NetVisualyzer supports many network protocols. Packet headers for supported protocols can be fully decoded by Analyzer and NetSnoop, and information about packets using supported protocols is available from NetAccount, NetGraph, and NetTop. In addition, other protocols are recognized, although not fully decoded, by NetVisualyzer tools.
This appendix lists the protocols supported and partially supported by NetVisualyzer tools and contains diagrams showing how these protocols relate to one another. You can use this information to create filters to capture the protocol packets of interest to you. This chapter also provides references for further information about the protocols.
You can see a list of protocols supported by NetVisualyzer tools by giving the command:
netsnoop -L all |
Table C-1 lists fully supported protocols. It contains protocol name acronyms, the names used by NetVisualyzer tools, and the full protocol names. Where available, the RFC sources for the protocols are listed.
Table C-1. Supported Protocols
Protocol Name | NetVisualyzer Name | Description |
|---|---|---|
AARP | aarp | |
ADSP | adsp | |
AEP | aep | |
AFP | afp | |
ARP | arp | |
ARPIP | arpip | |
ASP | asp | |
ATP | atp | |
BOOTP | bootp | |
DDP | ddp | |
DECnet | decnet | |
DNS | dns | |
ECHO | echo | |
ELAP | elap | |
ERROR | error | |
Ethernet | ether | |
FDDI | fddi | |
FTP | ftp | |
HELLO | hello | |
ICMP | icmp | |
IDP | idp | |
IGMP | igmp | |
IPX™ | ipx | |
IP | ip | |
LAT™ | lat | |
LLC | llc | |
MAC | mac | |
NBP | nbp | |
NFS | nfs | |
NLM | nlm | |
NSP | nsp | |
PAP | pap | |
PEP | pep | |
Portmap | pmap | |
RARP | rarp | |
rcp | rcp | |
RIP | rip | |
RIP | novellrip | |
RIP | xnsrip | |
rlogin, rsh | rlogin | |
RTMP | rtmp | |
SMT | smt | |
SNMP | snmp | |
SPP | spp | |
SPX | spx | |
SunRPC | sunrpc | |
TCP | tcp | |
TELNET | telnet | |
TFTP | tftp | |
Token MAC | tokenmac | |
Token Ring | tokenring | |
TSP | tsp | |
UDP | udp | |
XTP | xtp | |
ZIP | zip |
Table C-2 lists the protocols that are partially supported by NetVisualyzer. Analyzer and NetSnoop recognize these protocols, but don't decode them. These protocols are fully supported by the other NetVisualyzer tools.
Table C-2. Partially Supported Protocols
Protocol Name | NetVisualyzer Name | Description |
|---|---|---|
NetBIOS™ | netbios | |
OSI | osi | |
SMTP | smtp | |
SNA | sna | |
VINES® | vines | |
X | x11 |
This section contains diagrams showing the supported protocols listed in Table C-1 and Table C-2 and their relationships to each other. In these diagrams, arrows pointing up indicate that the layers above this protocol are shown in a diagram later in this section.
These diagrams are useful when constructing filters since each protocol must be completely specified except for its physical layer. These diagrams also show all of the packet types that are captured by Analyzer and other tools if you specify a lower-level protocol as a filter. For example, if you use ip.tcp (or the macro tcp) as a filter in Analyzer, the Type column in the Summary pane can show rcp, rlogin, telnet, and other protocols as well as tcp. You find out the complete list of possible protocol types by looking at Figure C-8 and noting the protocol layers above tcp.
Figure C-1 shows the Snoop pseudo-protocol, snoop, and the three physical layer protocols, ether, fddi, and tokenring, above it. loop is a pseudo-protocol.
Figure C-2 shows the Ethernet physical layer, ether, and the supported layers of protocols above it. The Loopback pseudo-protocol loop is also shown as the bottom layer because it has the same layers as ether above it.
Figure C-3 shows the FDDI physical layer, fddi, and the supported layers of protocols above it.
Figure C-4 shows the third supported physical layer, tokenring, and the supported layers of protocols above it.
Figure C-5 shows the Datagram Delivery Protocol, ddp, and layers above it.
Figure C-6 shows the AppleTalk protocols, Phases 1 and 2. EtherTalk™ is supported and decoded.
