“Have Sniffer will travel” we used to say. In the old days, every network geek had a Sniffer or Application Expert (now ApplicationVantage) to perform protocol analysis. Unfortunately market forces have pushed these tools beyond reach for most of us. It used to be that you could buy one of these software tools in the $400 range – an affordable price for most IT departments. But both tools have since been sucked up and incorporated into expensive all-encompassing network management platforms, leaving a vacuum that needs filling.
Sniffer was the prize in NetScout’s 2007 purchase of Network General, and predictably, NetScout is in the process of incorporating Sniffer into its nGenius platform. Similarly, Compuware scarfed up Application Expert when it acquired Optimal Networks in 2000, and it is now part of Compuware’s suite of “application analytics solutions”. These tried-and-true protocol analyzers are no longer viable standalone tools for most of us because they have become too unwieldy and expensive as part of a larger solution.
Unfortunately, when tools get sucked into big systems, not only do they become expensive, they also become unresponsive, static, and incapable of reacting quickly to change. This leaves a gaping hole in the average network geek’s toolkit – a hole that fortunately is being filled by the open source Wireshark (formerly Ethereal) tool, as well as a developing ecosystem of Wireshark enhancements and add-ons.
One member of the Wireshark ecosystem is a company called CACE (Creative, Advanced Communication Engineering) Technologies, which describes itself as “dedicated to enhancing the Wireshark user experience”. CACE sells a variety of Wireshark enhancements such as a network analysis, visualization and reporting tool called Pilot, an open source packet capture library for Windows, and a family of packet capture devices for Wireshark. CACE also sells Wireshark training, maintenance and support.
We wonder what will happen next.
We foresee several possible outcomes. In one scenario incumbent vendors will smell opportunity and develop an affordable, standalone protocol analysis tool with more functionality than Wireshark. In another, we foresee the ongoing availability of an open source Wireshark-type solution with add-on capabilities that can be purchased from the likes of CACE. And in a final scenario history repeats itself with the likes of CACE bought and incorporated into yet another all-encompassing solution – in which case we would be back to square one.
We suggest that vendors cater to network geeks by providing high-functioning yet affordable protocol analysis tools. Think about it. There are a lot of us, we can be a very loyal and passionate bunch, and if you can give us a ladder to climb up to more comprehensive network management platforms rather than leaving us in the lurch, we are likely to be allies that help increase your future sales.




