OmniPeek Product Family
AiroPeek SE & NX
Overview
Support FAQ
Tech Tips
Drivers
Decodes
AiroPeek VX
EtherPeek SE & NX
EtherPeek VX
Hardware
Other Products

Support FAQ

Some things just go together. AiroPeek + EtherPeek = OmniPeek

AiroPeek NX Only

AiroPeek SE & AiroPeek NX

AiroPeek NX Only

Return to top of page Can you explain the Profiles, Configuration and Node Visibilities tabs in the Peer Map view?

The Profile tab lets you save Peer Map configurations settings into a single profile that controls the appearance and layout of the Peer Map.

The Configuration tab lets you control what part of the traffic in the Capture window’s buffer is displayed in the Peer Map.

The Node Visibilities tab displays node counts, and nodes that are both shown and hidden in the Peer Map. For example, if this option is set to Always Hide, then all nodes that have not had their visibility assigned by the user will be hidden. This is useful if, during a live capture, the user doesn’t want new nodes to appear on the Peer Map as they are discovered.

Return to top of page Why does some activity in the Peer Map contain spaces?

The space shows you where protocol segments start and stop within conversations. This option is configurable by clicking the Options button. (Different from going to Tools -> Options).

Return to top of page Where can I find a definition for the expert messages?

Right-click on any Expert event and choose EventFinder Settings. Click the Show Info button for a description of the event and possible causes and remedies.

 

AiroPeek SE & AiroPeek NX

Return to top of page Are you going to release a patch for WildPackets Products in order to make them compatible with the new 2007 Daylight Savings Time changes?

Since all WildPackets products make use of the underlying Operating System for all time computations, no patch will be necessary for our products to operate correctly with the new Daylight Saving Time Change.

Important Vista Note:

Vista Operating System has a facility for dynamic Daylight Saving Time calculations that takes into account the fact that different years may have different DST dates. The next release of the OmniPeek Product Family (available end of Jan. 2007) will include the code to use this new operating system facility.

The end result is that everything will work correctly with Vista, but if a user has XP with the DST hotfix installed, the duration of captures that span the actual time change in past years may be incorrect since XP does not have the facility to understand that different years may have different DST dates.

Return to top of page Will AiroPeek run on 64 bit Operating Systems?

AiroPeek 3.1 will load and run on 64 bit operating systems in 32 bit compatibility mode and supports AMD and Intel x86 processors including the 64 bit capable Pentium and Xeon processors.

Return to top of page Can I use the same adapter to capture and send packets simultaneously?

Send functions (e.g., commands in the Send menu and Send window) cannot send packets via a wireless adapter when that adapter is being used to capture packets.

Return to top of page In Capture Options, 802.11, I select Channel by BSSID or ESSID. Why does the capture still display nodes and Access Points?

The BSSID and ESSID option under the Select Channel is only for selecting a wireless channel.  This option does not filter out specific wireless traffic, creating an advanced filter will accomplish this for you.

Return to top of page How often does AiroPeek scan for ESSID(s)?

When selecting the channel by ESSID in the 802.11 section of the Capture Options dialog, the behavior varies depending on which driver you're capturing from. For example, the Atheros driver will search for the specified ESSID for 2 seconds. If that ESSID is found, it will change to the channel which corresponds to that ESSID; otherwise, it will remain on the current channel.

Return to top of page Can AiroPeek capture error packets?

CRC errors are the only error type captured by AiroPeek. All error packets are processed by Network, Summary, Size, and History statistics. However, in Network statistics, error packets only count for total packet and byte count, not for broadcast and multicast counts. Node, Protocol, and Channel Statistics do not process error packets. The "802.11 Analysis" plug-in is currently the only plug-in that processes error packets. Most summary statistics information comes from plug-ins.

Return to top of page When I click on certain tabs within AiroPeek some text is not legible, is there a setting to adjust this?

This may be caused by a display DPI setting that is larger than 96 DPI. Confirm that the display's DPI setting is set to 96 DPI by checking the configuration for this setting in the Advanced Settings portion of the Display Control Panel.

Return to top of page Does AiroPeek support WPA?

Yes, with the use of an Atheros chipset based adapter and the WildPackets 3.0.1.x Atheros driver, WPA-PSK is supported in AiroPeek 3.x.

