Analyzing SMB/SMB2 with Network Monitor 3. Storage Developer Conference 2009 2009 Insert Copyright information here. All rights reserved.



Similar documents
Interoperability Tools for CIFS/SMB/SMB2 Paul Long and Simon Sun Microsoft

DALHOUSIE NOTES ON PAYROLL EXPENSE DETAIL IN FINANCE SELF SERVICE. QUICK REFERENCE As of September 1, 2015

Introduction to Wireshark Network Analysis

Microsoft SharePoint 2010

Default configuration for the Workstation service and the Server service

Customer Tips. Network Packet Analyzer Tips. for the user. Purpose. Introduction to Packet Capture. Xerox Multifunction Devices.

Application-Centric Analysis Helps Maximize the Value of Wireshark

Lab Conducting a Network Capture with Wireshark

Copyright EPiServer AB

IP Filter/Firewall Setup

Working With Network Monitor Brian M. Posey and David Davis (WindowsNetworking.com)

Introduction. Interoperability & Tools Group. Existing Network Packet Capture Tools. Challenges for existing tools. Microsoft Message Analyzer

Microsoft Windows Movie Maker

Microsoft Excel 2007 Mini Skills Overview of Tables

Also on the Performance tab, you will find a button labeled Resource Monitor. You can invoke Resource Monitor for additional analysis of the system.

Streaming Media System Requirements and Troubleshooting Assistance

Configuring Windows Server Clusters

CATC Multi-Protocol Analyzer (MPA) Reference Manual

Metadata in Microsoft Office and in PDF Documents Types, Export, Display and Removal

Biznet GIO Cloud Connecting VM via Windows Remote Desktop

Table of Contents. Cisco Disabling ICS when Preparing to Install or Upgrade to Cisco VPN Client 3.5.X on Microsoft Windows XP

Learn how to create web enabled (browser) forms in InfoPath 2013 and publish them in SharePoint InfoPath 2013 Web Enabled (Browser) forms

User Manual. Onsight Management Suite Version 5.1. Another Innovation by Librestream

Websense Web Security Gateway: What to do when a Web site does not load as expected

Network setup and troubleshooting

Introduction to Analyzer and the ARP protocol

Administrator s Guide

TREK HOSC PAYLOAD ETHERNET GATEWAY (HPEG) USER GUIDE

Decrypting RDP Traffic with Message Analyzer Bryan S. Burgin Sr. Escalation Engineer, Developer Support, Open Specs Microsoft Corporation

SSRS Reporting Using Report Builder 3.0. By Laura Rogers Senior SharePoint Consultant Rackspace Hosting

TalkShow Advanced Network Tips

Google Docs: Share and collaborate

technical tips and tricks

11.1. Performance Monitoring

Administrator s Guide

Integrating LANGuardian with Active Directory

Setting Up Scan to SMB on TaskALFA series MFP s.

Using the VCDS Application Monitoring Tool

StreamNet StreamNet-eNabled devices/ view virtual matrix control and installation GUide

Microsoft Message Analyzer Packet Analysis at a Higher Level. Neil B Martin Test Manager WSSC- Interop and Tools Microsoft Corporation

Oracle Fusion Middleware

Planning and Managing Projects with Microsoft Project Professional 2013

How to Program a Commander or Scout to Connect to Pilot Software

Suricata IDS. What is it and how to enable it

HoneyBOT User Guide A Windows based honeypot solution

PORTAL ADMINISTRATION

Using the Advanced Tier Data Collection Tool. A Troubleshooting Guide

Network Load Balancing

Microsoft Word 2011: Create a Table of Contents

DocAve 4.1 Backup User Guide

Application Monitor Application (APPMON)

for Managers and Admins

Troubleshooting Procedures for Cisco TelePresence Video Communication Server

DEPLOYMENT GUIDE Version 2.1. Deploying F5 with Microsoft SharePoint 2010

Lab - Using Wireshark to View Network Traffic

Figure 1. Wireshark Menu Bar

Lesson 07: MS ACCESS - Handout. Introduction to database (30 mins)

EINTE LAB EXERCISES LAB EXERCISE #5 - SIP PROTOCOL

Analytics Scheduling reports

Additional Setup Instructions for Modbus: RTU, ASCII, TCP, Omni & Enron

DIGITAL MARKETING. The Page Title Meta Descriptions & Meta Keywords

Welcome to Log on to Learn

Intercluster Lookup Service

ProSafe Plus Switch Utility

Contact Manager HELP GUIDE

DNS (Domain Name System) is the system & protocol that translates domain names to IP addresses.

INTRODUCTION 5 COLLABORATION RIBBON 5 SELECT THE UPDATING METHOD 6 MAKE YOUR PROJECT COLLABORATIVE 8 PROCESSING RECEIVED TASK UPDATES 9

Microsoft SharePoint

DEPLOYMENT GUIDE Version 1.2. Deploying the BIG-IP system v10 with Microsoft Exchange Outlook Web Access 2007

Microsoft SharePoint Products & Technologies

Deploying the BIG-IP System v10 with VMware Virtual Desktop Infrastructure (VDI)

Creating Excel Link reports with efficient design

1. Access your account Log in to your online account at using your main Ring Central phone number and password.

Basic File Recording

Protocols for Dummies

How to create Event Filters directly from the Event Viewer

For example, within General Settings, you can change the default language from English to Spanish and change the size of the text that is displayed.

