Surveyor
Finisar Software License Agreement
Trademarks and Copyrights
License
Term
Restricted Rights Legend
Limited Software Warranty
Patent and Copyright Indemnification
Limitation of Liability
Customer Support FAX
Customer Support Phone
Internet Address
World-Wide Web Mailing Address
Table of Contents
Surveyor
Configuring Surveyor
Views
Resources and Modes
Capture and Display Filters
Transmit Specification
10-1
Alarms
10-15
10-58
Multi-QoS 11-1
10-102
13-1
12-1
Counters
Utilities
Pre-Defined Filter Templates
Implementation Profile
Keyboard Shortcuts
Parser Names
List of Figures
10-1
List of Tables
Application Layer Host Table View, Table Column Descriptions
11-21 11-8
Surveyor
Introduction
Surveyor Functions
Surveyor Functions
Function Description
Introduction
Protocols Supported
Analyzer Devices
Finisar Analyzer Devices
Finisar Device Description
XNS
DECnet Phase
AppleTalk Phase2
Oracle Suite IPX/SPX Suite
Banyan Vines Suite
IBM ISO
Capture to Disk and THGsE Analyzer Support
Whats New in Release
Disk Caching
Capture Management
Expanded Multi-QoS Support
Smnp Extended Agent
New and Enhanced Protocol Decodes
Surveyor
System Requirements
System Requirements
RAM
PII
Upgrading Surveyor
Supported Analyzer Cards and Network Adapter Cards
Desktop PC
Installing Surveyor
Installing Analyzer Hardware in a Desktop PC
Installing Analyzer Hardware
Installing the THGm, Windows NT
Installing THGm, Windows 2000/XP
Installing Analyzer Hardware in a Notebook PC
Cdrom
Installation
Installing More Than One Analyzer Card in a Notebook PC
Hardware/Software Compatibility Matrix
Compatibility Matrix
Surveyor
Launching Surveyor
Surveyor System
Default Account Names, Passwords and Privileges
Basic Navigation Tips
Surveyor
Getting Started
Buttons and Toolbars
Surveyor Toolbar
Module Toolbar Summary View
Buttons and Toolbars
Detail View Toolbar
Getting Started
Data Views Toolbar
Getting Started
Surveyor
Filter Design Toolbar
Filter States Design Toolbar
Design window
Surveyor
Capture View Toolbar
Surveyor
Getting Started
File Formats
Providing a Name Table to Surveyor
Establishing Links for THGm
Configuring the Interface
Customizing Views and Windows
Docking Windows
Capture View Display Options
Configuring Surveyor
Histogram Options
Setting Histogram Colors
Setting the Histogram Download Size
Setting Histogram Zoom Factor
Setting the Monitoring View for a Module
Choose Monitor View Preferences
Table Views
Configuring Chart Views
Hardware Device Properties
Module Settings Properties
Module Setting Default Values
Default Module Settings
Buffer Size
Packet Slice Slicing Size
Non-Well-Known-Ports Mode
Expert Analysis Mode
Stop-and-Save Capture Buffer
Modes
Monitor M-QoS Only Mode
System Settings
Configuring Ports to Scan
WKP4620
RSP Time Out value
Configuring Remote Communications
Protocol Color Coding
Setting Update Timers
Display Timer Default Value
Default Display Timer Settings
Disk Options
Cache File Location
Disk Capture Location
Configuring Counter Logging
Configuring Alarms
History Log File Settings and Default Values Log Setting
Mmddhhmm.ss Mmmonth ddday hhhour mmminute sssecond
Configuring a Multi-Port Tap or Switch
Configuring a Multi-Port Tap or Switch
Setting the Local COM Port for Taps and Switches
Settings for Analyzer Devices
Connecting a Tap with THGs or THGsE
Resetting an Analyzer Device
Updating an Analyzer Device
Click the Reset Host/Image Upgrade button
Advanced Configuration
Customizing Expert Diagnostic Information
Surveyor.ini File
