Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

MS/DCE RPC?

Status
Not open for further replies.

ciscomeo

Technical User
Jun 9, 2003
94
US
What's the best way of adding MS/DCE RPC protocol in your protocol database? I notice it uses a lot of source port.

Any suggestions..?

Thanks,
 
If they are contiguous sequences of ports, you can use the port aggregation feature in Sniffer Distributed.
MP
 
Hi! Can you further elaborate? I am a new user in Sniffer and I don't know how to use the aggregation in my Sniffer Distributed.

Thanks,
 
Prerequisite - You should be on Sniffer Distributed 4.3 or greater.

Steps -
1. Go into Tools | Protocols Options,

2. Enter port ranges in UDP and / or TCP tabs and associate an intuitive protocol name -like Dce-Rpc.

3. Open the capture file & select Protocol Distribution tab or click Monitor | Protocol Options, if you're monitoring real time traffic

4. Now, when you view the protocol distribution charts, the packets with the TCP / UDP port nos. specified in step 2, should show up under the descriptive name you chose.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top