Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

Astute Observer



By Mandy Andress
May 03, 2002
 

AS WLANS (WIRELESS LANS) continue to be deployed throughout the enterprise, administrators need tools to help them audit wireless network installations, analyze performance, and identify security issues. One of the big security issues facing wireless networks today is the of rogue access points that employees may install on the network, exposing the organization's network and data to unauthorized users and malicious hackers.

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft



Observer Suite 8.1

Network Instruments, networkinstruments.com

Deploy  8.0
criteria score
Ease-of-use 9
Implementation 8
Innovation 8
Interoperability 8
Scalability 8
Security 8
Suitability 9
Support 9
Training 8
Value 9

Business Case:
This all-in-one network analysis tool would provide excellent value to any organization. Online reporting capabilities allow managers to quickly see performance reports at any time.

Technology Case:
Stable drivers allow Observer to be used on any system, including an administrator's laptop for quick troubleshooting. Historical trending and reporting provides useful data that can help pinpoint problems.

Pros:
+ Includes analyzers for wired and wireless networks in one product
+ Stores all historical data and creates trending reports
+ Provides powerful expert analysis
+ Includes SNMP probes


Cons:
- Works only with selected wireless cards


Cost:
$3,995

Platforms:
Runs on Windows 2000 and XP; supports Cisco, Symbol, Nortel, and Intel cards

About our Reviews and Scoring Methodology

Network Instruments' Observer line of software provides administrators an easy way to monitor wireless networks and help pinpoint those rogue access points. Observer comes in three flavors -- Observer, Observer Expert, and Observer Suite -- with Expert and Suite adding functionality such as real-time expert analysis and SNMP probes, respectively. We tested Observer Suite 8.1, and it displayed an ease-of-use and low price point that helped earn it a Deploy rating.

Observer is a protocol analyzer, similar to products offered by Sniffer and WildPackets. With the introduction of wireless capabilities, Observer has become one of the better protocol analyzers we have seen. The biggest plus for Observer is that the product includes all the components you need to analyze wired, fiber optic, and wireless networks; other analyzers typically focus on either wireless, wired, or fiber.

Another excellent feature of Observer is its ability to keep trend data. Observer stores all data captures and can use them to create trend reports and analyze data over periods of time. Observer Suite also includes a built-in Web server to make reports available remotely, providing a Web site for managers or executives to easily monitor network performance.

For managers of wireless networks, Observer can be a valuable tool. In addition to performing the standard packet decoding and analysis, Observer can also identify rogue users and access points as well as WEP (Wired Equivalent Privacy) misuse. The best way to identify rogue systems is to configure a list of valid MAC (Media Access Control) addresses for your organization's wireless devices and filter them out. Based on such a list, Observer can alert you to devices with invalid MAC addresses that are accessing the network. Observer also analyzes WEP configurations and can alert administrators if an access point is found with WEP disabled or without the proper configuration. This helps enforce the company's wireless security policy.

As with any wireless analysis tool, wireless NIC (network interface card) support is an issue. Many of these tools require their own special drivers that are suitable only for auditing the network. For example, Netstumbler works with Lucent or Compaq cards, while ISS Wireless Scanner supports only the Compaq WL110 NIC.

Furthermore, many WLAN analyzer vendors develop their own drivers from scratch, and these may not work properly in everyday use. Consequently, administrators without dedicated monitoring hardware may be required to reinstall the wireless NIC vendor's drivers to return to normal wireless network functionality.

Network Instruments takes a different approach than most, adding layers to existing wireless card drivers. Based on our experience with Observer, this avoids sacrificing everyday functionality for the sake of monitoring the WLAN.

We installed Observer Suite on a Windows 2000 SP2 laptop using a Cisco Aironet 350 wireless card. We installed Network Instruments' driver for the card and did not have any issues using the card as we normally do every day. Firing up Observer, we watched the activity on our wireless network, which included five Agere Orinoco access points. We monitored wireless traffic, WEP use, and access point utilization. To test Observer's ability to spot rogue access points, we added an Intel access point to the network and created a filter for our authorized Agere access points. Observer passed the test with flying colors, successfully providing us a list that included our Intel access point -- and some access points in the neighboring office.

Although not specifically designed for wireless security auditing, Observer is a versatile tool that can add value to any organization. Its ease-of-use and low cost make it an ideal candidate for that administrator trying to gain control of an ever-expanding wireless world.





 

TOP NEWS:


»  Vodafone acquires social-networking platform company
Danish company ZYB's social networking and online management tool for backing up and sharing information online works on mobile phones

»  Apple's iPhone may face uphill battle in some regions
Plans to sell the iPhone in the Middle East, and Africa might prove to be a challenge

»  Fujitsu tackles e-paper's slow screen speed
Fujitsu has improved its e-paper refresh speed by confining the refresh to just the parts of the screen that need to be changed

»  Windows coming on dual-boot OLPC
XO laptop that will have both the Linux-based Sugar OS and a low-cost student version of Windows XP is expected in August or September

»  More than 200,000 demand Microsoft save XP
InfoWorld's petition to keep the popular Windows version on the market has passed a new milestone

»  You don't know tech: The InfoWorld news quiz
Match your weekly tech news wits against our snarky quiz master




Virtualization: A Step by Step Approach to Success
Your virtual machines can be up and running in a matter of minutes. HP and Citrix have integrated XenServer with HP ProLiant servers and management tools, powered by hardware-assisted Intel Virtualization Technology to enable high- performance, cost-savings solutions for server consolidation and disaster recovery. Sponsor: HP

»  Click here to view this Webcast
  The Data Protection You've Been Looking For
Enterprise data is of supreme importance. If you can't find it quickly, it's worthless. If you lose it, it's a crisis. This IT Strategy Guide explores how to keep your data safe.

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 
  • Virtually Limitless Virtual Storage - Do you need virtualization space savings of 50% or more with virtually no performance impact? You might be able to get storage...
  • Invisible IT? - The goal of IT is to become an invisible entity within a larger organization. Eliminating visibility and road blocks IT ...
  • It Really Is Easy to be Green - "Green IT" is a popular concept. And IT organizations are learning the influence that IT purchase decisions have on data...
  • Key Strategies For SOA Testing - SOA requires a unique approach to testing. Unless you're willing to reorient your testing procedures and technology now,...
  • The Missing Piece of Virtualization - Server virtualization saves money and increases flexibility. But, challenges exist as I/O-intensive applications like databases...
  • Prevent Your Next Microsoft Exchange Outage - E-mail is mission critical, so why only back up data and not the entire e-mail infrastructure? Continuous application protection...

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS  IT EXEC-CONNECT   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist