Article ID: 812953 - Last Review: October 30, 2006 - Revision: 2.1 How to use Network Monitor to capture network trafficOn This PageSUMMARYThis article discusses several best practices to use when
you use Microsoft Network Monitor (Netmon.exe) to capture network traffic.
A network trace that has any of the following characteristics may prevent the successful analysis of captured network traffic:
DefinitionsThe following definitions are used in this article:
Making the Target Computer Traffic Available to the Monitor ComputerIf you are not running Network Monitor on the target computer, make sure that all the network traffic from the target computer is available to the network adapter of the monitor computer. To do so in the Ethernet environment, connect both the monitor computer and the target computer to a network hub. If the monitor and target computers are on a switched network (for example, they are connected to an Ethernet switch), all the network traffic to and from the target computer may not be available to the monitor computer.Note Typically, a hub presents all the network packets to all the network interfaces (or ports), and a switch presents all the packets to the intended port. More complex switches may permit options for multicast packet filtering and advanced port-to-port bridging for network captures and monitoring. Address DatabasesTo find and save the target computer addresses:Post-Capture Address Collection
Saving an Address DatabaseAddress database files may become inaccurate if the target computer address changes. This may occur if the Dynamic Host Configuration Protocol (DHCP) lease expires or you replace the network adapter. Therefore, Microsoft recommends that you save address databases specific to Network Monitor captures.To save the Network Monitor in-memory address database to an .adr file:
Pre-Capture Address Collection: Target Computer Is on the Network
Pre-Capture Address Collection: Target Computer Is off the NetworkTo use the following procedure, you must know the target address. Microsoft recommends that you use the media access control (MAC) address of the target computer. Capture filters set for specific protocols, such as IP, may cause Network Monitor to ignore other protocol traffic such as IPX/XNS.
Capture FiltersThe following examples illustrate how to configure several common capture filters. Microsoft recommends that you set the filter for the MAC address of the target computer (such as the ETHERNET address), if possible. Capture filters set for specific protocols, such as IP, will cause Network Monitor to ignore other protocol traffic, such as IPX/XNS.Capture all Traffic to and from a Target Computer
Capture all Traffic Between Two Target Computers
Saving a Capture FilterTo save a Network Monitor capture filter to a .cf file:
Capture BuffersBy default, Network Monitor can save captures of up to 1 gigabyte (GB). To change the default setting of 1MB, click Buffer Settings on the Network Monitor Capture menu.
Capture TriggersCapture triggers are typically set for situations where it is difficult to keep from overrunning the capture buffer. This frequently occurs if any of the following conditions are true:
The example error message is the WIN32 error code 0xC00000CC. The error code appears in a capture in the SMB 'Status Code System Error' field as 'STATUS_BAD_NETWORK_NAME'. This error is defined in 'ntstatus.h'. The Microsoft Software Development Kit (SDK) includes this definition. For additional information, visit the following Microsoft Web site: http://www.microsoft.com/msdownload/platformsdk/sdkupdate/
(http://www.microsoft.com/msdownload/platformsdk/sdkupdate/)
For additional information, click the
following article number to view the article in the Microsoft Knowledge Base: 113996
(http://support.microsoft.com/kb/113996/EN-US/
)
INFO: Mapping NT Status Error Codes to Win32 Error Codes
Troubleshoot
REFERENCES
For more information, click the following article numbers to view the articles in the Microsoft Knowledge Base:
810156
(http://support.microsoft.com/kb/810156/
)
'No Network Drivers Were Found' Error Message After You Install Network Monitor
261327
(http://support.microsoft.com/kb/261327/EN-US/
)
How to Add an Additional Parser to Network Monitor
164961
(http://support.microsoft.com/kb/164961/EN-US/
)
Network Monitor Setup Doesn't Find Previous Version Installation
For additional information about the Network
Monitor Capture utility included with Windows XP, click the following article
number to view the article in the Microsoft Knowledge Base: 310875
(http://support.microsoft.com/kb/310875/EN-US/
)
Description of the Network Monitor Capture Utility
| Article Translations
|
Back to the top