Assigning Names to Protocols Monitor
MONITOR.INI Format
Mapping= port num,short name,long name
Short name
Port num
Long name
MONITOR.INI Examples
Mapping=921,CXP,Company X Protocol
Mapping=6063, XWIN6063,X Windows on port
Mapping=2900,VIDEO,Video Audio Network Communicator
Monitoring Well-Known Ports
How Surveyor Assigns Protocol Names
12. Default Names for Non-WKP UDP Ports
11. Default Names for Non-WKP TCP Ports
Monitoring Non Well-Known Ports
Name TCP port values
Mapping=port num,ip addr,parser name,name Port num
Assigning TCP or UDP Ports to Protocol Parsers
Ip addr
Parser name
Parser Names
Surveyor
Resource Browser
Resources and Modes
Remote Resources
Software
Surveyor
Host Properties Dialog Box for Establishing an Alias
Naming Remote IP Resources Aliases
Resource Protection
Remote User Privileges
Privilege Description
Modes
Settings option from the Module
Hardware Devices
Surveyor Resource Modes Description Resource Type
Hardware Device Capabilities
Synchronized Resources
Hardware Device Capabilities
Ndis
Hints and Tips for Resources
Surveyor
Views
Static Data
Summary View
Module Window Tabs Within Summary View
Tab Description/Action
Vlan
Detail View
Detail View
Using Capture + Monitor Mode in Detail View
Capture View
Capture View Window
Summary Pane
Creating Filters from Capture View
Configuring the Capture View Display
Exporting and Printing Decodes
Display Options
Other Options
Histogram Options
Histogram Display and Button Controls
Histogram Color Coding
Views
Histogram Display Showing Colors
Histogram Display, Large Capture Example
Histogram Default Colors
Histogram Button Controls
Sizing/Selecting Areas with the Mouse
Histogram Mouse Controls
Saving Portions of the Data
Right Mouse Options in the Histogram
Line Graph or Stair Step
Linear Scale or Logarithmic Scale
Resume Analysis
Packet Editor
Packet Editor Buttons
Button Description/Action
Editing in Decode View
Data Views
Editing in Hex View
Ring Statistics View Token Ring Only
MAC Statistics View Capture
MAC Statistics View Rx
Frame Size Distribution View
MAC Statistics View Tx
Protocol Distribution View
Chart
Chart Button Description/Action
Protocol Distribution View, Chart Buttons Protocols
Protocol Distribution View, Chart Buttons Packets
NET
Protocol Distribution View, Graph Type Buttons
Utilization/Error View
Display Button Description/Action
10. Protocol Distribution View, Table Column Descriptions
11. Host Table View, Table Column Descriptions
Host Table View
Network Layer Host Table View
12. Network Layer Host Table View, Table Column Descriptions
Application Layer Host Table View
Host Matrix View
14. Host Matrix View, Table Column Descriptions
15. Network Layer Matrix View, Table Column Descriptions
Network Layer Matrix View
Application Layer Matrix View
Vlan
16. Application Layer Matrix View, Table Column Descriptions
Vlan View
Address Mapping View
17. Vlan View, Table Column Descriptions
Table Column Description
18. Address Map View, Table Column Descriptions
Duplicate Address View Expert plug-in only
19. Duplicate Address View, Table Column Descriptions
Vlan ID
Expert View Expert plug-in only
Application Response Time View Expert plug-in only
Multi-QoS View Multi-QoS software only
Hints and Tips for Using Views
Surveyor
Getting Started with the Filter Interface
Press the Create/Modify Capture Filter
Filter Design window
Available Filter Templates box
Creating Filters with Filter Templates
Add Port Numbers to Custom Filter Templates
Sample Filter Design window is shown below
