Return to Top Page

FAQs covering :-

  • Passive Analysis

  • Protocol Analysis

 

FAQ Index

Click to view FAQs for listed subject

 

Click to view FAQs for listed tools

 

Toolbox and access information

 

 

 

 

These tools are included in

Facilities accessible via autoAnalyzer tree branch

 

Video Tutorial information

These Tutorials can be used to answer questions:-

  • How to capture, filter and save frames

  • How to view live traffic trends

  • Reports Manager - Overview and Applications

  • How to use Reports Manager

  • How to use Codima Toolbox Alarm System

  • How to deploy Codima Toolbox

Click here to access Tutorial Sign up access point

 

 Deployment Information

Remote Manager - Probes

 

For deployment information, see the Passive Analysis and Active Operations section of the Codima Toolbox Deployment Guide

 

 

 

 

The Remote Manager tool is included in all the Codima Toolboxes, it is used to view and in some cases control Remote systems. These remote systems can be:-

  • Probes - Which enable you to use the functions accessible via the remote systems autoAnalyzer and autoVoIP tree branch. Extending  the domain being monitored by the Passive Analysis tool.

For more information, click on options below:-

 

 

 

FAQs covering Benefits

 

 

 

FAQs covering Installation, Licensing and Deployment

Installation :-

How much memory do I need to install?

How much disk space do I need?

Licensing :-

For more information on the license process see :-

Deployment :-

- Using multiple Network Adapters (NICs) :-

- Using as a portable tool :-

 

 

FAQs covering Scalability
 

 

 

FAQs covering Software Delivery, Software Updates and Software Release contents

Software Delivery and Software Updates :-

Software Release content and schedule :-

  • How do I find out what is included in the latest software releases?
  • How do I find out what is included in older releases?
  • How do I get the latest software version?
  • How do I get a copy of the Codima Toolbox software?
  • How do I check the version number of the software I have installed?

See  FAQs covering Software Releases

 

 

FAQs covering Troubleshooting and Check lists

Check lists:-

For more on Check lists/Reference Material and Evidence requirements - see FAQ - Troubleshooting Codima Toolbox

 

 

FAQs covering Tools
 

autoAnalyzer tree branch provides access to functions

TIP:

The functions accessible via the autoAnalyzer tree branch can be extended to cover multiple segments using the Remote Manager tool and multiple Probes.

Area / Question

Tutorials :-
 

 

Getting Started :-
 

 

Applications, Scope and Operations :-
Applications :-

 

Scope/Operations :-

- Automatic restart :-

 

- Frame Capture :-

 

- Internet Tools :-

 

- Live Views :-

 

- Mapping Network :-

 

- Protocol History Manager :-

 

- Remote Operations:-

- SNMP

 

 

 

Applications :-

Scope/Operations :- Alarm facilities

 

 

 

Applications

Scope - Statistics Reports :-

 

 

 FAQs on miscellaneous/linked subjects
Area / Questions
MIBs :-

 

Misc :-

 

Microsoft® Patch level :-

 

 

 FAQs and answers

Tutorials

Are there any tutorials to help me get started?

Yes - there are tutorials to assist you in learning how to use the facilities available via the autoAnalyzer tree branch. They are accessible from the Help facility and from the Codima Website.

Click here to access the sign in page for the Tutorials:-

The tutorials are titled :-

 

 

Installation

 

Can I install Toolbox on a Virtual Machine?

 

Yes, a supported operating system would need to be run inside the Virtual Machine. You also need to ensure that you have allocated sufficient disk space and memory to run the toolbox application. Failure to do this can cause operational problems.

 

Click here for details covering supported operating system, disk space and memory requirements.

 

 

Can I run the Toolbox as a Windows Service?

 

No, the Codima Toolbox won't run as service. If you do this you can't see the interface to interact with so you have to be logged in. Users can make the Toolbox start at windows startup by putting the shortcut to it in the startup programs folder.

