Colasoft Capsa Won the Best Products of 2012 Award from PC Magazine

2013年1月23日 没有评论

Colasoft received the Best Products of 2012 Award from PC Magazine for Colasoft Capsa, one of our flagship software products designed for LAN and WLAN network monitoring, troubleshooting and analysis. Capsa gets a 4.5-star Editors’ Choice pick for networking utilities.

The editors of PC Magazine note that Capsa is a well-designed, fairly user-friendly (at least for network admins), Windows-oriented network analysis tool that offers network admins deep insight into their networks without the steep learning curve required to learn the ins and outs of Wireshark, plus Capsa is heavier on data visualization.

Source: http://www.pcmag.com/article2/0,2817,2408410,00.asp

分类: News & Events 标签:

Use Filters to Capture Packets between Two Hosts

2012年11月11日 2 条评论

Product Versions: Since Capsa 7.0

Intended Audience:

  • Capsa Enterprise users
  • Capsa Professional users
  • Capsa WiFi users
  • Capsa Free users
  • Including all Demo and Evaluation users

When we need to do some tests or experiments, we just need to capture packet data between two hosts. The typical instance is to capture packet data between my local host and another host/server. In order to capture packets only between two hosts we can use a capture filter to ignore all packet data that we don’t need. For instance, we want to capture packets only between my host and Colasoft website:

  • My IP address – 192.168.6.112
  • Colasoft Website IP address – 207.218.235.182

Before we get started we should figure out where is the best place to capture packet data, make sure you are capturing right on the path of the traffic flow, read Where to Capture Packets on my Network for more details. If you are planning to capture packet data between your local host and another machine, the convenient way to do so is to install Capsa on your machine. And follow the steps below to create and enable a capture filter.

Create a Capture Filter in Capsa

  • Run Capsa; click the Set Capture Filter link on top-right corner.
  • Capsa Start Page

  • Capture filter window appears. Click the Add button (on the bottom on the window).
  • Filter Manager

  • Input Name, check Address Rule, and choose IP Address from Address 1 drop-down list. Input IP address, 192.168.6.112, in the textbox under the drop-down list. Then choose IP Address from Address 2 drop-down list, and input IP address – 207.218.235.182.
  • Filter

  • Click OK.
  • Check the new filter’s Accept checkbox, and click OK.
  • Enable Filter

We’ve already created and enabled Capsa to capture packet data only between my host and the remote IP address. Next we can click Start button to start a capture. And we see only packets between my local IP and Colasoft website address. By this way we can create filters to capture packets for certain IP or MAC addresses and also use combinations to create advanced filters with multiple conditions.

Packets

Tips:

  • You are suggested to use the Export function to back up your filter settings (you can find the Export button on Figure A), and make sure you export all filters.

分类: Articles, Tips & How-tos 标签:

Video Tutorials for nChronos

2012年9月13日 1 条评论

About nChronos

nChronos is a back-in-time network analysis server for high performance & critical enterprise networks. It combines nChronos Console and nChronos Server to deliver the capability of 7*24 continuous packet capturing, unlimited data storage, efficient data mining and in depth traffic analysis.

nChronos Console provide quick access to all distributedly deployed nChronos Servers where packets are stored, it serves as the center of the enterprise network management which is capable of visualizing the overall enterprise network activities, drilling down to isolate performance issues and troubleshooting high-priority and critical network issues.

nChronos Server performs 7*24 real-time packet capturing and continually store to hard disk for quick packets and statistics retrieval. With flexible and non-intrusive deployment with standard network mirror port or link tap technologies, it provides native packets for the Console to go back in time and complete retrospective network analysis.

With nChronos, you can

  • Retrospectively analyze the historical network traffic;
  • Proactive network monitoring and cost-effective network management;
  • Efficient drill-down for data-mining & index;
  • Provide forensics analysis and mitigate security risks;
  • Remote access for distributed LAN/WAN network management.

Video Tutorials List

分类: Articles 标签:

Colasoft Announces Colasoft-Firewall.cx Collaboration

2012年8月21日 没有评论

Colasoft, an innovative network analysis solution provider, announces its official collaboration with Firewall.cx, one of the world’s leading networking technology websites.

“With this collaboration, more users can benefit from our most popular and multi-awarded software applications covering network and packet analysis solutions, and with feedbacks from the users, slew of improvements will be made at future releases and products.” said Roy Luo, founder and CEO of Colasoft.

