NetPulse24network utilities, reviewed

Diagnose drawer · Diagnostic & Planning Utilities

Diagnostic and planning utilities for the Windows LAN

Some tickets have no obvious tool. A file server is “slow for accounting only”. A workstation holds a port open that nobody configured. The new guest VLAN needs a subnet that doesn’t collide with the one the phones already use. None of these is solved by sweeping a range; each needs either a plan worked out on paper before any change, or a close look at what one machine or one conversation is actually doing.

This drawer holds the utilities for those two moments. LanCalculator does the arithmetic of an addressing plan — masks, ranges, broadcast addresses, IPv6 prefixes — so the plan is right before the switch config is. Sysinternals Suite looks inside a Windows host: which process owns which socket, what starts at boot, what a service touches on disk. Wireshark listens on your own segment and shows the conversation itself. They are ranked by how often each one closes a ticket on a typical small Windows network, and three tools from other drawers fill out the table because a diagnosis often starts with a sweep or ends at a console prompt. The methodology page explains the criteria in full.

6 diagnostic and planning utilities side by side

Sysinternals first because most problems on a Windows LAN are visible from the host; Wireshark second because it answers the ones that aren’t; LanCalculator third because planning prevents a class of tickets rather than closing them. The last three are supporting tools borrowed from the other drawers. Each tool name opens the full review; the vendor links further down open the maker’s own site.

ToolLicenceSeat costPlatformsKey featureBest for
Sysinternals SuiteMicrosoftFreewareNo costWindows (x64 and ARM64 builds)Process Explorer, Process Monitor, TCPView, Autoruns, PsExec and dozens more in one bundleTroubleshooting Windows hosts that misbehave on the network
WiresharkWireshark FoundationGPLv2No cost on any number of machinesWindows, macOS, Linux, BSDPassive capture with deep protocol decoding and display filtersProving what a host or device actually sends on your own LAN
LizardSystems LanCalculatorLizardSystemsBusiness use: $49.95 per machine (perpetual)Windows 10/11, Server 2012 R2–2019 (vendor list)IPv4 and IPv6 in every notation, subnet splitting, and exportable lists of subnets and their addressesPlanning or double-checking an addressing scheme on a Windows desktop
Angry IP ScannerAnton KeksGPLv2No cost on any number of machinesWindows, macOS, LinuxPluggable fetchers (ping, hostname, MAC, ports), a command-line mode and CSV/TXT/XML/IP-port exportAdmins who want the same fast sweeper on Windows, Mac and Linux laptops
LizardSystems Network ScannerLizardSystemsBusiness use: $79.95 per machine (perpetual)Windows (vendor lists 7 through 10 and Server 2008 R2–2016)Enumerates NetBIOS/SMB (including hidden), FTP and web shares with read/write checks per userAuditing share permissions across a small Windows network
PuTTYSimon TathamMITNo cost on any number of machinesWindows, Unix-like systemsSaved sessions, serial console support, plus PuTTYgen, Pageant, Plink and PSCP/PSFTPConsole work on network gear and scripted SSH from Windows

Independent comparison: NetPulse24 is not any of these vendors, and none of them paid for a position. Licence terms, seat prices and supported platforms in this table were rechecked on each maker’s site as of the date shown.

Picking one for your bench

  1. Look at the host before the wire

    If one machine is the problem, TCPView and Process Explorer usually explain it faster than a capture: which process holds the port, which connection is stuck in SYN_SENT, which DLL is loaded. Go to packet capture when the host view looks fine and the traffic still misbehaves.

  2. Capture where the traffic actually flows

    On a switched network a laptop only sees its own traffic plus broadcasts. To watch a conversation between two other hosts you need a mirror (SPAN) port on a switch you manage, a network tap, or a capture running on one of the endpoints.

  3. Filter early, not after the fact

    A capture filter such as host 10.20.30.15 and port 445 keeps the file small and the investigation focused. Display filters in Wireshark are more flexible, but they don’t shrink a multi-gigabyte capture that nobody can open on a laptop.

  4. Put the subnet plan in writing before the change window

    Work out each VLAN’s network address, mask, gateway and usable range in a calculator, paste the result into the change request, and check it against existing DHCP scopes and static reservations. Overlaps found in a spreadsheet are cheap; overlaps found in production are not.

  5. Know which licences allow business use

    Sysinternals and Wireshark cost nothing to use at work. LanCalculator is free only for personal use; a work install needs a Business licence. Check the licence of every utility that goes on the shared admin image.

  6. Treat captures as sensitive data

    A packet capture can contain credentials from legacy protocols, file contents and personal data. Capture only on networks you run, store the files like any other confidential record, and delete them when the ticket closes.

What each utility costs to put on every admin laptop

Wireshark is open source under GPLv2 and runs on Windows, macOS and Linux; on Windows it captures through the Npcap capture driver, which is set up alongside it. Sysinternals Suite is Microsoft freeware under its own licence terms, Windows-only, and can also be run straight from live.sysinternals.com without installing anything. LizardSystems LanCalculator is free for personal use and needs a Business licence at work, listed by the vendor at $49.95 per machine at the time of writing — check the current price before you budget. The where-to-get page lists the official source for each one and how to verify what you receive.

Vendor pages: Sysinternals Suite learn.microsoft.com · Wireshark wireshark.org · LizardSystems LanCalculator lizardsystems.com · Angry IP Scanner angryip.org · LizardSystems Network Scanner lizardsystems.com · PuTTY chiark.greenend.org.uk

Questions about diagnostic and planning utilities

Which Sysinternals tools matter most for network problems?

TCPView shows every TCP and UDP endpoint with its owning process; Process Explorer shows per-process network and handle detail; PsPing tests ICMP, TCP connect latency and bandwidth between two hosts; PsExec runs commands on remote Windows machines. Autoruns helps when something reconnects at every boot.

Do I need Wireshark if I have Sysinternals?

They answer different questions. Sysinternals tells you what a Windows host is doing; Wireshark tells you what actually crossed the wire, including traffic from printers, phones and appliances that you can’t install anything on.

Why use a subnet calculator instead of doing the maths by hand?

Because the errors that hurt are small ones: an off-by-one broadcast address, a /23 that silently swallows the next /24, a gateway placed outside the usable range. A calculator shows every derived value at once, so the plan can be checked rather than re-derived.

Can I capture traffic on the office network with Wireshark?

On a network you administer, capturing to troubleshoot is a normal part of the job, though many organisations have a written policy about it. Capturing on a network you don’t run, or someone else’s traffic without authorization, is not something this site covers.

Keep going

Other drawers

Disclosure: every maker link here lands directly on that maker’s official site, with no affiliate tag and no commission for NetPulse24. See the affiliate disclosure.