If users are running Codima tools that need 24/7 operation, then you must run the application continuously and not log out.

Can I use a Wireless Network Adapter?

We do not recommend using 802.11 (Wireless) Network Adapter cards for packet capture, as there are too many known issues associated with operating in a Microsoft®Windows® environment.  Even if the cards are running in promiscuous mode there is no guarantee that you will see any packets.

 

Can I use a Host Platform with a 64bit Operating System?

What operating Systems can I use on the Host Platform?

 

The Codima Toolbox will operate on platforms running the following Operating Systems

  • Microsoft® Windows Vista, XP, Server 2003, Server 2008, Server 2008 R2 or Windows 7 with 2GHz CPU (minimum)

 

Toolbox includes WinPCap drivers (used for frame capture) that support 64bit Operating systems.

 

 

Can I install the Codima Toolbox on the same host platform as the Codima Spider?

You can either install a Codima Spider Server or a Codima Toolbox. However you can have a Codima Toolbox with Web Access, that can act as a Codima Spider Server but still allow access on the Host Platform to the tools in the Codima Toolbox.

 

 

 

How do I configure the Host Platform to connect to multiple ports using multiple Network Adapters?

Configuration - Network Adapters (System Module)

Ensuring that the Host system is correctly deployed to enable it to undertake active operations and to passively monitor the network traffic may require you to configure the network adapters assigned to the Host platform.

A standard Toolbox for example can operate with three Network Adapters simultaneous, each one being configured for connection to a specific port on the Host Platform. For deployment guidance, see :-

The system will default to configure the most suitable network adapter for use on port 1 (analysis) and port 3 (comms) - the same adapter will be set for both ports. 

What are the Host Platform requirements?

Click here to access information on the Platform requirements for the Codima Toolbox

 

 

What Network Adapters are supported?

The system uses the WinPCap Packet Driver. 

Microsoft® Windows® XP/2003 Server : the packet driver works correctly on Ethernet networks. Codima has not currently identified any 802.2 or 802.3 Network Adapters that do not work with the Toolbox.

However there are issues with Wireless Network Adapters.

 

Licensing

How are the tools licensed?

All the Codima Toolboxes are require licenses, the license files cover the following :-

  1. Toolbox License (File name = LICENSE.TXT)

The Toolbox License controls the following:- 

  • Tool structure, e.g., which tree branches can be accessed

  • Discovery Device limits, e.g., 50 Managed Devices (applies when user has access to autoAnalyzer and autoMap tree branches)

  • VoIP phone limits, e.g., 100 SIP Phones (applies when user has access to autoAnalyzer and autoVoIP tree branches)

  • Expiry date

  • MAC Address used to machine lock the software

  • Discovery Engine Version, e.g., 3.0-CDE

  • Software Release Version, e.g., 5.00 0001

  • The Demonstration/Evaluation status

  • PAYG status, i.e., user has a standard license or a PAYG license

  1. SNMP License (File name = LICENSE.KEY) 
This is the license file for the SNMP module, all the Codima Toolboxes require this license.  
 
Error Message 
If you do not install the License.Key file, you will get a regular warning message reporting that you are using an evaluation version of the WinSNMP module 

 

 

How do I find the MAC Address of the Platform I wish to install on? - required to machine lock license.

 

The license files used by the Codima Toolboxes are linked to the MAC Address of the Platform you install the software on. To obtain the MAC Address of a Platform you should type ipconfig/all from a DOS window.

 

The MAC Address is a 12 digit hex number, e.g., 00-07-E9-5A-77-DB

 

To get to a DOS window, click Start, then Run, then type cmd in the text box.

If Host Platform has multiple MAC Addresses, you need only to supply one for the license link.

 

DOS Window example:-

 

Alternatively if you are using a demonstration system, you can make use of the automated facility to request a license upgrade, this facility automatically finds your MAC address.

 

Display showing interface used to request license upgrades:-

  

 

 

 

 

Deployment

Can I undertake dual port analysis (monitor more than one port simultaneously with the same system)?