Protocol and Frame Type
Creating and Applying a Conversation
Station Addresses
ISL, Q+EV2
Apply Conversation to Template Check Box
Traffic Direction Indicator
Selecting Filter Templates
Creating and Applying a Port Number
Defining Port Numbers
Conversation Element Description
Multiple Byte Patterns in Filter Templates
Creating Custom Filter Templates
Custom Templates Based on Pre-Defined Templates
Custom Templates Based on Specification of Byte Patterns
Entering Values that Cross Byte Boundaries
Bit-Level Filtering
Creating Filter Template Combinations
Filter Creation
Operator Buttons for Template Combinations Description
Filter Actions
Not
Template Combination box
Capture Filter Actions
Actions for Capture Filters
Action Description
Packets until the buffer is %% full field
Actions for Display Filters
Counter Conditions for Filters
Display Filter Actions
Frame Types
Global Values that Affect Capture Filter Actions
Capture Filter Global Values
Capture Filter Global Description
Frame types are shown in Table
Multi-State and Multi-Statement Filters
Example Filter States Design Window
Filter Structure
Filter States
Changing States Changing Filter Operation
GoTo Current State
Filter Statements
Capture and Display Filter Differences
Activating Display Filters
Activating Capture Filters
Filter Example, Capture Conversation
Filter Examples
Surveyor
Filter Design Window, Template Combination Example
Filter Example, Template Combination
Surveyor
Filter Design Window, Capture TCP Port Example
Filter Example, Capture TCP Port Traffic
Surveyor
Advanced Filter, Filter States Design Window
Filter Example, Advanced Filter
Rules of the Capture or Display Filter
Hints and Tips for Using Filters
Filtering Tips Unique to THG-class Devices
Transmit Specifications
Transmit Specification
Defined Streams List Box
Transmit Specification Dialog Box
Radio Buttons and Fields for Defining a Stream
Transmit Specification Control Buttons
Transmission Mode and Status Controls
Stream Buttons
Stream Function Buttons
Transmit Specification Control Buttons
Control Button Transmit Specification Function
Repeating Frames
Surveyor
Stream Modes
Stream Mode Rate Setting
Bursts
Stream Modes
Transmission Mode
Specifying Transmit Data
Packet Editor
Packet Editor Button Editing Function
Changing Fields Directly in the Dialog Box
Packet Type
DA and SA Fields
Packet Size
Data Field
Creating Templates
Using Templates
Transmitting Capture Files
Transmit Specification Examples
Transmit Specification Example, Packet Gaps
Transmit Specification Dialog Box, Bursts
Transmit Specification Example, Bursts
Hints and Tips for a Transmit Specification
Surveyor
Alarms
Current Module Alarms
Current Module Alarms
Alarms
Alarm Editor
Alarm Editor Description
Mqos
Multi-QoS Alarms
Expert Alarms
Transport Layer
Data Link Layer, Ethernet
YES
Using Alarms with Different Devices
Thresholds and Alarms
Alarm Actions Description Support by Host Type
Alarm Actions
Mail Settings
Log File Settings
Alarm Actions
Settings
Snmp Trap Settings
Pager Settings
Trap Settings for THGs
Trap Settings for Surveyor Hosts
Hints and Tips for Alarms
Viewing the Alarm List and the Alarm Log
Alarm Example, Utilization
Alarm Examples
Alarm Example, MAC Errors
Alarm Example, MAC Errors
Alarm Example, Frame Size
Alarm Example, Frame Size
Alarm Example, Call Jitter and Call Setup Time
Alarm Example, VoIP Calls
10. Alarm Example, Expert and Application Response
Alarm Example, Expert and Application Response
