Hi
I added Packet Sniffer Sensor and through it choose other TCP and Other UDP Channel traffic .when I want to monitor I see high traffic pass through these 2 channels but not http and https I have two questions:
- other udp and other TCP means using internet or it is possible that it is in local network?
- how can I understand which port(Software ,Web service,..) is used in Other TCP/UDP
Thank you
Article Comments
Hi
I mean is there anywhere in Packet Sniffing(channel other UDP/TCP) inside this sensor that shows automatically(without adding port and addresses manually ) where the client (a computer that remote probe is installed on it) is visited(port or IP address), this shows where traffic is used for example: inside Local LAN (Shared folder, Local addresses ,...) or on internet(except http,https). Finally is it possible to say the only channel on this sensor that shows used traffic on internet is HTTP and HTTPS or other UDP/TCP also included if so how is it possible to distinguish how much internet traffic used in other TCP/UDP channel is for internet and how much is for Local Network?
Thanks a lot for your Patient.
Feb, 2016 - Permalink
Hello,
I am afraid that it is not possible to get those information automatically in the Packet Sniffer sensor.
Under sensor Settings -> Channel Configuration -> Channel Selection, you can choose the option 'Detail', so each 'Content' will be visible as one sensor channel. For example, for WWW traffic there will be two channels - HTTP and HTTPS.
However, if you want to obtain more specific details, you will need to apply filter rules: https://helpdesk.paessler.com/en/support/solutions/articles/7600006351183-what-filter-rules-can-be-used-for-custom-packet-sniffing-flow-or-ipfix-sensors
Best regards
Feb, 2016 - Permalink
Hello,
The channel "Other Protocols" (OtherUDP, OtherTCP) includes all traffic that does not belong to any of the other channel definitions in use.
For more information on how to filter OtherUDP/OtherTCP traffic, please have a look at this article: https://helpdesk.paessler.com/en/support/solutions/articles/76000063511033-what-does-the-othertcp-sensor-include
Best regards
Feb, 2016 - Permalink