Click below to obtain your copy of the Codima Toolbox Deployment Guide.

 

How do I monitor a full duplex connection?

Click below to obtain your copy of the Codima Toolbox Deployment Guide. This includes information on monitoring full duplex connections.

 

- Portable tool

 

How do I clean the Toolbox to move onto a new Network?

 

Applies when using the Toolbox as a portable tool.

 

There are a number of files that need to be deleted when you are using the Toolbox as a portable tool or connecting a demonstration system to multiple networks 

 

File Type  Location Additional Information
 

History Database Files (*.hd2)

 

..\Express\History New empty files are created when you next launch the Toolbox, you will need to select the file size.
 

Segment Map (Default.nwm)

 

..\Express\Map New empty file created on loading
 

SNMP list of targets for polling (Target.db)

 

..\Express\SNMP New empty file created on loading
 

Alarm Logs (*.xal)

 

..\Express\Alarms New empty files are created when you next launch the Toolbox.

 

 

Scalability

 

Are there any limits to the number of devices/nodes that can be monitored using the functions accessible via the autoAnalyzer tree branch?

 

Yes, this is controlled by the Node History Manager facility, see Help entry titled:-

 

 

Can I add Probes to extend the domain monitored by the Passive Analysis and Protocol Analysis tools?

Yes, you can add Probes to extend the domain monitored.

 

Deployment example - shows domain extended by adding additional Probes.

 

 

For detailed information, see FAQs - Remote Manager

 

 

 

 

How far back can I store network/device statistics and how much disk space would I need ?

 

This is a complex question as there are many variables involved - some of which are network specific.

Key points

1. Each Toolbox* needs to allocates disk space for multiple History database files for storing different sets of statistics - There are 30 database files in total - size range can be from 8MB to 1048MB for each file. So for maximum storage you can set for an individual database file to 1048Mb. The file will wrap when full, so you always have the last 1048Mb worth of statistics.

 

*When monitoring large networks, you may need to use multiple Toolboxes to extend the domain monitored by the Protocol Analysis and Passive Analysis tools. For detailed information, see FAQs - Remote Manager



2. Codima uses a proprietary high speed statistics storage system which allows it to collect bulk high resolution statistics e.g., minimum of 40 statistics for 500 devices in typically a few milliseconds on standard Host Platform.

3. For lower resolution statistics (network/device statistics based on 15 minute intervals) - we can not give an exact figure, but typically a single Toolbox can undertake months of tracking, before the file wraps. It is all dependant on the range and volume of statistics being tracked.

 

See Help entries titled:-



4. For high resolution statistics (15 second intervals) - we can not give an exact figure, but typically a single Toolbox can undertake several days/possibly weeks of tracking, before the file wraps. It is all dependant on the range and volume of statistics being tracked.

 

See Help entries titled:-



5. You also have daily, weekly, monthly report facilities that will take information from history databases and create Word Reports. The report creation takes place at end of day, week, and/or month - allowing you to continually have trend report covering network/device statistics.

It is not possible to provide a figure for the amount of space needed to store these word reports - that is subject to report size and report range activated. So for long term usage would recommend checking free disk space on a regular basis and removing older reports to make room for new ones. After running reports on the network for a couple of months, the user would get an idea of how much disk space a months worth of reports takes up.

 

For more information, see FAQ :-

 

 

 

 

 

 

 

Software Delivery and Software Updates

How do I get a copy of the Toolbox software need to operate the functions accessible via the autoAnalyzer tree branch?

Demonstration software

You can download trial Toolbox software from the Codima Web site download page - all Toolboxes provide access to this tree branch

Evaluation software or Purchased software

URLs to download software are provided in the installation instructions attached to the license delivery email.

 

How do I get the latest software version?

 

You should set up your Host Platform so that it is able to access to the Web. Then you can use the Automatic Installation Update facility. This will automatically tell you if there is an update to the system available. You will also need to be authorized to receive updates.

