Sourcefire's RNA provides instant visibility into your network - Network World

Skip Links

DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Network Management

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library.  Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.

Additional Resources

RSS

FEATURED WHITEPAPERS

Endpoint Security: Data Protection for IT, Freedom for Laptop Users Absolute Software

The movement towards laptop computers has fueled an unprecedented number of data breaches. For IT and Information Security, encryption and training has proven ineffective against careless users and insider threats. This paper discusses these limitations and explains how endpoint security allows remote deletion of sensitive data, tracking of computers outside the network and the physical recovery of missing computers. Learn how you can ensure mobile data protection regardless of end-user interference.

RSS

FEATURED REPORTS

Executive Guide: Storage Heats Up HP

Get the latest on storage technologies that allow IT professionals to better cope with new IT demands. Learn how storage technologies can help you successfully tackle e-Discover, regulatory compliance, green data center initiatives and the data explosion. Get all the details now.

RSS

FEATURED WEBCASTS

Learn how to Create a More Efficient Virtualized Data Center Novell

Find out how you can consolidate Windows workloads and create a more efficient virtualized data center in this informative webcast, "Reduce Complexity and Cost - Windows Server Consolidation with Virtualization." Six concise webcast modules are available for your viewing. Watch them all consecutively or only the topics that interest you. The modules cover performance, user case studies, enterprise-level support, managing windows workloads, setup and configuration and the future of virtualization. Learn more today. Register below to learn more and be entered to win an Archos 605 Portable Media Player.

Sourcefire's RNA provides instant visibility into your network

Sourcefire's RNA provides instant visibility into your network.
By Joel Snyder, Network World Lab Alliance , Network World , 08/23/2004
  • Social Web 
  • Email 
  • Feedback 
  • Close
Clear Choice Test

Sourcefire's Real-time Network Awareness Sensor 2000 is like a magic eye that watches everything happening on your network. By combining passive network analysis with a Web-based management system, Sourcefire delivers a powerful tool to IT personnel who need more information about their networks.

While RNA Sensors offer a wealth of information about the systems and services on your network, the downside is that it is up to you to make sense out of it all.


How we did it
Archive of Network World reviews
Subscribe to the Product Review newsletter


To help network managers understand the information from RNA Sensors and the alerts and events from the company's intrusion-detection systems  sensors (Intrusion Sensor), Sourcefire offers the Defense Center (if purchased collectively, Sourcefire refers to the package as its 3D Product Suite). RNA Sensors and Intrusion Sensors send information to the Defense Center, which provides a central view of alerts and events, network configuration information and forensic data.

RNA Sensors sit passively on the network and watch the traffic pass by. The RNA Sensor we tested had four Ethernet interfaces, but we used only one with virtual LAN-based monitoring to give RNA Sensor visibility into different parts of our production network. While this virtual LAN capability is a great feature for a network site, if you wanted to monitor multiple sites, you'd need to deploy multiple sensors. (See How we did it .) Configuration is simple: once you tell RNA Sensor what networks to watch, it begins collecting data and populating its databases.

As RNA Sensor watches the packets fly by, it builds a model of the network topology and pinpoints the hosts on your network, the network applications  they are running, and the users and devices they are communicating with. Because RNA Sensor watches every connection to every host, it also collects information about specific network flows, such as a particular HTTP connection from a client to a server.

RNA Sensor's information about our network was quite accurate. Application identification was excellent, as the sensor found obscure mail servers on non-standard ports and managed to get product and version information for most products. When it came to guessing operating systems , the results were mixed. RNA Sensor collected the least amount of information for embedded systems, such as printers and time servers.

1 | 2 | 3 |  Next >
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.
First Name
Last Name
E-mail
Zip Code
IT Buyer's Guides

View All Buyer's Guides