Surveyor
Expert Features
Getting Started with Expert View
Expert System Views
Application Response Time View
Duplicate Network Address View
Expert Features
Expert Overview Details
Expert Overview Detail Table Example
Layer Description
Expert Layers
Expert Application Layer Example
10-8
Expert Symptoms and Analyses by Layer Expert Analyses
Expert Symptoms, Analyses, and Network Entities
Symptoms
Tables in the Detail Area for Symptoms
Analyses
Tables in the Detail Area for Analyses
Entities
Entities for the Transport Layer Example
Application/Session Lists for Entities
Transport Lists for Entities
Network Lists for Entities
Data Link Lists for Entities
Expert Diagnosis Example
Expert Diagnostic Messages
Working with the Expert System
Configuring the Expert System
Setting Expert Alarms
Module Settings for the Expert System
Exporting Expert Data
Printing Expert Data
Working with Timestamps
Working with Analyzer Devices
Application Response Time
Application Layer
Excessive Mailslot Broadcasts
Rate of change of SMB Mailslot Broadcasts=40
FTP Login Attempts
Expert Symptom
Login attempts=4
Time passed since last announcement=4000 ms 3000 ms
Missed Browser Announcement
Between 00000010.0207012303E3 and 302A9950.000000000001
NCP File Retransmission
NCP Read/Write Overlap
Requests denied within 100 ms=5
NCP Request Denied
Loops on same request in 100 ms
NCP Request Loop
Rate of change of NCP Server Busy=5
NCP Server Busy
File retransmission ratio is 8 / 28 = 28%
NCP Too Many File Retransmissions
Requests denied ratio is 8 / 28 = 28%
NCP Too Many Requests Denied
Requests loops ratio is 8 / 28 = 28%
NCP Too Many Request Loops
NFS Retransmissions
Http Post request not responded
No Http Post Response
Smtp server not responded
No Server Response
Slow Http GET response=3608 ms 2000 ms
Slow Http GET Response
Slow Http Post response=2918 ms 2000 ms
Slow Http Post Response
Slow FTP server connect=298 ms 200 ms
Slow Server Connect
Slow Smtp server response=1258 ms 1000 ms
Slow Server Response
Invalid network name in tree connect
SMB Invalid Network Name
Invalid password
SMB Invalid Password
Session Layer
No Wins Response
Wins request not responded within 1000 ms
Slow TNS server connect=298 ms 200 ms
TNS Slow Server Connect
Slow TNS server response=238 ms 200 ms
TNS Slow Server Response
Idle Too Long
Transport Layer
Station 206.250.228.11 not responding
Non Responsive Station
SA=206.250.228.69 DA=206.250.228.11
TCP Checksum Errors
TCP Fast Retransmission
TCP Frozen Window
10-48
TCP Long Ack
Acknowledgement number is less than the one before
TCP Repeat Ack
TCP Retransmissions
TCP RST Packets
Rate of change of TCP SYN’s=150
TCP SYN Attack
TCP Window Exceeded
Count
Data length of 128 bytes exceeds last window size
Between 206.250.228.69/TCP/IP WKP1988 206.250.228.11/SMTP
TCP Window Probe
Expert Diagnosis
TCP Zero Window
Retransmission ratio is 49 / 50 = 98%
Too Many Retransmissions
Network Layer
Duplicate Network Address
Addr=206.250.228.67
SA=206.250.226.11 DA=206.250.228.69
Hsrp Coup
Hsrp Errors
Hsrp Resign
Parameter Problem
Icmp All Errors
Destination Unreachable
Source Quench Redirect
Icmp Bad IP Header
Cannot be reached by SA=206.250.228.11 DA=206.250.228.69
Icmp Destination Host Access Denied
Icmp Destination Host Unknown
Icmp Destination Network Access Denied
Icmp Destination Network Unknown
Icmp Destination Unreachable
10-69
Icmp Fragment Reassembly Time Exceeded
Icmp Fragmentation Needed D/F set
Icmp Host Redirect
Icmp Host Redirect for TOS