 

You can also use the Help Menu, where the option Check for Updates will open a Web page listing the available updates, which you can select to download.

 

For more information see Help entry titled:-

  • How to upgrade Software

 

Getting Started

 

Is there any guidance available to help me get started?

Yes, the following reference documents are available :-

 

 

 

Applications, Scope and Operations

 

What are the Benefits of using the Protocol Analysis tool?

 

For more information review the Features and Benefits Video Tutorial for the Tools in all Codima Toolbox:-

Click here to access the sign in page for the Tutorials:-

or click here to obtain a copy of the Codima Toolbox Features and Benefits list.

 

 

What are the Benefits of using the Passive Analysis tool?

 

For more information review the Features and Benefits Video Tutorial for the Tools in all Codima Toolbox:-

Click here to access the sign in page for the Tutorials:-

 

or click here to obtain a copy of the Codima Toolbox Features and Benefits list.

 

 

What functions/tools are accessible via the autoAnalyzer tree branch - what are they used for?


The main tools accessible via the autoAnalyzer tree branch are the :-

 

Analysis can be undertaken with a single Toolbox or you can use a Probe in conjunction with a Remote Manager to extend the domain.

 

Segment Map

The autoAnalyzer tree branch also provides access to a map display created by monitoring frames on the segment. This should not be confused with the mapping functions accessible via the autoMap tree branch, which is an active enterprise level discovery tool.

 

Segment Map example :-

 

This display is a central point to access devices specific information and Live Views covering real time traffic patterns, using right click menu.

 

SNMP Browsing

 

The autoAnalyzer tree branch also provides access to facilities that use SNMP to browse devices.

 

 

- Automatic restart

 

Can I automatically reload the Toolbox when Platform is powered on?

 

Yes, the process is exactly the same as it would be for any other applications, i.e., you include a short cut to the application in your Start up folder.

 

This facility is especially relevant to Probes.

 

 

 

- Frame Capture

 

Can I decode frames captured using Wire Shark (formally known as Ethereal™)?

 

Yes, you can open .pcap files in the Toolbox, they will be converted to .frm files on loading.

 

Can I view frames captured by the Toolbox on Sniffer or Wire Shark?

 

Yes, once you have saved a Frame file in the Toolbox frame format (.frm), you can select to save it in Sniffer™ format,

The Save as facility converts .frm format to .enc format (older DOS format ethernet type), not the newer .cap format.

This format can be read by Sniffer Pro™ v4.5 and Wire Shark™ (formally know as Ethereal™).

How do I filter frames?

 

You can filter frames pre and post capture, the help facility associated with the Toolbox provides detailed information on the filter process. You can also set Negative (exclusion) filters and floating text filters. Floating Text filters allow you to filter on strings of texts within text based protocols, like FTP, HTTP, SIP.

 

 

 

- Internet Tools

 

Can I trace routes and highlight route changes?

 

Yes, you can use the Trace Route facility, which has a feature to save trace route results to logs and when a later trace route is run, it will show the changes to the route.

 

Trace route display example:-

 

 

- Live Views

 

What type of Live Views are available show statistical trends?

The following live views are provided:-

 

The views apply to Segment Level statistics and Node level statistics:-

 

 

 

 

 

 

Can I find out if on line games are being played on the network?

 

Yes, the Live Views facility can be used to track Games. There is a protocol group called Games. The user can add ports to the Games Protocol Group using the Protocol History Manager if they identify any ports associated with specific on line games. The Segment Map shows each of the devices that are being passively monitored by the Toolbox. Each device has a protocol palette next to it, if the Passive Analysis tool sees the device transmitting or receiving traffic from the ports in the Games Protocol Group, the palette would show the color allocated to Games. You can then right click on the device to access its Live View - see example below:-

 

 

 

 

What is the Protocol History Manager?