Figure C-7 shows the Xerox Network Systems (XNS) Internetwork Datagram, idp, and NetWare Internetwork Packet Exchange, ipx, protocols. The two protocols are very similar; differences lie in the naming conventions used for the layers.
Figure C-8 shows the Internet Protocol, ip, and the layers above it. The dashed line from tcp to sunrpc indicates that the sunrpc protocol can be used over either tcp or udp.
As an example of how to use these diagrams, assume that you want to capture FTP packets and that Ethernet is your physical routing layer. Find ftp (in Figure C-8) and trace the layers down through tcp and ip until you come to the physical layer ether in Figure C-2. Putting this into the syntax for specifying protocol scoping, use ip.tcp.ftp as your filter to capture FTP packets (ether isn't included because you don't need to specify physical layers). To see if there is a macro that you can use for ip.tcp.ftp, give the command:
netsnoop -L ether |
In the Macro section of the output, notice that there is a macro called ftp:
ftp ip.tcp.ftp |
So, instead of using ip.tcp.ftp as your filter for FTP packets, you can use just ftp.
This section lists documentation sources for protocols supported by NetVisualyzer. The addresses for Request for Comment, ANSI, and ISO documents are listed at the end of this section.
| AppleTalk (AARP, ADSP, AEP AFP, ASP, ATP, DDP, NBP, PAP, RTMP, ZIP) | See ELAP. | |
| ARP | David C. Plummer, “Ethernet Address Resolution Protocol.” Request For Comment 826. November 1982. | |
| ARPIP | David C. Plummer, “Ethernet Address Resolution Protocol.” Request For Comment 826. November 1982. | |
| BOOTP | W.J. Croft and J. Gilmore, “Bootstrap Protocol.” Request For Comment 951. September 1985. J.K. Reynolds, “BOOTP Vendor Information Extensions.” Request For Comment 1084. December 1988. | |
| DECnet | DNA Routing Layer Functional Specification, Version 2.0. Digital Equipment Corporation. Part Number AA-K1821-TK. | |
| DNS | P. Mockapetris, “Domain Names—Implementation and Specification.” Request For Comment 1035. November 1987. | |
| ECHO | J.B. Postel, “Echo Protocol.” Request For Comment 862. May 1983. | |
| ELAP (AppleTalk) |
| |
| ERROR | See XNS. | |
| Ethernet | Carrier Sense Multiple Access with Collision Detection (CSMA/CD) Access Method and Physical Layer Specifications. ANSI/IEEE Standard 802.3-1985. | |
| FTP | J.B. Postel, “File Transfer Protocol.” Request For Comment 959. October 1985. | |
| HELLO | D.L. Mills, “DCN Local-Network Protocols.” Request For Comment 891. December 1983. | |
| ICMP | J.B. Postel, “Internet Control Message Protocol, DARPA Internet Program Protocol Specification.” Requests For Comment 792 and 950. Information Sciences Institute, University of Southern California. September 1981. | |
| IDP | See XNS. | |
| IGMP | S. Deering, “Host Extensions for IP Multicasting.” Request For Comment 1112. August 1989. | |
| IP | “Internet Protocol, DARPA Internet Program Protocol Specification.” Request For Comment 791. Information Sciences Institute, University of Southern California. September 1981. | |
| IPX | “NetWare System Interface Technical Overview.” Novell, Inc. June 1989. | |
| LAT | “Local Area Transport (LAT) Specification.” Digital Equipment Corporation. Part Number AA-NL26A-TE. | |
| LLC | See Token Ring. | |
| MAC | ANSI/FDDI Media Access Control (MAC) X3.139:1987 ISO 9314-2: 1989, Information Processing Systems—Fibre Distributed Data Interface (FDDI) – Part 2: Token Ring Media Access Control (MAC). | |
| NetBIOS | “Protocol Standard for a NetBIOS Service on a TCP/UDP Transport: Detailed Specifications.” Request for Comment 1002. March 1987. | |
| NFS | “NFS: Network File System Protocol Specification.” Request For Comment 1094. Sun Microsystems, Inc., Mountain View, California. March 1989. | |
| NLM | See SunRPC. | |