Icmp Host Unreachable
Icmp Host Unreachable for TOS
Addr=206.250.228.69. Subnet mask=255.255.255.240
Icmp Inconsistent Subnet Mask
Icmp Network Redirect
Icmp Network Redirect for TOS
Icmp Network Unreachable
Icmp Parameter Problem
Icmp Port Unreachable
Icmp Protocol Unreachable
Icmp Redirect
Icmp Required IP Option Missing
Icmp Source Quench
Icmp Source Route Failed
Icmp Time Exceeded
Icmp Time to Live Exceeded
Addr=255.255.255.255
Illegal Network Source Address
IP Checksum Errors
TTL=1 SA=206.250.228.69 and DA=206.250.228.11
IP Time to Live Expiring
ISL BPDU/CDP Packets
Vlan ID=1036
ISL Illegal Vlan ID
Ospf Broadcasts
RIP Broadcasts
Rate of change of Router Broadcasts=5
Router Storm
Addr=255.23.252.6
Same Network Addresses
SAP Broadcasts
Total Router Broadcasts
Rate of change of Topology=10
Unstable MST
Addr=0.0.0.0
Zero Broadcast Address
Bad Frames
MAC Layer
Rate of change of Bcast/Mcast Packets=500
Broadcast/Multicast Storms
CRC Frame counter
CRC error with more than 63 bytes
Rate of change of ARP Requests=20
Excessive ARP
Rate of change of Bootp/Dhcp Requests=25
Excessive Bootp
Excessive Broadcasts
Excessive Collisions
Excessive Multicasts
Fragment Frame
CRC error with less than 64 bytes
Addr=FFFFFFFFFFFF
Illegal MAC Source Address
Jabber Frame
CRC error with more than 1518 bytes
Utilization=42%
Network Overload
New MAC Stations
Oversized frame has more than 1518 bytes
Oversized Frame
Overload Frame Rate
Overload Utilization Percentage
Rate of change of Errors=450
Physical Errors
Runt frame has less than 64 bytes
Runt Frame
Addr=00800F13A65B
Same MAC Addresses
Total MAC Stations
Hints and Tips for Expert Features
Summary of Expert Counters and Symptoms
Response Time Alarm editor
Configuration dialog box
Summary of Expert Features
Summary of Expert Features
TOS
ISL BPDU/CDP
Surveyor
TCP RST
Surveyor
Multi-QoS
Protocols Supported by Multi-QoS
Using Multi-QoS with Analyzer Hardware
Multi-QoS User Interface Overview
Call Summary Range Table
All Calls Table
Channel View Table
Summary Range Graphs
Surveyor and Rtcp Jitter Values
Call Tables for a Specific Range
Call Details for a Single Call
Multi-QoS Configuration
Configuring Multi-QoS
Alarm Log Monitor Only
Protocol Type Timeout Value
Refresh Options MQoS Window Management
Call Filtering with Multi-QoS
Multi-QoS Performance Optimization
All Calls Table
H323
Red Phone
All Calls Table Field Descriptions
Field Descriptions for All Calls Table
Call Range Graphs and Summaries
Call Jitter, Call Rtcp Jitter, Call Setup Time
Multi-QoS Configuration, Call Jitter Ranges
Multi-QoS Packets Dropped Graph Example
Dropped Packets, Rtcp Dropped Packets
Multi-QoS Configuration, Packets Dropped
Call Range Summary Field Descriptions
Field Descriptions for Call Range Summaries
VQMon Metrics
Multi-QoS R-factor Example
Ranges for R-factors Network R-factor User R-factor
Multi-QoS Configuration, R-factor Ranges
10. Multi-QoS Utilization Graph Example
Utilization Graph
11. Example Call Details Window H.323
Field Descriptions for Call Details
FID
Sccp Call Field Descriptions
Field Name Description
H.323 Call Field Descriptions
SIP Call Field Descriptions Field Name
10. Unknown Call Field Descriptions
Channel Table Details
12. Channel Table Example
11. H.323, SIP, or Unknown Channel Table Column Descriptions
Multi-QoS
12. Sccp Channel Table Column Descriptions
Filtering on Single Channels
Call Playback
Playback PCMU/PCMA Data
Customizing All Calls or Range Summary Tables
Customizing Multi-QoS Table Displays
