|
The second type of agent which should be installed on at least one
terminal within a subnetwork is the monitoring agent. This agent serves
as a remote analyst of the network traffic. It captures all visible
packets and based on this information builds a quite rich set of
quantitative statistical data describing the traffic within a given
segment of a network. This includes the following parameters:
-
actual, peak and average bandwidth use within a subnetwork
-
activity list (transmitted/received) of a concrete workstation
within a subnetwork
-
list containing data transferred between workstations (traffic
matrix) on the level of the MAC layer and IP
-
statistics of traffic of particular network protocols
-
statistics of traffic of subprotocols of the IP protocol and the
TCP and UDP ports
-
statistics related to the size and type of frames etc.
A monitoring agent when not in use is in the passive state. Once
turned on by the administrative console the agent starts the capture and
analysis of frames, which results in a relative high load for the
workstation on which it is installed. This load depends on the computing
power of the workstation and the intensity and structure of network
traffic.
Apart from statistical functions the monitoring agent enables remote
capture of packets and their analysis on the administrator computer in a
decrypted form.
|