Appendix C. Protocols

NetVisualyzer supports many network protocols. Packet headers for supported protocols can be fully decoded by Analyzer and NetSnoop, and information about packets using supported protocols is available from NetAccount, NetGraph, and NetTop. In addition, other protocols are recognized, although not fully decoded, by NetVisualyzer tools.

This appendix lists the protocols supported and partially supported by NetVisualyzer tools and contains diagrams showing how these protocols relate to one another. You can use this information to create filters to capture the protocol packets of interest to you. This chapter also provides references for further information about the protocols.

Supported Protocols

You can see a list of protocols supported by NetVisualyzer tools by giving the command:

netsnoop -L all 

Table C-1 lists fully supported protocols. It contains protocol name acronyms, the names used by NetVisualyzer tools, and the full protocol names. Where available, the RFC sources for the protocols are listed.

Table C-1. Supported Protocols

Protocol Name

NetVisualyzer Name

Description

AARP

aarp

AppleTalk™ Address Resolution Protocol

ADSP

adsp

AppleTalk Data Stream Protocol

AEP

aep

AppleTalk Echo Protocol

AFP

afp

AppleTalk Filing Protocol

ARP

arp

Address Resolution Protocol (RFC 826)

ARPIP

arpip

IP to Ethernet ARP (RFC 826)

ASP

asp

AppleTalk Session Protocol

ATP

atp

AppleTalk Transaction Protocol

BOOTP

bootp

Bootstrap Protocol (RFCs 951 and 1084)

DDP

ddp

AppleTalk Datagram Delivery Protocol

DECnet

decnet

DECnet Phase IV protocol

DNS

dns

Domain Name System protocol (RFC 1035)

ECHO

echo

XNS® Echo protocol (RFC 862)

ELAP

elap

AppleTalk EtherTalk Link Access Protocol

ERROR

error

XNS Error protocol

Ethernet

ether

Ethernet version 2 protocol

FDDI

fddi

Fiber Distributed Data Interface protocol

FTP

ftp

File Transfer Protocol (RFC 959)

HELLO

hello

DEC™ HELLO routing protocol (RFC 891)

ICMP

icmp

Internet Control Message Protocol (RFCs 792 and 950)

IDP

idp

XNS Internetwork Datagram Protocol

IGMP

igmp

Internet Group Management Protocol (RFC 1112)

IPX™

ipx

NetWare® Internetwork Packet Exchange protocol

IP

ip

Internet Protocol (RFC 791)

LAT™

lat

DEC Local Area Transport protocol

LLC

llc

Logical Link Control protocol

MAC

mac

Media Access Control protocol

NBP

nbp

AppleTalk Name Binding Protocol

NFS

nfs

Sun Network File System protocol (RFC 1094)

NLM

nlm

Network Lock Manager protocol

NSP

nsp

DECnet IV Network Services Protocol

PAP

pap

AppleTalk Printer Access Protocol

PEP

pep

XNS Packet Exchange Protocol

Portmap

pmap

Sun RPC Portmap protocol (RFC 1057)

RARP

rarp

Reverse Address Resolution Protocol (RFC 903)

rcp

rcp

BSD Remote Copy protocol (RFC 1282)

RIP

rip

Routing Information Protocol (RFC 1058)

RIP

novellrip

Novell Routing Information Protocol

RIP

xnsrip

XNS Routing Information Protocol (Xerox)

rlogin, rsh

rlogin

BSD Remote Login/Remote Shell protocol (RFC 1282)

RTMP

rtmp

AppleTalk Routing Table Maintenance Protocol

SMT

smt

Station Management protocol

SNMP

snmp

Simple Network Management Protocol (RFC 1157)

SPP

spp

XNS Sequenced Packet Protocol

SPX

spx

NetWare Sequenced Packet Exchange protocol

SunRPC

sunrpc

Sun Remote Procedure Call protocol (RFC 1057)

