metrics for pinpointing root cause • Compare reports with GigaStor for historical
analysis
Aggregate View of top talkers 29
OBSER
VER REPORTING SER
VER
Scalability
• Server connects to multiple Observer Suites • Combines data from multiple locations into
a single report
• Authorized users can access Reporting Server from any web browser
Customizable Security
• Reporting application resides on secure web server
• Implement user-based and role-based authentication to control access reports • Allow outside consultants to view reports
without viewing underlying data
Deployment Options
Observer Reporting Server runs on a secure web server that works seamlessly with the Observer product line. Deployment options include:
• Software only • Stand-alone appliance
• Combination appliance with Observer Suite to connect directly to probes
optimize network performance macro and micro-level reporting Drill down with observer for fast problem resolution organize reporting by business unit, function, or location
www.networkinstruments.com
LINK ANALYST®
A high-level mapping device for your entire network
Link Analyst is a powerful, intuitive solution for managing critical networks and the routes that connect them. Whether your network spans multiple rooms or multiple continents, Link Analyst helps you map and manage your entire network.
Map in Minutes
• Generate a map of any segment or the entire network
• Obtain a visual grade of current response times • Drill down to individual station statistics • Display device addresses, protocols, response
time histories, and configuration status • Organize network maps by department,
function, or location for quick and easy reference
Verify Quality of Service and Service Level Agreements
• Monitor the severity of degradation and spot trends that may indicate an impending failure • Review QoS levels end-to-end and between
network components
• Audit network performance to ensure existing SLAs are in compliance
• Identify lapses quickly in third-party agreements
Obtain Point-to-Point Route Analysis • Review response time between hops on any
route between Link Analyst and IP-based devices
• Monitor connection performance between devices
• Create an independent QoS log for WAN vendor uptime and SLA verification • Keep track of any WAN, point-to-point
connection, or critical site connection Configure Alarms to Alert the Proper Administrator Based on Work Schedule
• Customize or arrange notifications based on your IT departments availability • Ensure notifications are sent to the right
administrator based on the time and day of the problem
• Ideal for 24/7/365 IT organizations
Network maps 31
LINK ANAL
Y
ST
Share Data with Web Reports
• Create and review reports via Link Analyst or any web browser
• Sort data by alert status or number of good, marginal, or poor polls
• Compare and contrast select time periods • Protect data from unauthorized access
or limit views to one user, groups of users, or by individual map views
• Track response over time for historical analysis Active Notification System
Link Analyst allows you to set performance thresholds. Then, as thresholds are crossed or as nodes become unavailable, the Link Analyst Active Notification System can alert you to immediately address the problem.
The Active Notification System has six alert options:
• Flags a failing device and displays it in red • Sends a SMS/text message to assigned cell
phones
• Prints trouble tickets on assigned printers • Plays a user-defined sound for audible
notification
• Sends an e-mail to predefined e-mail accounts • Sends a page to any predefined pagers Link Analyst Integrates with Observer®
• Select any network device, probe, or SNMP agent inside Link Analyst
• Right-click on that device to run analysis with Observer
• All filters and captures offer a choice of either MAC- (layer 2) or IP- (layer 3) based monitoring
• Associate probes with Link Analyst maps for Integrate with observer Log response times and create a historical baseline utilize Active Notification system for instant alerts Detect network abnormalities and device/route failures Create maps of complex local and remote networks with ease
www.networkinstruments.com
FULL-DUPLEX nTAP™
Complete visibility into full-duplex networks
Full-duplex nTAPs provide monitoring devices with access to all network traffic, including errors found in the physical layer from both sides of a full-duplex link.
How Full-Duplex nTAPs Work
A TAP is a passive splitting mechanism installed between a ‘device of interest’ and the network. TAPs transmit both the send and receive data streams simultaneously on separate dedicated channels, ensuring all data (up to 2000 Mbps for gigabit) arrives at the monitoring device in real time. For that reason, the monitoring device must be equipped with a dual-receive capture card capable of aggregating the two data streams. TAPs are ideal for accessing highly utilized or business-critical full-duplex links.
The Full-Duplex nTAP Advantage • Offers complete visibility regardless of traffic
levels
• Provides access to all network traffic, including errors found in the physical layer from both sides of a full-duplex link
• Economical to install
• Allows you to connect and disconnect a monitoring device to a permanently deployed
nTAP without breaking the full-duplex signal
• Supports redundant failover links
• Avoids being the target of a hack or virus attack because the TAP has no network address • Utilizes the latest chipsets to offer increased
reliability and a more compact design with higher port density
• Regardless of link type, device type, or analysis tool, there is an nTAP that fits your needs and budget
Full-Duplex nTAPs for Optical Links Several nTAP configurations are available to access network traffic on full-duplex optical links.
• Supports gigabit (SM and MM) and 10 Gb (MM) optical links
• Available in One-Channel, Two-Channel, and Three-Channel units
• Delivers nine channels in a single 1U rack • Offers 50/50, 60/40, 70/30, 80/20, and 90/10
signal split ratios • Supports PoE
Full-Duplex nTAPs for Copper Links Several nTAP configurations are available to access network traffic on full-duplex Ethernet links up to gigabit speed.
