Packet capture and analysis is crucial for managing large and small-scale networks. Tools to capture and replay are often useful for service providers who wish to make field captures of malignant behavior and want to carefully reproduce them in a lab.
Recorded high speed data can be used not only for examining each packet in real-time, but also examining trends across packets or streams of related packets to predict potential issues or potential illicit activity. Playing back the recorded high speed data can recreate the real-time packet network in the lab for further diagnosis.
GL’s Packet Recorder and Playback application allows Playback and Record modes of operation simultaneously. In Record mode, high rate real-time traffic can be recorded with precise hardware time stamping. The Record feature includes a powerful Hardware Filter that allows user to filter out unwanted traffic, and continuously capture the traffic of interest. The limitation being only the hard disk size and the disk write speed. The application supports file formats such as PCAP (Wireshark® format), HDL (GL Proprietary format), and 3GDAT (GL HD Proprietary format).
In Playback mode, you can re-transmit or playback the recorded traffic file on selected network interface ports, and further analyze this using any packet analyzer such as GL’s PacketScan™. Live traffic captured on a network using the Recorder utility, PacketScan™, or Wireshark® can be easily recreated in the lab.
The Packet Recorder and Playback application is designed to be used as an Add-on software with GL’s PacketScan™ HD network appliance with HD NIC of 1 GigE, 20 GigE and 40 GigE adapters and deployed at critical locations in IP networks to detect problems and avert them.
The traffic captured on a live network using packet analyzers such as PacketScan™-All IP analyzer or Wireshark® can be easily recreated in the lab using Playback feature.
- Packet Recorder:
- Captures 100% packet data on high speed lines (maximum of 5 Gbps data rate)
- Capture packets non-intrusively over Ethernet (Electrical) and Optical ports at Nano-second precision
- Recording can be done on single port or combination of one or more ports. Multiple instances of recorder can run simultaneously.
- Flexible options to record traffic continuously based on File size, File count, Frame count and Duration.
- Record only traffic-of-interest by applying hardware filters – up to 10 hardware filters can be defined for each port
- Create up to 10 user defined hardware filters to filter-out traffic based on MAC, 802.1Q (VLANs), IPv4 /IPv6, TCP, UDP, SIP, and RTP parameters
- Supports both IPv4 and IPv6
- Provides statistics of captured frame count, dropped frame count, recorded frame count capture rate, frame rate, recorded files count, and more.
- Playback File:
- Replay the pre-recorded traffic files at the same rate at which it is captured (maximum of 5 Gbps data rate)
- Provides options to playback single file or multiple sequential files.
- ‘Replay as per File’ option allows to playback the traffic in the same way as it was captured.
- Provides statistics of total frames transmitted, under sized frames count, oversized frames count and different sized frame count etc.
- Provides general statistics, per port statistics and aggregated statistics to help check the progress of the recorder and playback operations.