TCP

tcp

Transmission Control Protocol (RFC 793)

TELNET

telnet

Telnet protocol (RFC 854)

TFTP

tftp

Trivial File Transfer Protocol (RFC 783)

Token MAC

tokenmac

Token Ring Media Access Control protocol

Token Ring

tokenring

Token Ring protocol

TSP

tsp

Time Synchronization Protocol

UDP

udp

User Datagram Protocol (RFC 768)

XTP

xtp

Xpress Transfer Protocol

ZIP

zip

AppleTalk Zone Information Protocol

Table C-2 lists the protocols that are partially supported by NetVisualyzer. Analyzer and NetSnoop recognize these protocols, but don't decode them. These protocols are fully supported by the other NetVisualyzer tools.

Table C-2. Partially Supported Protocols

Protocol Name

NetVisualyzer Name

Description

NetBIOS™

netbios

NetBIOS Services protocol (RFC 1002)

OSI

osi

Open Systems Interconnection protocols

SMTP

smtp

Simple Mail Transfer Protocol (RFC 821)

SNA

sna

System Network Architecture protocol

VINES®

vines

Banyan® VINES protocol

X

x11

X network protocol


Protocol Layers

This section contains diagrams showing the supported protocols listed in Table C-1 and Table C-2 and their relationships to each other. In these diagrams, arrows pointing up indicate that the layers above this protocol are shown in a diagram later in this section.

These diagrams are useful when constructing filters since each protocol must be completely specified except for its physical layer. These diagrams also show all of the packet types that are captured by Analyzer and other tools if you specify a lower-level protocol as a filter. For example, if you use ip.tcp (or the macro tcp) as a filter in Analyzer, the Type column in the Summary pane can show rcp, rlogin, telnet, and other protocols as well as tcp. You find out the complete list of possible protocol types by looking at Figure C-8 and noting the protocol layers above tcp.

Figure C-1 shows the Snoop pseudo-protocol, snoop, and the three physical layer protocols, ether, fddi, and tokenring, above it. loop is a pseudo-protocol.

Figure C-1. Snoop Pseudo-protocol Diagram


Figure C-2 shows the Ethernet physical layer, ether, and the supported layers of protocols above it. The Loopback pseudo-protocol loop is also shown as the bottom layer because it has the same layers as ether above it.

Figure C-2. Ethernet Protocol Diagram


Figure C-3 shows the FDDI physical layer, fddi, and the supported layers of protocols above it.

Figure C-3. FDDI Protocol Diagram


Figure C-4 shows the third supported physical layer, tokenring, and the supported layers of protocols above it.

Figure C-4. Token Ring Protocol Diagram


Figure C-5 shows the Datagram Delivery Protocol, ddp, and layers above it.

Figure C-5. Datagram Delivery Protocol Diagram


Figure C-6 shows the AppleTalk protocols, Phases 1 and 2. EtherTalk™ is supported and decoded.

Figure C-6. AppleTalk Protocols Phase 1 and 2 Protocol Diagram


Figure C-7 shows the Xerox Network Systems (XNS) Internetwork Datagram, idp, and NetWare Internetwork Packet Exchange, ipx, protocols. The two protocols are very similar; differences lie in the naming conventions used for the layers.

Figure C-7. Internetwork Datagram and Internal Packet Exchange Protocol Diagrams


Figure C-8 shows the Internet Protocol, ip, and the layers above it. The dashed line from tcp to sunrpc indicates that the sunrpc protocol can be used over either tcp or udp.

Figure C-8. Internet Protocol Diagram


As an example of how to use these diagrams, assume that you want to capture FTP packets and that Ethernet is your physical routing layer. Find ftp (in Figure C-8) and trace the layers down through tcp and ip until you come to the physical layer ether in Figure C-2. Putting this into the syntax for specifying protocol scoping, use ip.tcp.ftp as your filter to capture FTP packets (ether isn't included because you don't need to specify physical layers). To see if there is a macro that you can use for ip.tcp.ftp, give the command:

netsnoop -L ether 

In the Macro section of the output, notice that there is a macro called ftp:

ftp                 ip.tcp.ftp

So, instead of using ip.tcp.ftp as your filter for FTP packets, you can use just ftp.