Our products, including nChronos back-in-time network analysis server, Capsa network analyzer and freeware will be available on Firewall.cx, and our products will be used for its upcoming network analysis articles.

About Colasoft

Ever since 2001, Colasoft has dedicated itself to the development of innovative network analysis software and solutions. The flagship products nChronos and Capsa network analyzer are offering real-time and back-in-time network analysis solutions for organizations of all sizes. Colasoft is a fast-growing company with more than half million users in over 80 countries. Featured customers include IBM, Dell, Philips, Emerson, and other industry leading companies.

分类: News & Events 标签:

Colasoft Launches Version 3.1 nChronos Back-in-time Network Analysis Solution

2012年8月16日 1 条评论

Capability, Customization, User Experience, All Enhanced in nChronos 3.1

Chengdu, China – August 16, 2012 – Colasoft, an innovative provider of network analysis software and solutions, today announced a new version of its flagship product, nChronos back-in-time network analysis solution. Capability, customization and user experience are all enhanced in v3.1 which allow network administrators to easily complete back-in-time and real-time network analysis on high performance enterprise networks over a long period of time.

nChronos now delivers real-time network monitoring, key real-time traffic statistics and charts are available, such as throughput and top IP talkers. It helps maintain a productive enterprise network by providing visibility of the bandwidth usage. Besides, it provides long-term packet capturing and recording, you can zoom in any traffic anomaly which needs deeper investigation and rapidly find out the root to solve the problem. Now, 40-Day time window is available, much longer traffic trends can be displayed and analyzed.

“Our customers want to control both back-in-time and real-time network,” said Kang Lin, Vice President at Colasoft. “The new nChronos capability fulfills both of these needs, and unlike existing solutions in the market, we enable customers enjoy this without paying a high price for what is fundamentally a very simple software solution. It is more flexible.”

Also, alarm is the first line of defense for business networks. Alarm is critical for network administrators to instantly identify and resolve network problems. Practical alarms including email, domain and signature alarms are now available. Traffic anomaly alarm is also enhanced which enables you customize alarms with complicated thresholds to monitor network faults and abnormal activities.

The new nChronos also optimized user interface, security settings and activation mechanism which make a better user experience.

The evaluation version is now available at Colasoft website www.colasoft.com.  

About nChronos
nChronos is a back-in-time network analysis server for high performance & critical enterprise networks including the following key features:

  • Back-in-time network analysis of historical traffic for forensics;
  • Benchmark and visualize trends of network performance;
  • 7×24 real-time network traffic capturing and recording;
  • Critical links monitoring & alerting;
  • In-depth network analysis for performance optimization;
  • Efficient drill-down for data-mining & index;

For more information, please visit http://www.colasoft.com/nchronos/index.php.

About Colasoft
Ever since 2001, Colasoft has dedicated itself to the development of innovative network analysis software and solutions. The flagship products nChronos and Capsa network analyzer are offering real-time and back-in-time network analysis solutions for organizations of all sizes. Colasoft is a fast-growing company with more than half million users in over 80 countries. Featured customers include IBM, Dell, Philips, Emerson, and other industry leading companies. For more information about Colasoft, please visit www.colasoft.com.

分类: News & Events 标签:

Colasoft Announces the Release of Capsa Network Analyzer 7.6

2012年6月20日 2 条评论

Capsa Network Anlayzer 7.6 is newly released! You are welcomed to try all the new features and improvements. The free trail is avaliable for download at Colasoft website.

New features and improvements in Capsa network analyzer 7.6:

Unique Analysis Task Scheduler Used to Preset Time for Analysis Projects;
Global Configurations Can Be Exported & Imported;
Display Filters Are Provided for Isolating & Viewing Particular Items;
Report with User-defined Name & Optional Statistic Items is Available;
Logs can be automatically saved in *.csv format.
Capsa can now identify encryption type of AP automatically.
An MAC address column is added to the Log tab.
Settings for analysis profile have been optimized.
Local engine settings are merged into Options on the Menu button.
Capsa can now decode Tunnel IP in IP protocol.
Analysis profiles, such as Traffic Monitor, Protocol Analysis and IM Analysis have been

Read the detailed descriptions about the new features here. For more information, please visit www.colasoft.com.