| NSP | “DNA Network Services Protocol Functional Specification,” Version 4.0. Digital Equipment Corporation. Part Number AA-X439A-TK. | |
| OSI | “Open Systems Interconnection.” International Standards Organization, Technical Committee ISO/TC 97. | |
| PEP | See XNS. | |
| PHY | ANSI/FDDI Physical Layer (PHY) X3.148:1988 ISO 9314-1: 1989, Information Processing Systems—Fibre Distributed Data Interface (FDDI) – Part 1: Token Ring Physical Layer Protocol (PHY). | |
| PMD | ANSI/FDDI Physical Medium Dependent (PMD) X3.166:1990 ISO 9314-3: 1990, Information Processing Systems—Fibre Distributed Data Interface (FDDI) – Part 3: Token Ring Physical Layer Medium Dependent (PMD). | |
| Portmap | “RPC: Remote Procedure Call Protocol Specification: Version 2.” Request For Comment 1057. Sun Microsystems, Inc. June 1988. | |
| RARP | Finlayson, Mann, Mogul, and Theimer, “A Reverse Address Resolution Protocol.” Request For Comment 903. Stanford University, Palo Alto, California. June 1984. | |
| rcp | B. Kantor, “BSD Rlogin.” Request for Comment 1282. September 1991. | |
| RIP | C. Hendrick, “Routing Information Protocol.” Request For Comment 1058. June 1988. | |
| RIP (Novell) | Novell's Portable Transports. Novell Part # 183-000347-001. Novell, Inc. Provo, Utah. April 1990. | |
| RIP (XNS) | See XNS. | |
| rlogin | B. Kantor, “BSD Rlogin.” Request for Comment 1282. September 1991. | |
| SMT | ANSI/FDDI Station Management (SMT) X3T9.5/84-49, Rev. 6.2, May 18, 1990. | |
| SMTP | J.B. Postel, “Simple Mail Transfer Protocol.” Request For Comment 821. August 1982. | |
| SNA | Systems Network Architecture Network Product Formats. Part Number LY43-0081-1. International Business Machines. June 1989. | |
| SNMP | Case, Fedor, Schoffstall, and Davin, “A Simple Network Management Protocol.” Request For Comment 1157. May 1990. | |
| SPP | See XNS. | |
| SPX | See IPX. | |
| SunRPC | Remote Procedure Calls: Protocol Specification. RPC4.0. Request For Comment 1057. Sun Microsystems, Inc., Mountain View, California. | |
| TCP | “Transmission Control Protocol, DARPA Internet Program Protocol Specification.” Request For Comment 793. Information Sciences Institute, University of Southern California. September 1981. | |
| TELNET | J.B. Postel, “Telnet Protocol Specification.” Request For Comment 854. May 1983 | |
| TFTP | K. R. Sollins, “The TFTP Protocol (Revision 2).” Request For Comment 783. June 1981. | |
| Token MAC | See Token Ring. | |
| Token Ring | “Token-Ring Network Architecture Reference.” Part Number SC30-3374-02. International Business Machines. 1989. | |
| TSP | Ricardo Gusella, Stephano Zatti, and James M. Bloom, “The Berkeley UNIX Time Synchronization Protocol.” Computer Systems Research Group, Computer Science Division, Department of Electrical Engineering and Computer Science, University of California at Berkeley, Berkeley, CA 94720. | |
| UDP | J.B. Postel, “User Datagram Protocol.” Request For Comment 768. August 1980. | |
| X | “X Protocol Reference Manual for Version 11 of the X Window System.” O'Reilly & Associates, Inc. 1990. | |
| XNS | “Xerox Internet Transport Protocols, Xerox System Integration Standard.” Xerox Corporation, Sunnyvale, California. XNSS 028112. December 1981. | |
| XTP | “XTP Protocol Definition.” Protocol Engines. Santa Barbara, California. Revision 3.5, September 1990. | |
| VINES | “VINES Protocol Definition.” Order Number DA254-00. Banyan Systems, Inc. February 1990. |
Internet Request For Comment (RFC) documents, in the Defense Data Network Protocol Handbook, are available from:
DDN Network Information Center
14200 Park Meadow Dr., Suite 200
Chantilly, VA 22021
To order ANSI and ISO documents, contact:
American National Standards Institute
1430 Broadway
New York, NY 10018
Telephone: (212) 354-3300
Fax: 212/302-1286
Telex: 42 42 96 ANSI UI