When it comes time to dissect a network problem, whether the problem is related to security or performance, a deep look into all the network activity surrounding the incident can be critical to resolving the issue. An intrusion detection system, with its rules for capturing problematic network events, can be of some help, but for real problem diagnosis or forensics, you need more. Network Instruments' GigaStor is designed to meet that need with full traffic capture that extends backward to hours or days. This "keep it all" capability makes the GigaStor a valuable addition to any network for which high performance, security, or regulatory compliance are critical issues. When you need to investigate a network slowdown, a security breach, or anything else that happened on your network, if you know when it happened, then GigaStor can take you there.
| Click for larger view. |
Interestingly, Observer isn't the only piece of the GigaStor solution that runs on Windows. Whereas most network and security appliances use Linux as the embedded OS, the GigaStor sits on Windows XP 64. When I asked why Network Instruments chose Windows XP 64 as the platform, I was told that it had to do with their developers' experience -- an absolutely valid reason for reaching a decision. In our testing, we had no issues with the device, no concerns about performance, and no problems with the operating system. I give you this information because it's unusual -- not because it was a problem.
The roughest part of installing the GigaStor was picking up the box to install in the rack. After the hard disks were installed in the chassis and various cables plugged in, I moved straight to software setup. I began by discovering the network devices. For the GigaStor system this is a passive activity performed by listening to network traffic, not scanning ports. This is a good thing if you aren't the Tripwire jockey for your network. After I built an accurate description of our test network, I began to set up filters for the activities and the criteria I wanted to set for alarms. The Observer software allows you to include or exclude traffic based on packet type, addresses, address pairs, traffic level, behavioral rules, and most other factors that can reasonably be considered for this kind of task.
Remember that time at 23:49?
| Test Center Scorecard | |||||||
|---|---|---|---|---|---|---|---|
| 20% | 20% | 20% | 15% | 15% | 10% | ||
| Network Instruments GigaStor | 8 | 9 | 9 | 9 | 8 | 8 |
8.6
Very Good
|
This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.
Download now »Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.
Download now »
The emergence of WLANs has created a new breed of security threats to enterprise networks.
Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation
Effectively address data protection challenges, implementing solutions that help store and protect businesscritical data while cutting costs and improving efficiency and reliability.
Download now »
Sign up to receive InfoWorld Resource Alerts