Protocol References

This section lists documentation sources for protocols supported by NetVisualyzer. The addresses for Request for Comment, ANSI, and ISO documents are listed at the end of this section.

AppleTalk (AARP, ADSP, AEP AFP, ASP, ATP, DDP, NBP, PAP, RTMP, ZIP) 

See ELAP.

ARP 

David C. Plummer, “Ethernet Address Resolution Protocol.” Request For Comment 826. November 1982.

ARPIP 

David C. Plummer, “Ethernet Address Resolution Protocol.” Request For Comment 826. November 1982.

BOOTP 

W.J. Croft and J. Gilmore, “Bootstrap Protocol.” Request For Comment 951. September 1985.

J.K. Reynolds, “BOOTP Vendor Information Extensions.” Request For Comment 1084. December 1988.

DECnet 

DNA Routing Layer Functional Specification, Version 2.0. Digital Equipment Corporation. Part Number AA-K1821-TK.

DNS 

P. Mockapetris, “Domain Names—Implementation and Specification.” Request For Comment 1035. November 1987.

ECHO 

J.B. Postel, “Echo Protocol.” Request For Comment 862. May 1983.

ELAP (AppleTalk) 


Gursharan S. Sidhu, Richard F. Andrews, Alan B. Oppenheimer, Apple Computer, Inc., Inside AppleTalk. Menlo Park, California; Addison-Wesley Publishing Company, Inc. May 1990.

ERROR 

See XNS.

Ethernet 

Carrier Sense Multiple Access with Collision Detection (CSMA/CD) Access Method and Physical Layer Specifications. ANSI/IEEE Standard 802.3-1985.

FTP 

J.B. Postel, “File Transfer Protocol.” Request For Comment 959. October 1985.

HELLO 

D.L. Mills, “DCN Local-Network Protocols.” Request For Comment 891. December 1983.

ICMP 

J.B. Postel, “Internet Control Message Protocol, DARPA Internet Program Protocol Specification.” Requests For Comment 792 and 950. Information Sciences Institute, University of Southern California. September 1981.

IDP 

See XNS.

IGMP 

S. Deering, “Host Extensions for IP Multicasting.” Request For Comment 1112. August 1989.

IP 

“Internet Protocol, DARPA Internet Program Protocol Specification.” Request For Comment 791. Information Sciences Institute, University of Southern California. September 1981.

IPX 

“NetWare System Interface Technical Overview.” Novell, Inc. June 1989.

LAT 

“Local Area Transport (LAT) Specification.” Digital Equipment Corporation. Part Number AA-NL26A-TE.

LLC 

See Token Ring.

MAC 

ANSI/FDDI Media Access Control (MAC) X3.139:1987 ISO 9314-2: 1989, Information Processing Systems—Fibre Distributed Data Interface (FDDI) – Part 2: Token Ring Media Access Control (MAC).

NetBIOS 

“Protocol Standard for a NetBIOS Service on a TCP/UDP Transport: Detailed Specifications.” Request for Comment 1002. March 1987.

NFS  

“NFS: Network File System Protocol Specification.” Request For Comment 1094. Sun Microsystems, Inc., Mountain View, California. March 1989.

NLM 

See SunRPC.

NSP 

“DNA Network Services Protocol Functional Specification,” Version 4.0. Digital Equipment Corporation. Part Number AA-X439A-TK.

OSI 

“Open Systems Interconnection.” International Standards Organization, Technical Committee ISO/TC 97.

PEP 

See XNS.