Stored Documents and the FileCabinet

Step by Step Bandwidth Management

Network Layer IPv4. Dr. Sanjay P. Ahuja, Ph.D. Fidelity National Financial Distinguished Professor of CIS. School of Computing, UNF

Configuring Security for FTP Traffic

WhatsUp Gold v16.3 Installation and Configuration Guide

Word 2010 to Office 365 for business

Table of Contents. Page 1 MLS PIN Customer Support Monday Friday 8 am to 7:30 pm, Saturday 9 am to 5 pm, Sunday 9 am to 1 pm

GLS Support Guide Tips and Tricks

Voice over IP. Demonstration 1: VoIP Protocols. Network Environment

Resource Management with Microsoft Project Professional 2010

Outlook Calendar Tips & Tricks

Addendum DVR670 Installation and Operation manual AM18-Q0617

Technical Information Sheet Page 1 of 8

See how social media listening and engagement can help your business

DIGITAL MARKETING TRAINING

How To Remotely View Your Security Cameras Through An Ezwatch Pro Dvr/Camera Server On A Pc Or Ipod (For A Small Charge) On A Network (For An Extra $20) On Your Computer Or Ipo (For Free

Tutorial 3 Maintaining and Querying a Database

Managing Your Leads Cradle to Grave Using WorkCenter CRM from vforms Software

Solution of Exercise Sheet 5

DEPLOYMENT GUIDE Version 1.2. Deploying the BIG-IP System v10 with Microsoft IIS 7.0 and 7.5

BroadSoft Partner Configuration Guide

Transcription:

Analyzing SMB/SMB2 with Network Monitor 3

Who are you? Paul Long - Technical Evangelist for Network Monitor Networking Specialist in CPR Support group for Microsoft for 15 years Blog on http://blogs.technet.com/netmon 2

What you will learn Where SMB/SMB2 Documentation Is How to Organizing Traffic with Conversations Understand Reassembly and Fragmentation Filtering Tips for SMB/SMB2 Traffic How to Locate SMB/SMB2 Errors with Color Filters Demo: SMB/SMB2 Trace Examples 3

Documentation of SMB/SMB2 Microsoft Open Specifications Bing MS-SMB or MS-SMB2 How Protocols Work Together MS-SYS MS-PROTO MS-SECO Open Protocol Forums 4

Organizing Traffic with Conversations 5

The Conversation Tree Organizes Network Traffic by Grouping Like Traffic For SMB, this means by File ID or File Name SMB Transaction 6

Conversation Tree Tricks Click on Tree Node to Filter Traffic Right Click Frame to Locate Conversation 7

Understanding Reassembly and Fragmentation 8

SMB/SMB2 and Fragmentation SMB/SMB2 Big, Ethernet Frames Small TCP/NBTSS can Fragment Data Continuation frames are a key Network Monitor does NOT reassemble by default 9

Reassembling with Network Monitor Press Reassemble Button Only Available on Saved Traces New Window Appears, New Frames are Inserted New Frames have PayloadHeader Prepended to Top 10

Working With Reassembled Trace Newly Inserted Frame Follows Fragmented Data Color Filter Makes Finding Frames Easier 11

Mid Frame Fragmentation Network Monitor Can t Deal with Mid Frame Fragmentation Occurs when NBTSS or TCP Streams Two SMB Commands Together Can use Decode As Filter to Find (or Color Filter) (!smb AND!smb2) AND (ContainsBin(FrameData, HEX, "FF 53 4D 42") OR ContainsBin(FrameData, HEX, "FE 53 4D 42")) 12

Mid Frame Fragmentation Example 13

Filtering Tips for SMB/SMB2 Traffic 14

Standard Filters SMB/SMB2 Standard Filters are Built Into Network Monitor Currently 3 available Standard Filters for SMB 15

Right Click add to Filter Click any field in Frame Details to create a filter that finds other frames with the same info. Great way to learn how to create filters! SMB.SMBHeader.ProcessID == 0xfeff 16

Properties of Interest for SMB/SMB2 Properties are Meta Data defined by the Parser Property.SMBFileName.contains(.txt ) Property.SMBCommand == 0x72 Property.SMBMID == 0x40 SMB File ID Property.SMBFileID == 0x4000 SMB2 File ID Property.SMBFileIDPersistent Property.SMBFileIDVolatile 17

Properties of Interest for SMB/SMB2 Many others, to find type Property.SMB and use Intellisense. 18

Properties As Columns Any Property can be added as a column in Column Chooser 19

Locating SMB/SMB2 Errors Trace with Color Filters 20

Color Filter for SMB Errors Filter will find any frame with an SMB error. (smb.doserror.error!= 0 AND smb.doserror.error!= 22) OR (smb.ntstatus.code!= 0 && smb.ntstatus.code!= 22) 21

Color Filter for SMB2 Errors Filter will find any frame with an SMB2 error. SMB2Header.Status!= 0 AND smb2.smb2header.status!= 259 22

Demos 23

Demo: Trace Examples Trouble Shooting a Delayed Write Failure Looking at SMB Oplocks 24

Network Monitor 3 NM3 is a protocol analyzer and network capture tool. Features such as Process Tracking and the Conversation Tree allow you to quickly locate traffic. http://www.microsoft.com/downloads Latest released version. http://blogs.technet.com/netmon - Includes general help topics and training videos. http://social.technet.microsoft.com/forums/en/netmon - Public Support Forums http://www.codeplex.com/nmparsers - Open Source Parsers and latest parser version. http://www.codeplex.com/nmexperts - Experts Landing Page http://connect.microsoft.com Latest Betas, Beta support Forums and Bug Reporting