It is a facility to help track protocol patterns, the Toolbox is able to track a wide range of protocols. Some to the more important protocols are grouped together to enable you to view patterns. The patterns are used by the Reports Manager and the Segment Maps Protocol Groups

The Protocol History Manager is used to:-

You can use the edit facilities associated with the Protocol History Manager to change what is tracked, for example you can:-

 

 

- Mapping Network

 

Can I map the network?

 

There are two methods which can be used to provide maps:-

  1. Real time segment maps provided when you use the functions accessible via the autoAnalyzer tree branch :-

Created by monitoring the frames on the Segment and using the name discovery facility.

See FAQ entry titled :-  Segment Map

 

Segment Map example (local segment):-

 

A Remote Manager can be used to view Segment Maps for each Probe from a central point.

 

Remote Manager view covering Segment Map for a local segment and two Probes (each probe is allocated a unique color):-

 

 

Devices in the Segment Map displays can be sorted and moved.

 

  1. Enterprise level topology maps (in Microsoft® Office Visio® format) provided when you use the functions accessible via the autoMap tree branch

Created using the Codima Discovery Engine to gather topology information and Microsoft® Office Visio® to present results.

See FAQ page covering autoMap tree branch

 

Visio View drawing examples - shows some of the Topology views available:-

         This type of map can be saved as a Microsoft® Office Visio® file (.vsd) or a Web page (.htm).

 

- Alarm facilities

 

What are the Benefits of using the Global Alarm System?

For more information on Features and Benefits click here to obtain a copy of the Codima Toolbox Features and Benefits list.

 

 

Can I have alarm reports automatically emailed to me?

Can I set SNMP Traps?

Can I set threshold alarms?

 

Yes. This tool uses a Global Alarm System to log and report Threshold alarms. The Global Alarm System can be set up to apply one or more of the following actions

• Log the alarm report
• Send out an SNMP Trap when a threshold value is breached (goes above threshold setting) or when a value drops (goes below threshold setting).
• Send a notification email or SMS text message when a threshold value is breached (goes above threshold setting) or when a value drops (goes below threshold setting).
 

For detailed information on this facility, see Help entries titled

 

 

 

- Reports

 

What are the benefits of using the Reports Manager? - when using the Passive Analysis tool

 

The key benefit is it that this tool provides you with evidence at your finger tips. Producing a wide range of Reports that can be used to show both network trends and isolate problems. The Passive Analysis tool includes :-

 

 

For more on the Reports Manager tool - see FAQs - Reports Manager

 

For more information on Features and Benefits click here to obtain a copy of the Codima Toolbox Features and Benefits list.

 

What kind of Statistics Reports are available?

 

There are a number of different types of Statistic Reports, they include :-

 

For additional information, see FAQ - Reports Manager

 

 

- Remote Operations

 

What is the Remote Manager - what is it used for?

The Remote facilities provide remote viewing and control. A Remote Manager is used to view and in some cases control the Remote systems, These remote systems can be:-

Type of Remote system What is it used for:-

 

Enables you to use the functions accessible via remote systems autoAnalyzer and autoVoIP tree branches. Extends the domain being monitored by the Passive Analysis tool
  • Toolboxes on the remote site
Enables you to use the functions accessible via the remote systems autoMonitor or autoPinger tree branches.
  • Sink systems designated as Blaster Managers

 

Enables you to remotely control the stress testing process used by the VoIP Pre Deployment Assessment tool

For more information, see FAQ - autoVoIP Blaster Tree branch and the VoIP Pre Deployment Assessment tool section in the Codima Toolbox Deployment Guide

 

It provides the console view to show the information supplied by the Probes.

 

For more information - see :-

 

What are Probes - what are they used for?

 

They are Remote Systems that provide the Remote Manager with access to the following tree branches on the remote system.

 

 autoVoIP tree branch - used by :-

autoAnalyzer tree branch  - used by:-

 

They are used to provide local management, monitoring and analysis facilities. The following diagram shows how multiple Probes can be deployed to extend the domain managed:-

 

Displays showing the Remote Manager and Probe deployment - Remote Manager in these examples has access to tools locally:-

 

 

 

 

It is also possible to access and control probes from an external site.