PHY 

ANSI/FDDI Physical Layer (PHY) X3.148:1988 ISO 9314-1: 1989, Information Processing Systems—Fibre Distributed Data Interface (FDDI) – Part 1: Token Ring Physical Layer Protocol (PHY).

PMD 

ANSI/FDDI Physical Medium Dependent (PMD) X3.166:1990 ISO 9314-3: 1990, Information Processing Systems—Fibre Distributed Data Interface (FDDI) – Part 3: Token Ring Physical Layer Medium Dependent (PMD).

Portmap 

“RPC: Remote Procedure Call Protocol Specification: Version 2.” Request For Comment 1057. Sun Microsystems, Inc. June 1988.

RARP  

Finlayson, Mann, Mogul, and Theimer, “A Reverse Address Resolution Protocol.” Request For Comment 903. Stanford University, Palo Alto, California. June 1984.

rcp 

B. Kantor, “BSD Rlogin.” Request for Comment 1282. September 1991.

RIP 

C. Hendrick, “Routing Information Protocol.” Request For Comment 1058. June 1988.

RIP (Novell) 

Novell's Portable Transports. Novell Part # 183-000347-001. Novell, Inc. Provo, Utah. April 1990.

RIP (XNS) 

See XNS.

rlogin 

B. Kantor, “BSD Rlogin.” Request for Comment 1282. September 1991.

SMT 

ANSI/FDDI Station Management (SMT) X3T9.5/84-49, Rev. 6.2, May 18, 1990.

SMTP 

J.B. Postel, “Simple Mail Transfer Protocol.” Request For Comment 821. August 1982.

SNA 

Systems Network Architecture Network Product Formats. Part Number LY43-0081-1. International Business Machines. June 1989.

SNMP 

Case, Fedor, Schoffstall, and Davin, “A Simple Network Management Protocol.” Request For Comment 1157. May 1990.

SPP 

See XNS.

SPX 

See IPX.

SunRPC 

Remote Procedure Calls: Protocol Specification. RPC4.0. Request For Comment 1057. Sun Microsystems, Inc., Mountain View, California.

TCP 

“Transmission Control Protocol, DARPA Internet Program Protocol Specification.” Request For Comment 793. Information Sciences Institute, University of Southern California. September 1981.

TELNET 

J.B. Postel, “Telnet Protocol Specification.” Request For Comment 854. May 1983

TFTP 

K. R. Sollins, “The TFTP Protocol (Revision 2).” Request For Comment 783. June 1981.

Token MAC 

See Token Ring.

Token Ring 

“Token-Ring Network Architecture Reference.” Part Number SC30-3374-02. International Business Machines. 1989.

TSP 

Ricardo Gusella, Stephano Zatti, and James M. Bloom, “The Berkeley UNIX Time Synchronization Protocol.” Computer Systems Research Group, Computer Science Division, Department of Electrical Engineering and Computer Science, University of California at Berkeley, Berkeley, CA 94720.

UDP 

J.B. Postel, “User Datagram Protocol.” Request For Comment 768. August 1980.

X 

“X Protocol Reference Manual for Version 11 of the X Window System.” O'Reilly & Associates, Inc. 1990.

XNS 

“Xerox Internet Transport Protocols, Xerox System Integration Standard.” Xerox Corporation, Sunnyvale, California. XNSS 028112. December 1981.

XTP 

“XTP Protocol Definition.” Protocol Engines. Santa Barbara, California. Revision 3.5, September 1990.

VINES 

“VINES Protocol Definition.” Order Number DA254-00. Banyan Systems, Inc. February 1990.

Internet Request For Comment (RFC) documents, in the Defense Data Network Protocol Handbook, are available from:

DDN Network Information Center
14200 Park Meadow Dr., Suite 200
Chantilly, VA 22021

To order ANSI and ISO documents, contact:

American National Standards Institute
1430 Broadway
New York, NY 10018
Telephone: (212) 354-3300
Fax: 212/302-1286
Telex: 42 42 96 ANSI UI