Return to top of page Does AiroPeek support WPA2?

Currently WPA2 is not supported.

Return to top of page What type of encryption does AiroPeek support?

AiroPeek supports TKIP and WEP encryption.

Return to top of page Can I use the "Send" feature for control and management packets?

It is not possible to use the 'Send' feature for control and management packets. The Send feature will work with 802.3 data packets only. Control and management packets in a trace file were used for previous wireless transmissions. When you attempt to send them via AiroPeek, the driver for the 'Send Adapter' will not forward them. While AiroPeek has the ability to send 802.3 frames, it was not designed to replay wireless trace files and 'simulate' wireless traffic.

Return to top of page Can I measure noise using AiroPeek?

Yes, if your adapter has an Atheros chipset, the WildPackets Atheros driver will allow noise measurements to be passed to AiroPeek. (This is an approximate measurement by the wireless adapter).

Return to top of page What is the reference point for timestamping packets?

If the adapter driver hasn't already timestamped the packet, the timestamp is provided by the Peek driver.

Return to top of page How secure is AiroPeek?

Network analysis tools are powerful and must be protected from misuse. Data captured and sent across the network may be sensitive, so AiroPeek has been designed from the ground up to adhere to strict IT security requirements.

Return to top of page When I use AiroPeek to monitor my high speed network, the application tends to slow down. Are there any tips to optimize performance?

In the Capture/Monitor Options, select Performance. For peak performance, right click on one of the features and choose Disable All. This way, AiroPeek will function at peak performance, but the features are still available when needed. When you need a particular feature, you can always enable it. As you enable/disable individual features, the performance bar at the bottom of the Performance Options dialog will move to show you an estimate of the impact of each feature.

Here are a few more tips to improve the performance of AiroPeek:

  • Disable the Monitor adapter (Monitor/Select Monitor Adapter/None)
  • Turn off scroll during capture. Control + K will start/stop scroll.
  • Disable passive name resolution. Under Tools/Options/Name Resolution, uncheck enable passive name resolution.
  • Turn off any automatic report production for monitor and/or capture. Under Monitor or Capture options, select Statistics Output. Uncheck Save Statistics Report.

Return to top of page I am unable to start a wireless capture. When I select 'OK' in the Capture Options I receive the error 'The adapter "Wireless Network Connection" is not supported by this product.' What am I missing?

In order to capture wireless traffic with AiroPeek, you must install a custom WildPackets driver.

A list of supported cards and the WildPackets drivers can be found here:
http://www.wildpackets.com/support/product_support/airopeek/hardware

Please find your card from the list and download the appropriate driver.

***First install and test the adapter with the OEM driver. Do not install the WildPackets driver until the adapter is functioning properly on your network using the OEM driver***

Also, be sure to follow the ReadMe carefully; you must choose 'Don't search. I will choose the driver to install.'

Return to top of page I have entered the correct key or passphrase but the TKIP encrypted packets are not being decrypted. Can you please tell me what's wrong?

Peek *must* capture the complete (EAPOL) key exchange to successfully decrypt WPA-PSK encrypted traffic. This exchange consists of the 4 packet Pairwise Master key (PMK) and the 2 packet Group Temporal Key (GTK). Below is an example of a successful EAPOL capture.

Screenshot

 - Click on thumbnail for larger view

Return to top of page Where can I find a list of supported adapters?

Please refer to the AiroPeek Supported Wireless Adapters page, for a current list of wireless adapters that are supported by AiroPeek.

Return to top of page I have captured the required EAPOL keys but I still can't decrypt the WPA traffic, what am I doing wrong?

When WMM (802.11e) is enabled WPA-PSK decryption will fail, some adapters have an Advanced Settings Tab that will allow this feature to be disabled. If your adapter does not have this setting, disable the feature on the corresponding Access Point. Once you have disabled the feature on the client's adapter who is sending the traffic of interest or the AP, you should be able to decrypt the traffic completely.

Download a demo of OmniPeek

OmniPeek Product Family

The OmniPeek Product Family gives network engineers real-time visibility into every part of the network – simultaneously from a single interface – including Gigabit, Ethernet, 802.11 wireless, VoIP, and WAN links to remote offices.

Get Started Today