Commview Manual
Total Page:16
File Type:pdf, Size:1020Kb
TAKE CONTROL IT'S YOUR SECURITY df TAMOSOFT CommView® Network Monitor and Analyzer for Microsoft Windows Help Documentation Version 6.5 Copyright © 1999-2015 TamoSoft Contents Contents ........................................................................................................................................................ 2 Introduction .................................................................................................................................................. 4 About CommView ..................................................................................................................................... 4 What's New ............................................................................................................................................... 5 Overview ................................................................................................................................................... 8 Selecting Network Interface for Monitoring ........................................................................................... 11 Latest IP Connections .............................................................................................................................. 13 Packets .................................................................................................................................................... 16 Logging .................................................................................................................................................... 19 Viewing Logs ............................................................................................................................................ 21 Rules ........................................................................................................................................................ 23 Advanced Rules ....................................................................................................................................... 28 Alarms ..................................................................................................................................................... 31 Reconstructing TCP Sessions ................................................................................................................... 35 Reconstructing UDP Streams .................................................................................................................. 41 Searching Packets .................................................................................................................................... 42 Statistics and Reports .............................................................................................................................. 43 Using Aliases ............................................................................................................................................ 47 Packet Generator .................................................................................................................................... 48 Visual Packet Builder ............................................................................................................................... 50 NIC Vendor Identifier .............................................................................................................................. 52 Scheduler ................................................................................................................................................. 53 Using Remote Agent ................................................................................................................................ 54 Using RPCAP ............................................................................................................................................ 57 Capturing Loopback Traffic ..................................................................................................................... 58 Port Reference ........................................................................................................................................ 59 Setting Options ........................................................................................................................................ 60 Frequently Asked Questions ................................................................................................................... 66 VoIP Analysis ............................................................................................................................................... 69 Introduction ............................................................................................................................................ 69 Working with VoIP Analyzer .................................................................................................................... 70 SIP and H.323 Sessions ............................................................................................................................ 71 2 Contents | CommView RTP Streams ............................................................................................................................................ 73 Registrations ............................................................................................................................................ 75 Endpoints ................................................................................................................................................ 76 Errors ....................................................................................................................................................... 77 Call Logging .............................................................................................................................................. 78 Reports .................................................................................................................................................... 79 Call Playback ............................................................................................................................................ 80 Viewing VoIP Logs ................................................................................................................................... 82 Working with Lists in VoIP Analyzer ........................................................................................................ 83 NVF Files .................................................................................................................................................. 85 Advanced Topics.......................................................................................................................................... 86 Capturing High Volume Traffic ................................................................................................................ 86 Working with Multiple Instances ............................................................................................................ 87 Running CommView in Invisible Mode ................................................................................................... 88 Command Line Parameters ..................................................................................................................... 89 Exchanging Data with Your Application .................................................................................................. 91 Custom Decoding .................................................................................................................................... 93 CommView Log Files Format ................................................................................................................... 95 Sales and Support ........................................................................................................................................ 97 3 Contents | CommView Introduction About CommView CommView is a program for monitoring Internet and Local Area Network (LAN) activity capable of capturing and analyzing network packets. It gathers information about data passing through your dial-up connection or Ethernet card and decodes the analyzed data. With CommView you can see the list of network connections and vital IP statistics and examine individual packets. Packets are decoded down to the lowest layer with full analysis of the most widespread protocols. Full access to raw data is also provided. Captured packets can be saved to log files for future analysis. A flexible system of filters makes it possible to drop packets you don't need or capture only those packets that you wish to capture. Configurable alarms can notify you about important events, such as suspicious packets, high bandwidth utilization, or unknown addresses. CommView includes a VoIP module for in-depth analysis, recording, and playback of SIP and H.323 voice communications. CommView is a helpful tool for LAN administrators, security professionals, network programmers, or anyone who wants to have a full picture of the traffic going through one's PC or LAN segment. This application requires an Ethernet or Wi-Fi network card, or a standard dial-up adapter. CommView features an advanced protocol decoder that can parse over a hundred widely used network protocols. In addition, our new remote monitoring technology allows CommView users to capture network traffic on any computer where Remote Agent is running, regardless of the