How to Create and Edit Custom Protocol

2012年5月20日 没有评论

Although Capsa network analyzer supports more than 160 protocols, there are still circumstances that you need add your private protocol rules. For example, you have a special service using a private TCP port in the network, and you want Capsa to recognize it. Or a protocol uses non-standard port. This document is to show you how to create your own custom protocols and edit built-in protocols as your need.
Create Custom Protocols
If you want to create a private protocol rule, follow the instructions below.
Step 1, run Capsa network analyzer. On the Start Page, click the Menu button (on the top-left corner). Choose Local Engine Settings -> Custom Protocol from the menu.
Step 2, on the Custom Protocol window, you can click the Add… button to create a custom protocol. For example, you are testing a new protocol, which uses TCP port 8080. You can just click Add, and type in protocol name, short name and port number, and choose a color for the protocol on the new dialog box. Then click OK to save the custom protocol.

Note: if the capture is running, you need to go back to the start page. Otherwise the Add button and Edit button will be grayed out.
Edit Protocols
If you use non-standard protocols in your network, for example, DNS isn’t on port 53 (TCP or UDP), or HTTP isn’t on TCP port 80, you should modify the default port number for these two built-in protocols. Or Capsa will recognize them as TCP/UDP Other type. Let’s make an example that HTTP uses TCP port 8080, rather than port 80.
Step 1, open the Custom Protocol window, type in http in the search box.
Step 2, double-click on the HTTP protocol item, and modify its port number to 8080 in the dialog box. Click OK to save.

Now if you start a capture, or replay a packet file, all packets using TCP port 81 will be labeled as HTTP protocol. On the Custom Protocol window, you can create private protocols on TCP/UDP ports, IP protocol type, and Ethernet type. TCP and UDP port numbers are used more often rather than the other two. And also you can use the Import button and Export button to back up your private protocols.

FAQ: Why the Add/Edit/Delete buttons of the Custom Protocol window are grayed out?
You are not allowed to change protocol rules while there is a capture running because the changes could crash the program. If you need to add/edit protocol rules, you need stop the capture and go back to the Start Page (if you run multiple instances, you need to close all others). Then click on the Menu button on the top-left corner of the Start Page, and choose Local Engine Settings > Custom Protocol to open the Custom Protocol window. Now you will find the buttons are clickable.

How to baseline network throughput and performance

2012年5月10日 1 条评论

What is network baseline?

Do you know what your normal network throughput volume is, what types of traffic are most used in your network? If you can’t answer these questions then you should baseline your network. Network baseline is very important to network management because the data will tell you what it’s like when everything goes all right.

To baseline your network, you need software or hardware to listen on your network or a particular device. Both Colasoft nChronos and Capsa can be used to accomplish this task. Both of them are used to listen into packet data of a wire and generate all kinds of statistics on the network. To baseline a network, you need to use them to monitor the network traffic long enough, because a wider time span presents a more real picture of network traffic pattern. The use of network baseline is listed as follows:

• Understand healthy network pattern and traffic trends.

• Evaluate network management policies compliance.

• Understand how the network resources are allocated.

• Accelerate to troubleshoot network issues, i.e. abnormal traffic and spam traffic, etc.

• Provide data on network and security management to support decision making.

• Provide history statistics on network upgrade.
阅读全文…

Colasoft nChronos: How to Display IP Addresses as Host Names

2012年3月27日 1 条评论

If you use nChronos to monitor traffic on a core switch you will see lots of internal IP addresses, and also the Internet IP addresses. You can find that most of the Internet IP addresses are shown as their domain name, such as www.colasoft.com, and www.google.com, etc. Wouldn’t it be great if nChronos shows host names of our local machines, because they are much easier to understand, rather than just IP addresses? This tips article will show you how to use Name Table to display IP and MAC addresses as host names.

Suppose that there is a user, Steve, whose laptop has this IP address, 192.168.8.25, and you want nChronos to show his IP address as the text – Steve’s Laptop. First you run nChronos Console, connect to the server, right-click on the server name, and click Settings from the context menu. Then select Name Table on the Server Settings window.

阅读全文…

Thanksgiving Big Sale, Get Capsa at up to 40% off!

2011年11月21日 没有评论

Colasoft Thanksgiving big sale is now online! You can get Capsa at the most favorable price. Get coupons of up to 40% off now by clicking here!