 

Display showing the Remote Manager and Probe deployment - Remote Managers in this example have no access to tools locally:-

 

For more information - see :-

 

 

- SNMP Management Systems

 

Can I integrate with SNMP Managers?

Yes, this is done by accessing the fully integrated SNMP Module. This module can add value to an already installed SNMP Manager, in a number of ways. Including the following:-

EXTEND MANAGERS RANGE TO COVER NON-SNMP NODES/TRAFFIC

This will use information obtained from Passive Analysis of the Network.

 

Traps can be issued to multiple SNMP Managements systems, for full information, see Help entry titled:- How to set SNMP Traps

 

The SNMP Manager must have compiled the Codima MIB. The MIB {Enterprise.226} is included in the file set installed with the Codima Toolbox.

..:\Program Files\Codima\Express\SNMP\CODIMA-EXPRESS-MIBs\

How do I get a copy of the Codima MIB, so that my SNMP Management system can read the traps it receives?

 

Codima MIBs are installed with the Toolbox

- C:\Program Files\Codima\Express\snmp\Codima Mibs. 

 

These are the MIBs that need to be compiled by the third-party SNMP Management system.

 

 

 

- MIBs :-

 

What is the SNMP SIM Generator?

 

This is a tool to automate the MIB Walk process and email results back to Codima, it is specifically designed to obtain information for the customization of the Codima Discovery engine.

 

Help entries titled "How to run SNMP Sim Generator" are included with these tools.

 

Note: To provide a successful MIB walk you must use the correct community strings for the device you are browsing.

 

 

How do I run a MIB walk?

 

The easiest way to obtain a MIB walk is to use the SNMP Sim Generator, this runs the MIB walk and automatically emails the results to Codima.

 

Note: To provide a successful MIB walk you must use the correct community strings for the device you are browsing.

 

 

How do I export a MIB walk?

 

The SNMP Sim Generator will do the Mib walk and email results automatically.

 

 

- Netflow :-

 

What is NetFlow and does the Codima Toolbox support it?

 

NetFlow is a network protocol developed by Cisco Systems for collecting IP traffic information. The Codima Toolbox does not currently support this.

 

The Codima Toolbox provides it's analysis instead by using a mixture of information obtained from both passive monitoring and active analysis:-

 

 

Support/Troubleshooting

Can I have a check list to cover what is needed to successfully operate the functions accessible via the autoAnalyzer tree branch?

 

Yes, click below to obtain Check list:- 

 

 

If I have problems with the system what evidence do I need to supply?

Click below to obtain a hard copy of the evidence requirements for the Toolbox.

 

How do I check that the Toolbox is correctly configured to enable me to monitor traffic?

Click below to obtain your copy of the Codima Toolbox Deployment Guide.

 

Microsoft® Patch level

What is the latest Microsoft® Patch level that the Codima Toolbox software been tested with?

The process of testing with Microsoft® patches is an ongoing one, latest level tested is as follows :-

  • Windows XP Service Pack 3

  • Windows 2003 Server SP 2

  • Windows Vista SP1

  • Window Server 2008 SP1

  • Windows 7

 

 
 

 

 

Copyright/Disclaimer

Copyright ©2011 Codima Inc. All Rights Reserved.
No part of this document may be copied or reproduced in any form or by any means without the prior consent of Codima Inc.
Information in this document is subject to change without notice and does not represent a commitment on the part of Codima Inc. Codima Inc. reserves the right to revise or change this document without obligation of Codima Inc. to notify any person of the revision or changes. Information in this document is believed to be accurate at the time of publication but no liability whatsoever can be accepted by Codima Inc. arising out of the use of this information. Also, this document could include typographical errors or technical inaccuracies.
Any trademarks or trade names owned or registered by any other company and used in this document are the property of their respective companies