10/100 Full-Duplex Copper nTAP
• Transfers Fast Ethernet traffic from a full-duplex copper link to a copper monitoring device • Includes a connection to the full-duplex link
under test and an analyzer equipped with a dual-receive capture card
10/100/1000 Full-Duplex Copper nTAP • Transfers gigabit traffic from a full-duplex
copper link to a copper monitoring device • Auto-negotiates to support 10 Mb and Fast
Ethernet traffic
• Includes a connection to the full-duplex link under test and an analyzer equipped with a dual-receive capture card
10/100/1000 Full-Duplex Copper to Optical Conversion nTAP
• Transfers traffic from a full-duplex copper link to a copper or optical monitoring device • Includes a connection to the full-duplex link
under test, and a copper or optical analyzer equipped with a dual-receive capture card Compatibility
nTAPs are ideal for enterprises using analysis tools
such as:
• Network analyzers • Protocol analyzers • RMON probes • Forensic appliances
• Remote monitoring appliances • Intrusion detection systems • Security monitoring devices
FULL
-DUPLEX
n
TA
P
economical to install supports redundant failover links Compact design offers high port density Provides visibility into all network traffic several copper and optical configurations available10/100/1000 Full-Duplex Copper ntAP
two-Channel Full-Duplex optical ntAP
1u ntAP rack-mount Configuration
www.networkinstruments.com
AGGREGATOR nTAP
Complete visibility into moderately utilized full-duplex links
Aggregator nTAPs provide a copy of the data from full-duplex copper links integrated into a single stream to an analysis or security device with a standard (single-receive) capture interface.
How Aggregator nTAPs Work
An Aggregator nTAP represents a good compromise between the SPAN and full-duplex nTAP options for low-to-moderate utilization links. The Aggregator
nTAP provides access to data streams passing
through a full-duplex network link, copying both sides of the link. Both sides of the link are then aggregated into a single stream. The integrated stream is then sent out a simplex port to an analysis or security device with a single-receive capture interface.
The Aggregator nTAP Advantage • Offers complete visibility to full-duplex,
moderate utilization links
• Will not block physical-layer error packets • Industry-leading 1 GB buffer option • Economical to install
• Allows you to connect and disconnect a monitoring device to a permanently deployed
nTAP without breaking the full-duplex signal
• Supports redundant failover links on your network
• Avoids being the target of a hack or virus attack because an nTAP has no address on the network
35
Link under test 10/100/1000 Mb C
opper Interface
Analysis Devices
Server
Switch
A
GGREGA
T
OR
n
TA
P
512 mB optional buffer supports redundant failover links Provides access to physical layer errors supports two monitoring devices on a single linkAggregator ntAP
Aggregator Conversion ntAP
Aggregator nTAP
• Choose a 256 MB, 512 MB, or 1 GB buffer to cache network traffic spikes that exceed an analyzer’s capture capacity
• Auto-negotiates to support 10 Mb, 100 Mb, or Gigabit network traffic
• Optionally transfers 10 Mb or 100 Mb input from the network to an analyzer connected to a gigabit link
Aggregator Conversion nTAP
• Streams full-duplex traffic on a single TAP into two different optical or copper single-receive devices
• SFP-based outputs supports the use of an SX, LX, or ZX device
Redundant Power Supply
A redundant power supply is available for all copper Aggregator nTAPs. By adding a second power supply, the nTAP will continue to send data to the analysis device if the primary power supply fails. If both power sources fail, network traffic will continue to pass through the nTAP.
Supports Redundant Failover Links All Aggregator nTAPs have the ability to support redundant failover links. If the link on one side of the nTAP goes down, the nTAP will automatically bring down the other link, allowing the corresponding device to switch over to a redundant link.
www.networkinstruments.com
NI UNIVERSITY
Network Instruments University offers in-depth
programs to help you get the most out of Observer
Network Instruments University classes are offered at various locations across the U.S. and through authorized training centers worldwide. Network Instruments also provides on-site customized training options. TR01- Basic Network AnalysisThis two-day course lays a foundation for learning basic network management and troubleshooting skills.
• Discover a logical troubleshooting methodology for capturing and analyzing data frames
• Learn to troubleshoot, maintain, optimize, and monitor your network using Observer • Quickly fine tune your network analysis skills • Increase your company’s productivity by
proactively identifying network problems TR02 - TCP/IP Network Analysis
This two-day course focuses on the protocols and issues facing network managers and technicians in TCP/IP and NFS environments.
Prerequisite: TR01
• Learn to troubleshoot common problems in all layers of the TCP/IP stack
• Use a field technician’s perspective to examine, analyze, and dissect components
• Utilize knowledge of the functions of upper layer protocols to identify anomalies in buffer • Understand the SNMP model and RMON MIB
structure
• Reinforce training with hands-on exercises
TR10 – 802.11 Wireless Network Analysis This two-day course is designed to teach students solid network management skills using a network analyzer. This class also provides a logical troubleshooting approach to capturing and analyzing wireless data frames.
• Learn how to troubleshoot, optimize, and monitor WLANs
• Utilize Observer’s wireless tools to keep on top of WLAN issues
• Understand how to perform a wireless site survey
• Find rogue access points and learn to eliminate WLAN vulnerabilities
TR30 – Security Training
This two-day course focuses on securing the network environments. Learn how a network analyzer can help protect your network against internal and external security threats.
• Learn to identify common security threats, filter for virus/hack attacks, and how to deal with security issues
• Discover how to examine, analyze, and detect protocol components using a network analyzer • Manage and troubleshoot security issues • Analyze buffers
• Understand methods of network penetration • Correct and/or block anomalies found in buffer
Network Instruments also provides on-site customized training options.
For a complete schedule of training courses in the United States, visit our Training Center at: www.networkinstruments.com/training
For a complete schedule of training courses in the United Kingdom and Europe, visit our UK Training Centre at: www.networkinstruments.co.uk/training