Network Monitor (NM) is a free network protocol analyzer utility that runs on Windows, which allows you to view and capture network related protocol traffic. In many cases, when you are posting questions on the Open Protocol Specifications support forums, a capture will be required if the on-the-wire packet behavior does not match the documentation. At the very least, NM will help Microsoft protocol support team members quickly understand your request.
Submitting a NM Capture:
You can gather traces and analyze the data using the latest version of NM. Future versions of NM will include parsers for Windows Protocol Documents. The latest version of NM is available here:
http://www.codeplex.com/NMParsers
Support for NM:
We host an interactive site on http://connect.microsoft.com. If you have not previously joined the site, select the Network Monitor 3 project from the main page. Once you’ve joined, your participation in our project will show on the connect home page. Consequently, the project no longer appears in the global list. You can file NM bugs, ask NM questions on our forums, and try our new Beta NM software on this site.
Our team also has a blog at http://blogs.technet.com/netmon/default.aspx, which contains helpful tips on filtering, capturing, and many other topics.
NM3 was designed with Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and future operating systems in mind. For earlier operating systems, you can also use Wireshark (www.wireshark.org), or your favorite capture utility, as long as you can save in Netmon 2.x format or pcap version 2.4.