14. Multi-QoS Channel Table View Options, Sccp Example
Customizing Channel Tables
Exporting Multi-QoS Data
Exporting All Multi-QoS Data to CSV Format
Choose Export Multi-QoS Data... from the File menu
Exporting a Single Multi-QoS Table to CSV Format
11-34
Packet Counters
MAC Layer Counter Types
Counter Type Description
Custom Counters
Error Counters
Counters
Last frame received
Expert Counters
Network Unknown, Destination Host Unknown, Destination Net
Overload Utilization Percent
Surveyor
Counter Log File Overview
Multi-QoS Counters
Log Directory Structure
Utilities
Name Table Utility
Utilities
Building a Name Table From the Network
NIS2NAM output-name-table
NIS-to-Name Table Conversion Utility
Internet Advisor Translator Utility
Sniffer Translator Utility
Get Version Information Utility
Sniffer Translator Utility, Tool Menu Options
Convert Capture Files to Histogram Files
Merge Histogram Files
From the Tools menu, choose Merge Histogram Files
Logging Utilities
Extract Frames From a File Using a Filter
Export Utilities
Exporting Packets
Exporting to Optimal CSV Format
Exporting Tables to CSV Format or Graphs to a Bitmap
Choose Export to Optimal Performance from the File menu
Exporting Counter Log Files to Excel
13-11
13-12
How Resources Use Buffers
Buffers
Table A-1. Buffer Types Used By Surveyor
Buffer Type Description
Resource Buffer Usage
Table A-2. Resource Use of Buffers
Hardware Dependencies
Table A-3. Hardware Real-Time Functions
Table A-4. Hardware Transmit Functions
Table A-6. Hardware Connectivity
Table A-5. Hardware Capture Functions
Captured Packets
About Ndis Mode
Capture Rate / Transmit Speed
Counters
Ndis Configuration Options
Setting the Interface
Set Capture Buffer and Packet Slicing Size
Filter Templates
Pre-Defined Filter Templates
Macdabroadcast
ARP
HEX Fffffffffff
Macdamulticast
Icmp
Eigrp
Igmp
DEC
RIP IPX
Rsvp
SAP IPX
FTP
DNS TCP
Http
Imap
Smtp
Sccp
TCP
Telnet
DNS UDP
Dhcp
Mgcp UDP
NB-DATAGRAM
RIP UDP
NTP
SIP
Snmp
HEX
Dsap
HEX F0F0
HEX E0E0 Nmpi
HEX AAAA03
Snap
Snaparp
Snapcdp
Isldns TCP
Islarp
Isleigrp
Islftp
HEX Ffffffffffff
Islldap
HEX 01005EFFFFFF
Islmgcp TCP
Islssp
Islsmtp
Isltcp
Isltelnet
HEX 0C
HEX 0D
HEX 0B
HEX 2A
HEX 0E
HEX 0F
Nonmac
Function Keys
Keyboard Shortcuts
Standard and Navigational Keys
Keyboard Shortcuts
Surveyor
Table D-1. Parser Names, DLC Suite
Recognized Parser Names
Parser Name Protocol
Table D-2. Parser Names, Applications and Others
Table D-3. Parser Names, Apple Talk Suite
Parser Name Protocol Name
Table D-4. Parser Names, Banyan Suite
Table D-5. Parser Names, Cisco Suite Protocol Name
Table D-6. Parser Names, DECnet Suite Protocol Name
Table D-7. Parser Names, Fujitsu Suite Protocol Name
Table D-9. Parser Names, Internet Suite
Table D-8. Parser Names, IBM Suite
Table D-9. Parser Names, Internet Suite Protocol Name
Table D-11. Parser Names, Netware Suite
Table D-10. Parser Names, Internet Next Generation Suite
Table D-13. Parser Names, XNS Suite Protocol Name
Table D-12. Parser Names, PPP Suite Protocol Name
Table D-15. Parser Names, ITU Codecs
Table D-14. Parser Names, H.323 Suite
Table D-17. Parser Names, Other Multimedia Protocol Name
Table D-18. Parser Names, Intel Suite Protocol Name
Table D-19. Parser Names, VPN Suite Protocol Name
Surveyor
Glossary
Alarm Browser
Avvid
Capture Mode
Dram
Expert View
Log Files
Ndis
NIS
Pause
Sccp
Token Error
Transmit Specification
WKP
Index
Index-2
Index
Index-4
Index-5
Index-6
Index-7
Index-8
Index-9
Index-10
Index-11
Index-12
Index-13
Index-14