An acute observer of LAN behaviour

The latest version of the Observer packet analyser can now troubleshoot MPLS systems

Written by Dave Bailey

Larger Image

Network Instruments’ Observer family of application performance troubleshooters was updated earlier this year to give enterprises the capability to troubleshoot multi-protocol label switching (MPLS) streams. Other new features in Observer 12 include improved multi-hop analysis, which can check performance issues, such as high router and switch latency, and can be used to lessen excessive jitter on IP telephony deployments, improving call quality.

Observer 12 is available in three versions offering different levels of functionality: Standard, Expert and Suite. The Standard version is designed for run-of-the-mill protocol analysis and troubleshooting. The Expert version includes the multi-hop analysis feature as well as the capability to analyse the performance of large enterprise applications, such as SQL databases, and integrate with HP’s OpenView enterprise management package.

Observer Expert can also process information from NetFlow- and sFlow-enabled switches. NetFlow is a Cisco protocol for collecting IP traffic, while sFlow has been used for similar IP traffic collection on other vendors’ network hardware, including Alcatel, Extreme, Foundry and HP ProCurve.

The full Observer Suite adds Simple Network Management Protocol (SNMP) device management, network trending and reporting, and a web publishing service that can give IT managers and other technical executives network health reports on their firm’s intranets or extranets.

The working install on a fresh Windows XP Professional system was simple, although it required two reboots: one after the program was installed; and another after Observer 12 allocated a user-specifiable amount of system memory as a buffer in which to store network packet data.

A test access point (TAP) was also required to properly take network packets from our test network. A TAP is a piece of hardware that copies traffic from full-duplex network ports and connects to a console to give a real-time display of all the network traffic traversing that link. Network Instruments supplied one of its aggregator TAPs, which can be connected to a PC or operate as a standalone system.

TAPs are taking over from Switched Port Analysers as they are much better at dealing with Gigabit Ethernet and 10 Gigabit Ethernet (10GbE) systems, and Network Instruments can even supply a TAP with optical fibre connections.

Although we could check performance of a local-area network (LAN) with several servers and client systems, firms with large enterprise systems with fast wide-area network (WAN) connections, 10GbE connections and optical fibre-connected storage area networks (SANs) will require extra hardware. Network Instruments can supply gigabit and 10GbE probe appliances, as well as the GigaStor, an appliance that can capture up to 48TBs of gigabit-speed network traffic.

After we had set up the system memory buffer, the drivers for our network interface cards (NICs) and wireless PC cards had to be updated. The reason for this is that although the drivers normally shipped with NICs or wireless cards ­ so-called network driver interface specification (NDIS) ­ can tell you how many error packets are seen on the network, these error packets are not processed or passed. Observer ships with drivers that can be easily installed to pass these error packets to the main Observer console. Observer 12 supports 802.11a/ b/g networks, but not pre-draft 802.11n networks.

Easy troubleshooting

Starting the Observer console up, we could run a SQL query against the Microsoft SQL Server 2005 database we set up on our Windows Server 2003 and check the response times we obtained. As expected, these were normal, but firms using a centralised headquarters database with branch offices downloading large chunks over WAN connections with less than optimal bandwidth and latency should easily be able to see problems.

The Observer 12 graphical user interface (GUI) has evolved gracefully over time and we found it an easy and powerful system with which to record and save packet data and then use the Observer Expert probe to analyse the file retrospectively, if required.

Observer 12 can show standard “top talkers” statistics, the network protocol distribution seen by the system, network packet size distribution, as well as virtual LAN (VLAN) statistics. It can also be used to generate network traffic to test network hardware performance and traffic flow through companies’ network infrastructure.

Observer 12 comes with a full set of alarms and triggers that can alert users to problems in real time or, alternatively, can be sent to admins via a paging service that can use Ethernet or dial-up through an onboard modem. It was easy to set up an alarm for duplicate IP addresses or unknown IP addresses. We also set up an alarm to trigger a pager message if network utilisation averaged 50 per cent over a prescribed interval.

Overall, Observer 12 is suitable for any size or enterprise that is looking for a comprehensive system for monitoring and troubleshooting network-attached hardware and applications. One of the few complaints that can be levelled at it is that a high level of technical expertise is required to set up and run the system properly, but this also applies to all comparable systems on the market.

The systems competing with Observer 12 include WildPacket’s OmniAnalysis platform, NetScout’s nGenius system, and Network General’s Sniffer and NetVigil products. The proposed takeover of Network General by NetScout could provide even tougher competition for Network Instruments, and Fluke Networks’ acquisition of Crannog software earlier this year will mean further competition in the enterprise performance management arena.

For smaller enterprises, there is also the open source Wireshark package, which, although less polished, offers enough features for experts to perform an excellent job of troubleshooting less complex networks. Wireshark also runs on Linux and Unix systems.

Tags:

Product overview

Ratings

  • Our rating: 4
  • Average user rating:

Verdict

Observer Suite 12 improves on an already fine system for application performance troubleshooting and network packet analysis.

Pros: Can now troubleshoot MPLS systems; comprehensive hardwareprobes exist for most types of network equipment.

Cons: OS support limited to XP Professional and Windows Server 2003; Draft 802.11n not supported

Best prices

reader comments

related articles

Growth of VoIP boosts EPM prospects

As more real-time apps are run over networks, enterprise performance management tools are becoming vital 03 Oct 2007

 

Spirent reinvents testing tool

Spirent TestCenter 2.0 enables a "step change in performance" 04 Jun 2007

GroundWork aims at enterprise network monitoring

Open source monitoring firm launches enterprise grade products 26 Mar 2008

Network management increasingly challenging

Research indicates application performance problems are on the rise 01 Apr 2008

Packeteer releases new WAN management platform

Packeteer's WAN management platform will let firms monitor application performance 05 Dec 2007

today's top stories

Analysis: The true cost of printing

Organisations need to get a better sense of how much they spend on printing before finding ways to reduce it 05 Sep 2008

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Looking to the future - exclusive Michael Dell interview

Dell's chief executive talks to Computing about the way the company continues to adapt to major changes in the industry 04 Sep 2008

Interview: Delivering power where it's needed at Betfair

The online gambling firm is putting its money on grid computing and virtualisation to underpin global expansion 04 Sep 2008

E-paper displays are an open book

A display revolution is on the way - but only once the user interface issues are solved 04 Sep 2008

Most commented stories

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use a mobile phone as an alternative to cash?

Would you use a mobile phone as an alternative to cash?

When mobile phones include inbuilt payment technology - would you use one instead of cash?

Previous poll results

Latest audio and video articles

BlackBerry BoldVideo

Video Review: BlackBerry Bold

Technology editor Daniel Robinson takes a hands-on look at the latest device from Research in Motion 01 Sep 2008

Podcast imageAudio

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Latest in-depth articles

A meetingAnalysis

Turning adversity into an advantage

IT chiefs under pressure to make cost cuts can turn the situation to their benefit 04 Sep 2008

CloudAnalysis

How to introduce cloud computing into your organisation

Best practice advice from Forrester Research 04 Sep 2008

Primary Navigation